First, what you are buying

ISO/IEC 27001 is a management system standard. You are not buying a set of documents and you are not buying a piece of software. You are buying a way of running information security that can be shown to work — decisions recorded, risks reviewed, controls operating, evidence kept.

That distinction decides whether the project succeeds. Companies that treat it as a document exercise pass nothing, because the audit is not a document review.

One thing to be clear about before you start: the certificate is issued by an accredited certification body, not by a consultant. Anybody who offers to both implement your management system and certify it is offering you a certificate that a serious customer will not accept. Those two roles are deliberately separate, and we are on the implementation side of that line.

The sequence

  1. Scope. Which parts of the business, which sites, which services. The single most consequential decision in the project, and the one most often made carelessly.
  2. Gap analysis. Where you are against where the standard expects you to be.
  3. Risk assessment. What could go wrong, how likely, how bad, and what you intend to do about it.
  4. Statement of Applicability. Every control, and either how you apply it or why you do not. Auditors read this closely.
  5. Implementation. Policies written, controls actually put in place, people told.
  6. Operation. The system runs and produces records. This takes months and cannot be shortened.
  7. Internal audit and management review. Both are required before certification. Both must be evidenced.
  8. Stage 1 audit. The certification body checks you are ready. Findings here are normal.
  9. Stage 2 audit. They test whether the system is operating. This is the real one.
  10. Surveillance audits in the following years, and recertification after three.

Where the money actually goes

People ask what a certificate costs and expect one number. There are three budgets, and they are usually confused with each other.

  • The certification body’s fees. Stage 1, Stage 2, and the surveillance audits that follow. Priced on your headcount and scope. This is generally the smallest of the three, and the only one most people think about.
  • Implementation help. Consultancy, if you use it. Varies enormously with how much you do yourselves.
  • Your own people’s time, plus anything you have to go and buy. Interviews, workshops, writing, testing, the internal audit, and whatever the gap analysis says is missing — backup that gets restored and tested, logging you do not currently have, a password manager, multi-factor authentication.

The third is nearly always the largest and nearly always the one left out of the budget. If the gap analysis finds you have no working backup, ISO 27001 did not create that cost. It found it.

Three places it stalls

1. The scope is drawn too wide

The customer asking for the certificate cares about one service line. The project gets scoped across the whole company anyway, because that felt more impressive, and it triples the work for no commercial gain. Scope narrowly, certify, extend later if there is a reason to. A narrow scope honestly stated beats a wide one you cannot sustain.

2. Nobody owns the risk assessment

It gets written once, by whoever is helping you, and never touched again. At the audit it is obvious — the risks do not match the business, and nobody in the room can talk about them. A risk assessment that management has never argued about is not a risk assessment.

3. There is no evidence

This is the one that fails Stage 2. The control exists, and everybody genuinely does it, but nothing is recorded. Access reviews happen in conversation. Backups are tested when somebody remembers. Incidents get resolved and never written down.

Auditors want records across a period, and you cannot manufacture three months of history in the last three weeks. Deciding early what each control leaves behind — a ticket, a signed list, a dated report — is most of the difference between passing and not.

How long it really takes

For a company of around forty people starting from nothing, six to nine months to Stage 2 is realistic. Faster is possible where good practice already exists and only needs documenting.

What does not work is compressing it to three months because that is when the tender closes. The compressible parts are writing and implementation. The part that cannot be compressed is the system running long enough to produce evidence that it runs, and that is exactly what Stage 2 examines.

If the deadline is immovable, the honest move is usually to tell the customer where you are in the programme rather than to buy a certificate that will not survive its first surveillance audit.

What the certificate proves, and what it does not

It proves an accredited third party tested your management system against the standard on a particular date and found it operating. It is a strong signal, and in a tender it is often decisive.

It does not prove you cannot be breached. Certified organisations are breached. What it changes is whether you find out, whether you respond in an order somebody decided in advance, and whether you can show a customer or a regulator what you did.

The point

Most of what ISO 27001 asks for is what a competently run company should be doing anyway. The certificate is the part a customer can verify. The value is in the half you would have needed regardless.

How we run these programmes is set out under Compliance & Certification, and the free gap check is ninety minutes with a written summary you keep either way.

General guidance on ISO/IEC 27001. Fees, timelines and audit practice vary by certification body and by scope — confirm both with the body you intend to use.