Skip to main content

How to get your company ISO 27001 certified

By Harry Sidhu — Director and Principal Consultant, Aegentra · Updated

To get an organisation ISO 27001 certified, define the ISMS scope, assess and treat information-security risks, create the Statement of Applicability, implement and operate the selected controls, retain evidence, complete internal audit and management review, address relevant corrective actions, and then engage an independent accredited certification body for Stage 1 and Stage 2. Aegentra can support implementation, readiness and separately scoped internal audits where objectivity and impartiality can be demonstrated. It does not issue the certificate.

For Australian cost components, certification-body fees and timeline factors, use the ISO 27001 certification guide for Australia.

For itemised costs and a worked three-year budget, read the detailed ISO 27001 cost guide. The model separates implementation, internal audit and independent certification.

The step-by-step certification checklist

  1. Define the ISMS scope. Document the organisational, physical, technological and information boundaries that the management system will cover, plus relevant interfaces and dependencies.
  2. Assess and treat information-security risk. Use a repeatable method to identify, analyse and evaluate risks, assign owners and approve treatment decisions.
  3. Create the Statement of Applicability. Record necessary controls, compare them with the 93-control Annex A reference set, justify applicability decisions and track implementation status. Risks come first; Annex A is the cross-check, not the starting point.
  4. Implement and operate selected controls. Assign responsibilities, establish necessary documented information and operate the selected organisational, people, physical and technological controls.
  5. Retain objective evidence. Keep decisions, records, test results, reviews, approvals, exceptions and corrective actions that demonstrate how the ISMS operates.
  6. Complete an objective internal audit. Appoint a competent auditor who was not responsible for the work being assessed. Aegentra can support implementation and a separately scoped Clause 9.2 internal audit through different consultants, where objectivity and impartiality can be demonstrated.

    Before the audit, the assigned auditor’s competence, prior involvement, potential conflicts and reporting arrangements are documented. The auditor retains responsibility for the audit findings and conclusions. Where impartiality cannot be adequately protected, a separate external auditor is required.

    Certification remains separate: an independent accredited certification body conducts Stage 1 and Stage 2 and makes the certification decision. Aegentra does not issue the certificate.

  7. Complete management review and corrective action. Top management reviews the ISMS and its required inputs, makes decisions and ensures relevant nonconformities and corrective actions are addressed.
  8. Proceed to Stage 1. The independent accredited certification body reviews documented readiness and determines whether the organisation is prepared for Stage 2.
  9. Complete Stage 2. The certification body samples implementation and effectiveness, records findings and alone decides whether to issue certification.

Frequently asked questions

Can we implement ISO 27001 ourselves?

Yes. An organisation may implement its own ISMS if it can assign competent owners, make the necessary risk and management decisions, operate controls and retain objective evidence. External support is optional; internal audit and certification responsibilities must still be separated appropriately.

Do we need every Annex A control?

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

Who performs Stage 1 and Stage 2?

An independent accredited certification body performs Stage 1 and Stage 2 and makes the certification decision. Aegentra does not issue the certificate.

Can the implementation provider perform the internal audit?

Yes, provided objectivity and impartiality can be demonstrated. Aegentra can assign different consultants to implementation and a separately scoped internal audit. The auditor must not assess work they designed, implemented or operate, and prior involvement, potential conflicts and reporting arrangements must be documented. If adequate impartiality cannot be protected, a separate external auditor is required. Certification remains with an independent accredited certification body.

Where can we compare Australian costs and timeline factors?

Use the ISO 27001 certification guide for Australia. It separates implementation, internal-audit and certification-body costs and explains the factors that affect timing.