Back to Blog
Compliance
Featured
9 min read

ISO 27001 Certification: What It Takes and What It Costs

Certification is an audit of a management system, not of your controls. The Statement of Applicability, the two-stage audit, and the three-year surveillance commitment people underestimate.

GuardsArm Team

Security Experts

June 8, 2025

ISO 27001 certification

ISO 27001 certifies a management system, not a set of controls. That distinction explains most of what surprises organisations going through it: the auditor spends less time than expected checking whether your firewall is configured well, and more time checking that you decided what risks matter, did something about them, measured whether it worked, and can show the paperwork.

A management system
Certification is of the ISMS, not of individual technical controls
You define the scope
Scope is yours to set — and the certificate means nothing outside it
Three-year cycle
Certification plus two surveillance audits, then recertification

Scope is the most consequential decision

You define what the ISMS covers — a product, a business unit, a location, or everything. A narrow scope is faster, cheaper and easier to maintain. It is also less useful, and customers increasingly read the scope statement rather than accepting the certificate at face value.

Scope too narrowly and you get a certificate that excludes the service the customer is buying. Scope too broadly and the programme takes twice as long. The usual sensible answer is the service the customer cares about, plus the supporting functions that genuinely touch it.

Read a supplier’s scope before accepting their certificate
A certificate naming one office and one product tells you nothing about the service you are buying from them. This is the single most common misreading of ISO 27001 in vendor due diligence — see vendor risk scoring.

The Statement of Applicability

The SoA lists every Annex A control, states whether it applies, and if not, why. It is the document auditors return to constantly and the one most often produced carelessly.

An exclusion needs a defensible reason tied to your scope and risk assessment. "Not applicable because we do not do that" is fine when true and evidenced. "Not applicable" against a control you simply have not implemented is a finding waiting to happen.


The audit, in two stages

ISO 27001 certification timelineISO 27001 certification timeline1Gap analysisMonths 1-2Where you are against the standard. Optional, and almost always worth it.2Build the ISMSMonths 2-8Risk assessment, policies, SoA, controls, records. The bulk of the work.3Operate itMonths 6-10You need evidence of the system running — internal audit, management review, metrics.4Stage 1 auditMonth 9-11Documentation review. Is the ISMS designed correctly and ready to be tested?5Stage 2 auditMonth 11-13Effectiveness. Does it operate as documented? Findings raised here.6SurveillanceYears 2 and 3Smaller annual audits, then full recertification in year three.
The "operate it" phase is what organisations underestimate — you cannot certify a system with no operating history.

That operating-history requirement catches people. You need internal audits, a management review and records showing the system ran before Stage 2. Three months of evidence is a realistic minimum; there is no way to compress it to zero.


What it costs

Certification body fees are usually the smallest line. The real costs are:

CostNote
Certification bodyScales with scope and headcount; three-year cycle
Internal effortConsistently the largest, and consistently underestimated
ConsultancyOptional; most useful for the risk assessment and SoA
ToolingOptional. A platform helps with evidence, not with judgement
RemediationWhatever the gap analysis found
Ongoing operationInternal audit, management review, continual improvement — forever

That last row is the one that determines whether certification survives. An ISMS built by a project team that then disbands will fail its first surveillance audit.


Where it sits against other frameworks

If you are choosing rather than committed, see SOC 2 vs ISO 27001. Briefly: ISO 27001 is the international standard and is expected by European and Asian buyers; SOC 2 dominates North American software procurement. For healthcare specifically, neither replaces HIPAA obligations — they demonstrate a managed approach, but the Security Rule applies regardless, and its risk analysis requirement is separate. See HIPAA risk analysis.


Where to start

Write the scope statement first, in one sentence, and show it to whoever is asking you to certify. If a customer is driving this, confirm the scope you intend would satisfy them. Discovering after twelve months that the certificate excludes the service they buy is the most expensive mistake available here.

GuardsArm supports ISO 27001 programmes including scoping, risk assessment and Statement of Applicability development. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “ISO 27001 Certification: What It Takes and What It Costs”

Talk to the GuardsArm team about how these services apply to your environment.