Abstract navy, teal and gold network illustration representing an ISO 27001 information security management system

ISO 27001 Compliance Guide: What Certification Really Costs and How Long It Takes

ISO/IEC 27001:2022 is the world’s most widely recognised standard for managing information security, and it’s increasingly showing up as a customer contract requirement, a tender prerequisite, or the natural next step for organisations that have already built NIS2 risk-management measures. If your organisation has spent the past year documenting risk assessments, access controls, and incident-response procedures to satisfy NIS2, you are not starting an ISO 27001 project from a blank page — you’re extending work you’ve already done.

This guide covers what the standard actually requires, what certification involves in practice (the accredited audit process itself, not marketing claims about it), what it realistically costs and how long it takes for a small or mid-size company, and a practical, step-by-step roadmap you can follow whether you’re starting from an existing NIS2 baseline or from scratch.

What Is ISO/IEC 27001:2022?

ISO/IEC 27001 is an international standard, jointly published by ISO and IEC, that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). The current version, published in 2022, sets out its formal, auditable requirements in clauses 4 through 10 — these are the clauses a certification body actually tests an organisation against, structured loosely around the Plan-Do-Check-Act cycle used across other ISO management-system standards [1].

Clauses 1-3 (Scope, Normative References, Terms and Definitions) are introductory. The requirements that a certification audit is actually scored against start at clause 4:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Clause Focus
4. Context of the Organization Understanding internal/external issues, stakeholder needs, and defining the ISMS scope [1]
5. Leadership Top-management commitment, the information security policy, and defined roles and responsibilities [1]
6. Planning Risk and opportunity assessment, risk treatment, measurable security objectives, and planning for changes [1]
7. Support Resources, competence, awareness, communication, and documented information (your policy and record set) [1]
8. Operation Operational planning and control, and carrying out the risk assessment and risk treatment in practice [1]
9. Performance Evaluation Monitoring and measurement, internal audits, and management review [1]
10. Improvement Handling nonconformities and corrective actions, and continual improvement of the ISMS [1]

Clauses 4-10 tell you how your management system has to operate. What that system actually has to manage — the specific security controls — is listed separately, in Annex A.

Annex A: The 93 Controls Auditors Actually Test

Annex A of ISO/IEC 27001:2022 lists 93 controls, organised into four themes: 37 Organizational controls (clauses 5.1-5.37), 8 People controls (6.1-6.8), 14 Physical controls (7.1-7.14), and 34 Technological controls (8.1-8.34) [1][2]. That’s down from 114 controls in the 2013 version of the standard — not because requirements were quietly dropped, but because overlapping controls were consolidated and 11 new controls (covering areas such as threat intelligence, cloud security, and data masking) were added on top [2].

Theme Controls Examples
Organizational 37 Policies, roles, asset management, supplier relationships, incident management, compliance
People 8 Screening, terms of employment, security awareness and training, disciplinary process
Physical 14 Secure areas, entry controls, equipment siting and protection, clear desk/clear screen
Technological 34 Access rights, encryption, malware protection, logging, network security, secure development

Not every organisation implements all 93. Which controls actually apply to you — and which you can justify excluding — is documented in a Statement of Applicability (SoA), built directly from the results of your risk assessment [1]. The SoA is one of the first documents an auditor asks to see, and it effectively becomes the table of contents for the entire certification audit.

What Certification Actually Involves: Stage 1, Stage 2, and the Three-Year Cycle

Certification isn’t self-declared. An organisation can build an ISMS internally and benchmark it against ISO 27001 without ever hiring an outside body, but a certificate that customers and procurement teams will actually recognise has to come from an accredited certification body — one accredited by a national accreditation body such as UKAS (UK), ANAB (US), or DAkkS (Germany), all operating under the International Accreditation Forum (IAF) framework [3]. A certificate issued by a non-accredited “certification body” is not equivalent, and is frequently rejected during customer vendor-security reviews.

The audit itself happens in two distinct stages. Stage 1 is a documentation review: the auditor checks whether the ISMS scope, policies, risk assessment, and Statement of Applicability are complete enough to support a full audit, and flags gaps before the organisation commits to Stage 2 [3]. Stage 2, typically scheduled some weeks later, is the substantive audit — interviews, evidence sampling, and observation of the controls actually operating, tested against clauses 4-10 and the Annex A controls listed in the SoA [3]. If Stage 2 passes, the certification body issues a certificate valid for three years.

That three-year certificate is not a “set and forget” credential. Certification bodies run annual surveillance audits at the 12-month and 24-month marks — narrower in scope than Stage 2, typically sampling a subset of controls each time — and a full recertification audit, comparable in depth to the original Stage 2, at the end of year three [3]. An ISMS that isn’t actively maintained between audits is one of the most common reasons certifications get suspended or fail to renew.

What It Costs and How Long It Takes (Realistically)

Cost estimates vary considerably by company size, ISMS scope, and how mature the organisation’s existing security programme already is, but industry figures consistently point to a three-year total in the region of roughly $10,000 to $75,000-plus for a small-to-mid-size organisation, broken approximately into: preparation and implementation ($15,000-$40,000-plus, covering gap analysis, internal audits, and documentation work), the initial Stage 1 + Stage 2 certification audit ($10,000-$50,000-plus), annual surveillance audits (commonly cited around $5,000 per year), and the year-three recertification audit ($10,000-$50,000-plus) [4]. Treat these as planning ranges rather than quotes, and get a scoped, fixed proposal from your chosen certification body before finalising a budget.

Timelines are similarly variable and depend heavily on starting point. Organisations that already have security processes in place — which describes most companies that have implemented NIS2 risk-management measures — can sometimes reach certification in as little as around six months; a more typical range cited for small-to-mid-size companies is six to twelve months, with larger or more complex organisations often taking twelve to eighteen months or more [4]. The single biggest lever on timeline is usually how much of the documentation and control-implementation work has to be built from a blank page versus adapted from something that already exists.

If You’re Already NIS2-Compliant, You’re Most of the Way There

If your organisation already complies with the EU’s NIS2 Directive, you are not starting an ISO 27001 project from zero. We’ve measured this overlap in detail elsewhere on this site: a NIS2-compliant organisation typically sits at roughly 70-80% of the way toward ISO 27001 readiness, because the two frameworks are built on the same underlying foundations.

Both are risk-based rather than checklist-based: NIS2’s Article 21 measures and ISO 27001’s clause 6 planning requirements both start from identifying risks to information and systems and choosing proportionate measures to treat them, instead of prescribing one fixed list of controls for every organisation. And both frameworks cover largely the same control domains — access control, incident detection and response, business continuity, supplier and third-party risk, cryptography, and physical security all show up in NIS2’s required measures and in ISO 27001’s Annex A alike. What NIS2 doesn’t hand you is the formal management-system layer: a documented ISMS scope, a Statement of Applicability, an internal audit programme, management review, and — critically — an independent, accredited audit trail that a certificate represents. That structural layer, more than brand-new security controls, is usually what makes up the remaining 20-30%. For the full control-by-control breakdown of exactly where NIS2 and ISO 27001 overlap and diverge, see our detailed NIS2 vs ISO 27001 comparison.

The Practical Roadmap to Certification

The path from “we have some security measures” to “we’re certified” follows a broadly consistent sequence, whether you’re starting from an existing NIS2 programme or from scratch. Each step below is covered in its own dedicated guide on this site, published alongside this one:

  1. Gap analysis. Compare your current state against ISO 27001’s clauses and the 93 Annex A controls to find out what’s missing before committing resources. See our gap analysis guide.
  2. Define your ISMS scope. Decide which parts of the organisation, which locations, and which systems the certificate will actually cover — get this wrong early and you’ll redo work later. See our ISMS scope statement template.
  3. Run a formal risk assessment. Identify information-security risks and treat them using a documented, repeatable methodology, commonly aligned to ISO 27005. See our risk assessment methodology guide.
  4. Build your Statement of Applicability. Document which of the 93 Annex A controls apply to you, which don’t, and why — this is the document the auditor keeps returning to throughout Stage 1 and Stage 2. See our Statement of Applicability template.
  5. Write and implement the required policies. Most organisations need, at minimum, an access control policy, an incident response policy, a business continuity policy, and a supplier security policy, alongside the broader Annex A-aligned policy set.
  6. Run an internal audit. Test your own ISMS against clauses 4-10 and your SoA before an external auditor does. See our internal audit checklist.
  7. Book the certification audit. Choose an accredited certification body and go through Stage 1 and Stage 2 as described above. See our certification cost breakdown for what to budget specifically for this stage.

If you’re approaching this from an existing NIS2 programme, it’s worth reading our NIS2 vs ISO 27001 comparison before starting the gap analysis step — it will save you from re-assessing risks and re-writing policies you have, in large part, already built.

FAQ

Is ISO 27001 certification required under NIS2?
No. The NIS2 Directive requires in-scope organisations to implement risk-based technical, operational, and organisational security measures, but it does not name ISO 27001 (or any other specific standard) as mandatory. ISO 27001 certification is one widely recognised way to demonstrate that those measures are in place and independently verified, which is why many NIS2-affected organisations pursue it — but it remains a choice, not a legal requirement in itself. See our NIS2 vs ISO 27001 comparison for the full picture.

How much does ISO 27001 certification actually cost?
There’s no single number — cost depends on company size, ISMS scope, and existing maturity — but industry estimates commonly put the three-year total for a small-to-mid-size company somewhere between $10,000 and $75,000-plus, covering preparation, the initial audit, annual surveillance audits, and year-three recertification [4]. Get a scoped quote from an accredited certification body rather than budgeting a single unverified figure.

How long does ISO 27001 certification take?
Typically six to twelve months for a small-to-mid-size company with some existing security processes in place, though it can be as short as around six months or stretch past twelve to eighteen months for larger or more complex organisations [4]. Control implementation and documentation is usually the longest single phase.

What’s the difference between a Stage 1 and Stage 2 audit?
Stage 1 is a documentation review that checks whether the ISMS — scope, policies, risk assessment, Statement of Applicability — is ready to be audited in depth. Stage 2, usually held some weeks later, is the substantive audit: the certification body tests whether the controls are actually operating as documented, through interviews, evidence review, and observation [3]. Both stages must be passed to be certified.

Does using documentation templates guarantee certification?
No, and any provider implying otherwise is misrepresenting how certification works. Templates and toolkits, including ours, can give an organisation a documented ISMS foundation — policies, risk methodology, Statement of Applicability, internal audit pack — so the work isn’t starting from a blank page, but the certification decision itself is made independently by an accredited third-party certification body after a Stage 1 and Stage 2 audit of the organisation’s actual, operating controls [3]. Documentation prepares an organisation for the audit; it does not replace it.

Do I need a UKAS, ANAB, or similarly accredited certification body?
If the goal is a certificate that customers, regulators, and vendor-risk teams will actually accept, yes. Accreditation bodies under the International Accreditation Forum (IAF) — UKAS in the UK, ANAB in the US, DAkkS in Germany, and their national equivalents elsewhere — audit certification bodies themselves to confirm they follow consistent, competent audit practices [3]. A certificate from an unaccredited body is not equivalent and is frequently rejected during customer due diligence.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: