SecurSentry
← All notes
Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

The honest end-to-end path from a standing start to an ISO 27001 certificate, written for busy UK business owners who want to know what they're actually signing up for.

The short version

Getting ISO 27001 certified is less a single event and more a project with a clear shape: you decide what you’re protecting, build a management system around it, run that system until it produces real evidence, and then have an independent body check your work.

If you’ve landed here because a customer contract, a tender, or a nervous board has raised ISO 27001, you probably want a straight answer to one question: what does this actually involve? This guide walks the whole path, in the order it really happens, with honest notes on effort and time. It’s written for the owner or operator of a UK small business, not for a security specialist. If you’re still weighing whether the standard is right for you at all, our overview of ISO 27001 for SMEs is a gentler starting point, and it’s worth comparing the options in Cyber Essentials vs ISO 27001 before you commit.

1. Define your scope and get leadership behind it

Before anything else, decide exactly which parts of your business the certificate will cover, and get genuine buy-in from the top.

Scope is the single most important early decision. It sets the boundary of your information security management system (the ISMS), which is the framework of policies, processes and controls at the heart of ISO 27001. You might scope it to the whole company, or to one product, one team, or one site. A tight, honest scope is far easier to certify and maintain than a sprawling one you can’t keep on top of.

Leadership matters just as much. The standard expects top management to own information security, not delegate it and forget it. In a small firm that usually means the founder or a director puts their name to it, sets a short security policy, and makes clear that this is real work with real time attached. Without that, the project stalls the first time it competes with fee-earning work.

Keep the scope small and true

A common mistake is scoping too broadly to look impressive. Auditors aren't impressed by breadth, they're reassured by control. Cover what you can genuinely manage well, and expand later if you need to.

2. Run a risk assessment and write your Statement of Applicability

Work out what could go wrong with your information, decide what you’ll do about each risk, and record which controls apply to you and why.

This is the analytical heart of the standard, and the part people most often underestimate. You identify your information assets, think through the threats to them, and assess each risk in a consistent way. Then you decide how to treat each one: reduce it, accept it, avoid it, or share it (through insurance or a supplier, for example).

Out of that comes your Statement of Applicability, or SoA. This is the document that lists the controls from Annex A of the standard, says which ones apply to your organisation, and explains your reasoning for any you’ve left out. ISO/IEC 27001:2022 lists 93 controls across four themes: organisational, people, physical and technological. The SoA is the spine of your ISMS, and auditors lean on it heavily, so it’s worth doing properly rather than copying someone else’s.

3. Implement the controls and write your policies

Put the controls you’ve chosen into practice and document how your organisation actually does things.

Now you turn decisions into reality. Depending on your risk assessment, this might mean tightening access controls, sorting out backups and encryption, formalising how you onboard and offboard staff, managing your suppliers, or improving how you handle incidents. Much of it will be things you half-do already, brought into a consistent, written form.

Policies and procedures are part of this step. You’ll produce a set of documents that describe your approach, from an information security policy down to specific procedures for, say, access requests or reporting a suspected breach. The trick is to write what you’ll genuinely follow. A drawer full of aspirational policies nobody reads is worse than a lean set that matches reality, because Stage 2 tests whether the words and the working practice line up.

Don't reinvent what you've built before

If you already hold Cyber Essentials, a good chunk of your technical groundwork is done. Our Cyber Essentials checklist maps the basics, and much of it feeds straight into your ISO 27001 controls. Work you do once should keep paying off.

4. Operate the system and build up records

Let the ISMS run for long enough to produce real evidence, including at least one internal audit and a management review.

Here’s the part that catches people out, and the reason ISO 27001 can’t be rushed. It isn’t enough to have a system on paper. You have to operate it and generate records that prove it’s working: risk reviews happening, incidents logged and handled, access being granted and removed, training taking place. An auditor at Stage 2 wants to see history, not intentions.

Two activities are non-negotiable before you’re ready for that Stage 2 visit. First, an internal audit, where you (or someone independent of the work) check your own ISMS against the standard and flag gaps. Second, a management review, where leadership formally looks at how the system is performing and decides on improvements. Both need to have actually happened, with documentation retained as evidence. In practice this is why you typically need a few months of live operation before you invite the external auditors in.

5. Choose a UKAS-accredited certification body

Pick an independent certification body that is accredited by UKAS, so your certificate carries proper weight.

You can’t certify yourself. An accredited, independent certification body audits you and issues the certificate. In the UK, the body that oversees those certification bodies is the United Kingdom Accreditation Service, or UKAS. It’s the single national accreditation body, and it assesses each certification body for auditor competence, impartial decisions and consistent application of the standard.

Why does this matter to you? Because a certificate from a UKAS-accredited body is the one your customers’ procurement teams will recognise and trust. An unaccredited certificate can look similar and cost less, but it may not satisfy the very contract that sent you down this road. When you gather quotes, ask directly whether the certification body is UKAS-accredited for ISO 27001, and factor the answer into your decision alongside price. Speaking of which, our guide to ISO 27001 certification cost breaks down where the money actually goes.

6. Pass the Stage 1 and Stage 2 audits

Your certification body assesses you in two stages: first your documentation and readiness, then your implementation and effectiveness.

The Stage 1 audit is a readiness and documentation review. The auditor checks whether your ISMS is designed correctly and whether your paperwork is likely to hold up under closer inspection. It’s often shorter, sometimes done remotely, and it usually surfaces a few things to tidy up. Think of it as a friendly warning of where Stage 2 might press.

The Stage 2 audit is the substantial one. Some weeks later, the auditor returns to test whether the system is genuinely operating: sampling your records, interviewing your people, and checking that what you wrote in Stage 1 matches how you actually work. If they raise non-conformities, you’ll get time to address them. Once the auditor is satisfied and the certification body signs off, your ISO 27001 certificate is issued.

Gaps at Stage 2 are normal

Very few organisations sail through Stage 2 with nothing raised. Minor non-conformities are common and usually just mean a corrective action and some evidence you've fixed it. Go in expecting a to-do list, not a pass-or-fail exam.

7. Maintain it: surveillance audits and recertification

The certificate lasts three years, with lighter surveillance audits each year and a fuller recertification audit at the end of the cycle.

Certification isn’t the finish line, it’s the start of a three-year rhythm. Your certificate is valid for three years, but the certification body checks in with annual surveillance audits, typically shorter than Stage 2, to confirm your ISMS is still operating and improving. At the end of the three years, a recertification audit renews the certificate for a further cycle.

This is actually good news framed correctly. The habits you build (regular risk reviews, an internal audit each year, a management review) are exactly what keep your security genuinely healthy between audits. Do the work once and keep it ticking over, and each surveillance visit becomes a light check rather than a scramble.

How long it takes, and ways to make it easier

For most SMEs the work commonly runs from around three to twelve months, and the honest answer is that it depends on where you’re starting from.

There’s no fixed clock. A well-organised firm that already has decent security habits and perhaps holds Cyber Essentials might move through the earlier steps quickly. A business starting from a blank page will take longer, mostly because of step 4: you can’t shortcut the requirement to operate the system and accumulate records before Stage 2. Anyone promising you a certificate by a specific date is describing the process length as if it were a guaranteed outcome, and that’s not how certification bodies work. The work takes time; the certificate is earned when you’re genuinely ready.

A few things genuinely make it lighter. Keep your scope tight. Reuse anything you already have, including Cyber Essentials groundwork (if that phrase is new to you, Cyber Essentials explained is a two-minute primer). Write policies you’ll actually follow rather than borrowed ideals. And decide honestly whether to run it in-house or bring in help. Doing it yourself is entirely possible and saves money, but it asks for real time and a bit of comfort with the reading. Getting help costs more but can take the unfamiliar parts off your plate. Neither is the right answer for everyone, so weigh it against your budget and your spare capacity.

Whichever route you pick, the value of ISO 27001 is that the effort compounds. The system you stand up doesn’t just win you one contract, it becomes the way you run security from then on.


SecurSentry is launching soon to help UK SMEs work through a journey like this step by step, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.

This article is for general information only and does not constitute legal or compliance advice. Timelines and scope vary by organisation; where in doubt, consult a qualified professional or an accredited certification body.

Frequently asked questions

How long does it take to get ISO 27001 certified?

For a small or medium business the work commonly runs from around three to twelve months, depending on how much you already have in place. The single biggest factor is that you have to operate your ISMS for long enough to build up real records, including at least one internal audit and a management review, before the Stage 2 audit. Treat any promise of a certificate 'by a fixed date' with caution, because the certification body decides when you're ready, not the calendar.

Do I need a UKAS-accredited certification body?

For a certificate that customers and auditors will recognise, yes. UKAS is the UK's national accreditation body, and a UKAS-accredited certification body has been assessed for auditor competence, impartiality and consistency. An unaccredited certificate may cost less, but it can carry far less weight when a client's procurement team checks it. Always confirm accreditation before you sign anything.

What's the difference between the Stage 1 and Stage 2 audits?

Stage 1 is a readiness and documentation review. The auditor checks whether your ISMS is designed properly and whether the paperwork is likely to pass. Stage 2 is the deeper visit, where the auditor tests whether the system is genuinely operating and effective, by sampling your records and talking to your people. Stage 2 usually happens several weeks after Stage 1 so you can close any gaps first.

Can a small business do ISO 27001 without consultants?

Yes, it's possible to do it in-house, especially if someone on the team is organised and has time to give it. The standard doesn't require you to hire anyone. That said, many smaller firms bring in help for the parts that are unfamiliar, such as the risk assessment or the internal audit. The right choice depends on your budget, your appetite for the reading, and how much spare capacity you honestly have.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min
Cyber Essentials

An ISO 27001 Checklist for Small Businesses

11 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.