Get ISO 27001 ready
For organisations preparing for ISO/IEC 27001:2022 certification
ISO 27001 is the international standard for an information security management system (ISMS) - the policies, processes and controls through which an organisation manages its security risks on an ongoing basis. It is the certification enterprise customers ask for most, and for many deals a current certificate is the difference between passing and failing the vendor security review.
What certification actually requires
The standard has two halves. Clauses 4-10 define the management system itself: understanding your context, leadership commitment, risk assessment and treatment, resourcing, operation, performance evaluation and continual improvement. Annex A then lists 93 reference controls, organised into four themes:
- Organisational (37 controls) - policies, roles, supplier relationships, incident management, business continuity, legal and regulatory compliance.
- People (8 controls) - screening, terms of employment, awareness training, disciplinary process, responsibilities after termination.
- Physical (14 controls) - secure areas, entry controls, protecting equipment and media, clear desk and screen.
- Technological (34 controls) - access control, authentication, encryption, logging and monitoring, backups, vulnerability management, secure development.
You do not have to implement every Annex A control - you have to assess your risks, decide which controls apply, and justify every inclusion and exclusion in a Statement of Applicability. That risk-to-control thread is what auditors pull on hardest.
How the audit works
Certification is a two-stage audit by an accredited certification body (UKAS-accredited in the UK). Stage 1 reviews your documentation and readiness; Stage 2 tests that the ISMS actually operates - auditors sample evidence, interview staff and trace risks through to treatments. A certificate runs on a three-year cycle with surveillance audits in between, so the system has to keep working, not just exist for audit week.
The most common reasons organisations stall: a risk assessment disconnected from the controls it supposedly drives, a Statement of Applicability written last instead of first, no evidence of internal audit or management review, and supplier risk handled by hope. All of them are findable months before an auditor finds them.
The sensible order of work
- 1. Scope the ISMS deliberately. Which parts of the business, which locations, which services? A tight, honest scope is easier to certify and still satisfies customers.
- 2. Assess yourself against the standard before engaging a certification body, so you know your real position rather than your assumed one.
- 3. Run the risk assessment and build the Statement of Applicability from it - not the other way round.
- 4. Close the gaps in priority order, keeping evidence as you go: policies approved, controls configured, training delivered.
- 5. Internal audit and management review - both are mandatory, both are checked, and both are routinely missing at Stage 1.
How Assura helps
Assura includes a guided ISO 27001 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each control with written reasoning. When you finish you get the full picture in one pass:
- a scored readiness view across the control themes, so you know how far from certifiable you are today;
- a prioritised gap list and remediation plan, ranked by severity;
- a live risk register that tracks each fix through to done;
- and because Assura maps controls across frameworks, work you have already done for Cyber Essentials, SOC 2 or NIST CSF pre-fills its ISO 27001 counterparts - and vice versa.
Assura prepares you for certification; the certificate itself is issued by an accredited certification body after audit. Arriving with your gaps already closed is what keeps that engagement short.
Check your readiness with Assura
Related guides: Cyber Essentials · NIST CSF 2.0 · SOC 2