Guide

Get ISO 27001 ready

For organisations preparing for ISO/IEC 27001:2022 certification

ISO 27001 is the international standard for an information security management system (ISMS) - the policies, processes and controls through which an organisation manages its security risks on an ongoing basis. It is the certification enterprise customers ask for most, and for many deals a current certificate is the difference between passing and failing the vendor security review.

What certification actually requires

The standard has two halves. Clauses 4-10 define the management system itself: understanding your context, leadership commitment, risk assessment and treatment, resourcing, operation, performance evaluation and continual improvement. Annex A then lists 93 reference controls, organised into four themes:

You do not have to implement every Annex A control - you have to assess your risks, decide which controls apply, and justify every inclusion and exclusion in a Statement of Applicability. That risk-to-control thread is what auditors pull on hardest.

How the audit works

Certification is a two-stage audit by an accredited certification body (UKAS-accredited in the UK). Stage 1 reviews your documentation and readiness; Stage 2 tests that the ISMS actually operates - auditors sample evidence, interview staff and trace risks through to treatments. A certificate runs on a three-year cycle with surveillance audits in between, so the system has to keep working, not just exist for audit week.

The most common reasons organisations stall: a risk assessment disconnected from the controls it supposedly drives, a Statement of Applicability written last instead of first, no evidence of internal audit or management review, and supplier risk handled by hope. All of them are findable months before an auditor finds them.

The sensible order of work

How Assura helps

Assura includes a guided ISO 27001 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each control with written reasoning. When you finish you get the full picture in one pass:

Assura prepares you for certification; the certificate itself is issued by an accredited certification body after audit. Arriving with your gaps already closed is what keeps that engagement short.

Check your readiness with Assura

Related guides: Cyber Essentials · NIST CSF 2.0 · SOC 2