ISO/IEC 27001:2022 certification

Information security, tested against evidence.

Certification of an information security management system, for organisations that need to show rather than assert that their security arrangements work.

Who is ISO/IEC 27001 certification for?

ISO/IEC 27001 suits organisations that hold information other people care about and are being asked to demonstrate how that information is protected. It is used most often by:

  • Software and technology businesses whose customers raise certification during procurement or vendor security review.
  • Managed service providers and processors carrying security obligations on behalf of their clients.
  • Organisations tendering into government or regulated sectors where a certified management system is a condition of supply.
  • Organisations that have outgrown informal security practice and need a defensible basis for decisions about risk.

Size is not the qualifier. A small organisation with a clearly drawn scope can hold certification; a large one with an ill-defined scope will struggle. What matters is that the boundary is honest and the arrangements inside it are real.

What does an ISO/IEC 27001 audit assess?

Our audit examines the management system against ISO/IEC 27001:2022 and against the arrangements you have stated for yourself. We look at:

  • The boundary and applicability of the management system, including cloud services, remote working and processes performed by others.
  • Leadership, roles and responsibilities, and the information security objectives set for the system.
  • The information security risk assessment and risk treatment process, and whether treatment decisions trace back to the risks recorded.
  • The Statement of Applicability: the controls determined to be necessary, those excluded, and the justification recorded for each position.
  • Controls as they operate, tested through interviews, observation and records rather than documentation alone.
  • Performance evaluation: monitoring, measurement, internal audit and management review.
  • Nonconformity handling, corrective action and continual improvement.

Certification confirms that the management system meets the standard within the certified scope. It is not a guarantee that incidents will not occur, it is not an assessment of any individual product or service, and it is not a penetration test.

How does ISO/IEC 27001 certification work?

  1. Application and review

    You describe your organisation, sites, activities, requested scope and use of outsourced processes. We determine the competence required and the audit time applicable under the scheme, and confirm that we can take the work impartially.

  2. Stage 1

    We examine readiness for Stage 2: how the scope is drawn, the risk assessment method, the Statement of Applicability, internal audit and management review records, and your understanding of the standard. Areas of concern that would become nonconformities at Stage 2 are reported to you.

  3. Stage 2

    We test implementation and effectiveness across the certified scope, gather objective evidence and record findings.

  4. Correction and corrective action

    Where nonconformities are raised, you analyse cause and act. We review the response and verify effectiveness as required before a decision can be made.

  5. Independent certification decision

    Competent personnel who were not members of the audit team review the audit information and make the certification decision.

  6. Surveillance and recertification

    Surveillance audits monitor continuing conformity through the certification cycle. A recertification audit evaluates continued fulfilment of the standard before certification expires.

Each stage is described in full on our certification process page.

What evidence should you prepare for an ISO/IEC 27001 audit?

Bring the records the management system actually produces, rather than documents written for the audit. For ISO/IEC 27001 we normally expect to see:

  • A scope statement naming the boundary, the locations, and the interfaces and dependencies with other parties.
  • The information security policy and the objectives set beneath it.
  • The risk assessment methodology, the current risk register and the risk treatment plan.
  • The Statement of Applicability, current and under version control.
  • Records showing controls in operation: access reviews, change records, backup and restoration testing, logging and monitoring output, supplier assessments and awareness activity.
  • Incident records, including how each incident was classified, handled and closed.
  • The internal audit programme, the individual audit reports, and the basis on which the auditors were judged competent.
  • Management review inputs and the decisions recorded as outputs.
  • Continuity and availability arrangements, together with evidence that they have been tested.

What are the most common ISO/IEC 27001 readiness gaps?

These are the issues that most often delay a Stage 2 audit or generate findings.

  • Scope drawn for convenience. A scope that excludes the systems customers actually rely on will not survive scrutiny, and the resulting certificate is difficult to use commercially.
  • A Statement of Applicability without reasoning. Marking controls as applicable is not sufficient. The justification for inclusion or exclusion must be recorded and must agree with the risk treatment plan.
  • Risk treatment disconnected from risk. Risks recorded in one document and controls selected in another, with no visible line between the two.
  • Internal audit as a formality. A single short audit across the whole system, performed by the person who built it, rarely produces useful evidence and raises questions about independence.
  • Management review as a calendar entry. Minutes that record attendance but no decisions, with no evidence that the required inputs were considered.
  • Supplier arrangements assumed rather than assessed. Cloud platforms and outsourced functions sit inside the dependency chain of the scope and need documented assessment.
  • Documentation describing an intended system. Where the written process and daily practice differ, the audit follows practice.

ISO/IEC 27001 enquiries

Tell us what you need certified.

Send us your proposed scope, your locations and an approximate headcount. We will explain what an ISO/IEC 27001 engagement would involve, what evidence to prepare, and where we think your readiness sits.

Start an enquiry

Related information

General enquiries: info@acscert.com.au. Complaints and appeals: complaints@acscert.com.au.