How do I get ISO 27001 certification: SME guide

How do I get ISO 27001 certification: SME guide

ISO 27001 certification is the formal, third-party validation that your organisation’s Information Security Management System (ISMS) meets the requirements of the ISO/IEC 27001:2022 standard. For small and medium enterprises, understanding how do I get ISO 27001 certification is increasingly urgent: clients, insurers, and procurement teams now treat the certificate as a baseline requirement rather than a differentiator. The process is structured and achievable, but it demands genuine commitment, the right preparation, and a clear understanding of what auditors actually look for.

What do you need before starting ISO 27001 certification?

Getting certified starts well before you write a single policy. The businesses that struggle most are those that treat ISO 27001 as a documentation exercise rather than a management commitment.

Assemble the right team

Every successful implementation needs three roles filled from day one. An executive sponsor with budget authority, a project manager who owns the timeline, and an ISMS lead who understands information security controls. For most SMEs, the ISMS lead is either an experienced internal manager or a virtual CISO brought in for the project. Top management engagement is not optional: without explicit executive support, systems frequently fail to sustain compliance after certification.

SME team meeting discussing ISO 27001 preparation

Define your ISMS scope carefully

Scope is the single decision that shapes everything else. A scope that is too broad creates unnecessary complexity and cost. A scope that is too narrow may not satisfy the client or regulator who asked for the certificate in the first place. Define your scope around the business units, locations, systems, and services that handle the information you need to protect. Document it precisely, because auditors will test whether your controls actually cover everything within it.

Gather your prerequisites

Before implementation begins, you need a clear picture of what you already have. Conduct a review of existing security policies, access controls, incident records, and supplier agreements. This baseline review feeds directly into your gap assessment. You also need to understand the 93 Annex A controls in ISO/IEC 27001:2022 and decide which apply to your organisation. That decision is recorded in the Statement of Applicability, which documents applied and excluded controls with rationale for each choice.

Pro Tip: Before engaging a certification body, confirm it holds accreditation recognised under the UKAS scheme or an equivalent national body. An unaccredited certificate carries no weight with enterprise procurement teams.

Prerequisite Why it matters
Executive sponsor Provides authority, budget, and visible commitment
Defined ISMS scope Determines audit boundaries and control coverage
Gap assessment Identifies what needs to be built or improved
Statement of Applicability Required document for Stage 1 audit
Existing policy inventory Avoids duplicating work already done
Vertical flow infographic showing ISO 27001 certification steps

How does the ISO 27001 certification process work, step by step?

The full certification process typically takes 36–54 weeks from gap assessment to certificate issue. Control implementation is the longest single phase. Understanding each stage prevents the most common cause of delay: arriving at the external audit unprepared.

Phase 1: Gap assessment (4–6 weeks)

A gap assessment compares your current security posture against the requirements of ISO/IEC 27001:2022. The output is a prioritised list of what needs to be built, improved, or documented. This phase sets your project plan and budget. Skipping it is the fastest route to scope creep and cost overrun.

Phase 2: Risk assessment and treatment (6–8 weeks)

ISO 27001 is built around risk. You must identify information security risks, assess their likelihood and impact, and decide how to treat each one: accept, mitigate, transfer, or avoid. The risk treatment plan then maps each decision to specific Annex A controls. This is not a one-time exercise. The risk register becomes a living document that auditors will review at every surveillance audit.

Phase 3: Policy and documentation development (6–10 weeks)

Your ISMS documentation must cover the policies, procedures, and records required by the standard. This includes an information security policy, access control procedures, incident response procedures, and supplier security requirements, among others. Documentation must reflect how your organisation actually operates. Auditors are experienced at spotting policies that were written for the certificate rather than for the business.

Phase 4: Control implementation (12–20 weeks)

This is the longest phase and the one most businesses underestimate. Controls must be technically implemented, staff must be trained, and evidence of operation must begin accumulating. Certification bodies require at least three months of operational evidence before the Stage 2 audit. Attempting the audit with fewer records frequently results in major nonconformities that delay certification.

Phase 5: Internal audit and management review (4–6 weeks)

The internal audit must be independent and fully documented. It is your organisation’s formal check that the ISMS is working as designed. Any nonconformities found must have corrective actions raised and evidence of resolution in place before the external audit. The management review follows the internal audit and requires senior leadership to formally assess ISMS performance, risks, and objectives.

Pro Tip: Treat the internal audit as a rehearsal, not a formality. Auditors at Stage 2 will ask to see internal audit findings and the corrective actions taken. A well-documented internal audit signals maturity.

Phase 6: External certification audit (4–8 weeks)

The external audit has two stages. Stage 1 is typically one to two days, conducted remotely or on-site, and focuses on your documentation and readiness. The auditor reviews your ISMS scope, Statement of Applicability, risk assessment, and key policies. Stage 2 is the main audit: three to eight days on-site depending on your organisation’s size, during which the auditor tests whether your controls are operating effectively in practice. Passing Stage 2 results in certificate issue.

Phase Duration Key output
Gap assessment 4–6 weeks Prioritised remediation plan
Risk assessment 6–8 weeks Risk register and treatment plan
Policy development 6–10 weeks ISMS documentation set
Control implementation 12–20 weeks Operational controls and evidence
Internal audit 4–6 weeks Audit report and corrective actions
Certification audit 4–8 weeks ISO 27001 certificate

What mistakes do SMEs make during ISO 27001 certification?

The most common failure mode is not a lack of effort. It is effort directed at the wrong things. These are the pitfalls that derail SME certification projects most often.

  • Confusing documentation with compliance. A policy binder does not equal a working ISMS. Auditors test whether controls operate in practice, not whether documents exist on a server.
  • Underestimating the evidence accumulation period. Most SMBs underestimate how long it takes to gather three months of operational records. Starting the clock too late pushes the Stage 2 audit back by months.
  • Losing management engagement mid-project. Executive sponsors who disengage after the kick-off meeting create a vacuum that no project manager can fill. The standard requires active top management involvement throughout.
  • Changing scope mid-project. Expanding or contracting the ISMS scope after implementation has begun forces rework across the risk assessment, Statement of Applicability, and control set.
  • Using an unaccredited certification body. Unaccredited certificates are routinely rejected by enterprise procurement and insurers. Always verify accreditation through UKAS or an equivalent body recognised under the Global ACI framework.
  • Selecting a certification body that also offers consultancy. Under ISO/IEC 17021-1, certification bodies cannot consult and certify the same client. Using one that does invalidate the independence of your audit.
The businesses that achieve certification fastest are not the ones with the most resources. They are the ones that treat the ISMS as a genuine management tool from day one, not a compliance project to be completed and forgotten.

Pro Tip: Engaging a virtual CISO or experienced ISO 27001 implementer for the gap assessment and risk treatment phases pays for itself in time saved and nonconformities avoided at Stage 2.

What happens after you get ISO 27001 certified?

Certification is not a finish line. The three-year certification cycle requires ongoing commitment to keep the certificate valid and meaningful.

  • Year 1 and Year 2: Surveillance audits. Annual surveillance audits verify that your ISMS continues to operate effectively. The auditor reviews a subset of controls, checks that internal audits and management reviews have taken place, and confirms that any previous nonconformities have been resolved.
  • Year 3: Recertification audit. A full recertification audit covers the entire ISMS scope. It is broadly equivalent in scope to the original Stage 2 audit and results in a new three-year certificate if passed.
  • Continuous internal audit. The standard requires ongoing internal audit activity, not just an annual exercise before the external auditor arrives. Build internal audit into your annual calendar from the moment you receive your certificate.
  • Management review cadence. Senior leadership must review ISMS performance at planned intervals. Quarterly reviews are common practice and provide the documented evidence auditors look for.
  • Living documentation. Policies, risk registers, and the Statement of Applicability must be reviewed and updated as your business changes. A policy written for a 20-person business may not reflect the risks of a 100-person business two years later.

The key difference between ISO 27001 and a point-in-time compliance assessment is the continuous improvement requirement. The standard expects your ISMS to get better over time, not simply remain static.

Key takeaways

Achieving ISO 27001 certification requires a structured ISMS, at least three months of operational evidence, and an accredited external auditor who is independent of your implementation team.

Point Details
Define scope early Scope decisions shape every subsequent phase; changing scope mid-project forces costly rework.
Allow 9–18 months The full process from gap assessment to certificate typically takes 36–54 weeks.
Accumulate evidence early Auditors require at least three months of operational records before Stage 2.
Verify accreditation Only certificates from UKAS-accredited bodies are accepted by enterprise procurement and insurers.
Plan for ongoing audits Annual surveillance audits and a Year 3 recertification audit are mandatory to keep the certificate valid.

The uncomfortable truth about ISO 27001 in an SME

Working with small and medium businesses on ISO 27001 reveals a pattern that rarely appears in formal guidance. The organisations that sail through certification are not the ones with the largest budgets or the most experienced security teams. They are the ones where the business owner or compliance manager treats the ISMS as a genuine operational tool rather than a certificate-generating exercise.

The hardest part of ISO 27001 for an SME is not the technical controls. It is sustaining management attention across a 9–18 month project while running a business at the same time. The risk assessment gets done. The policies get written. Then the project stalls because the executive sponsor is focused on a new client contract and the internal audit gets pushed back three months.

The practical fix is to make compliance visible and low-friction from the start. When your risk register, policy library, internal audit schedule, and evidence log live in one place, the ongoing work takes hours per month rather than days. That is the difference between a certificate that stays current and one that lapses at the first surveillance audit. PilotVantage was built specifically for this reality: a structured compliance programme that an ops manager can run without a consultant on retainer.

— PilotVantage

How PilotVantage helps SMEs achieve ISO 27001 certification

https://pilotvantage.com

PilotVantage is a GRC platform built for UK small and medium businesses that need to achieve and maintain ISO 27001 certification without enterprise-level complexity or cost. The platform brings your ISO 27001 compliance programme into a single organised system: risk registers, policy management, internal audits, incident tracking, supplier risk, staff training, and evidence collection. Everything your auditor needs to see is in one place, structured the way accredited certification bodies expect to find it. PilotVantage starts at £49 per month, making it accessible for businesses from 10 employees upwards that are serious about certification without the overhead of a full-time CISO.

FAQ

What is ISO 27001 certification?

ISO 27001 certification is third-party validation that your organisation’s ISMS meets the requirements of the ISO/IEC 27001:2022 standard. It is issued by an accredited certification body following a two-stage external audit.

How long does it take to become ISO 27001 certified?

The full process typically takes 36–54 weeks from gap assessment to certificate issue. Control implementation is the longest single phase, lasting 12–20 weeks on its own.

Do I need ISO 27001 certification as a small business?

You need it if a client, insurer, or regulator requires it as a condition of doing business. Many UK enterprise procurement processes now treat ISO 27001 as a baseline security requirement for suppliers.

How much operational evidence do I need before the Stage 2 audit?

Most accredited certification bodies require at least three months of operational evidence to confirm your ISMS is working in practice. Attempting the audit earlier frequently results in major nonconformities.

How do I choose a certification body for ISO 27001?

Choose a certification body accredited by UKAS or an equivalent national body recognised under the Global ACI framework. Confirm that the body does not also offer consultancy services, as ISO/IEC 17021-1 prohibits the same entity from both consulting and certifying the same client.

← Back to the blog