ISO 27001 certification
What is ISO 27001 certification?
Increasing pressure from regulators, clients and the public for better assurances about the way in which organisations manage confidential and sensitive data has resulted in rapid growth of certification to ISO 27001– especially in the UK (which ranks second in the world).
ISO 27001 is the international standard that lays out the specifications for implementing an ISMS (information security management system). An ISMS can be audited by an independent CB (certification body) as a way to assess whether it conforms to the requirements of the Standard.
Prepare for certification
How long does ISO 27001 certification last?
Once certification is granted it is valid for three years, although the ISMS will need to be managed and maintained throughout that period. Auditors from the CB will continue to conduct surveillance visits every year while the certification is valid.
Advantages of ISO 27001 certification
Although many organisations use ISO 27001 as a framework for information security best practice, organisations may prefer not to get certified at all, or postpone the certification process. There are, however, numerous benefits to achieving certification. Many organisations opt for certification because of client or contractual requirements.
Explore the benefits of achieving ISO 27001 certification
Learn more about the benefits of ISO 27001 certification in our free green paper: Information Security & ISO 27001: An introduction
The steps to ISO 27001 certification
Organisations that have identified that they need ISO 27001 certification often come to us for advice about what to do first. There are a number of options, depending on your budget, timeframe and resource availability.
We’ve outlined the basic recommended routes in a helpful guide: Download the steps to ISO 27001 certification (PDF) now.
The ISO 27001 certification process
Once you are ready for certification, you will need to engage the services of an independent, accredited CB. These CBs have been assessed by the relevant national authority based on their competence, impartiality and performance capability through a rigorous assessment process. Read more about the importance of accredited certification.
The certification process consists of two stages and is conducted by a qualified auditor.
The auditor will review your documentation to check that the ISMS has been developed in accordance with the Standard. You will be expected to present evidence of all key aspects of the ISMS, but how much depends on the CB’s requirements.
If you pass the first stage, the auditor will conduct a more thorough assessment. This will involve reviewing the actual activities that support the development of the ISMS. The auditor will analyse your policies and procedures in greater depth, and review how the ISMS works in practice, with an on-site investigation. The auditor will also interview key members of staff to verify that all activities are undertaken in accordance with the specifications of ISO 27001.
If you are considering tackling an ISO 27001 project, read more about how to go about it and our resources that can help you here.
ISO 27001 certification costs
Certification costs usually depend on the number of employees working for the organisation. Certification for an organisation with up to 500 employees could cost in the region of £10,500. Our ISO 27001 Global Report provides further information on what organisations usually pay and whether they think ISO 27001 certification is worth it.
Take a look at our table of ISO 27001 certification costs for further guidance.
Can you get certified to ISO 27001 with IT Governance?
IT Governance is not a CB. Instead, we specialise in helping organisations like yours to fully prepare for certification. We do this by providing any combination of training, consultancy, tools, books and advice, so that you are ready by the time you engage a CB.
We support the concept of independent, accredited certification, which means that we do not audit our own work. For the same reason, CBs are not permitted to provide consultancy and advice to their clients before conducting a certification audit.
Through our years of experience assisting more than 600 organisations with ISO 27001 implementation and certification projects, we know exactly what CBs expect. As a result, we can offer you unrivalled advice and expertise on how to achieve certification with a certification guarantee.
Download our consultancy brochure here.
More reasons to use IT Governance
- Our implementation methodology has been honed over more than 15 years.
- We are known as the global authority on ISO 27001 – our management team led the world’s first ISO 27001 (formerly known as BS 7799) certification project.
- We offer everything you need to implement an ISO 27001-compliant ISMS – you don’t need to go anywhere else.
- We guarantee certification (provided you follow our advice!).
- We have trained more than 7,000 professionals on ISO 27001 implementations and audits worldwide and helped more than 600 consultancy clients achieve certification to and/or compliance with ISO 27001.
- Our technical expertise, combined with our management system standards track record, puts us in a different class to other consultancy providers.
- Our pricing and proposals are completely transparent, so you won’t get any surprises.
- We can help small organisations prepare for ISO 27001 certification in just three months.
Ready for ISO 27001 certification? Let’s get started
Contact one of our account managers today, who can talk you through various options to get started. You may also want to consider discussing a gap analysis.