ISO 27001 Certification: Complete Implementation Guide for Your Business

1. Introduction
ISO 27001 certification is the international recognition that proves an organization manages information security systematically through an Information Security Management System (ISMS). For a company that wants to sell to large clients, bid for international projects or simply prove that it takes cybersecurity seriously, ISO 27001 certification has become an almost indispensable competitive advantage.
In this guide we explain what ISO 27001 certification involves step by step: the ISMS model, Annex A and the statement of applicability, the implementation phases, the certification audit process and the real costs and timelines. If your company is considering this project, Jaymon Security supports organizations on the road to ISO 27001 certification, from the initial analysis to the preparation of external audits.
2. What the ISMS is and what ISO 27001 requires
ISO 27001 is an international standard, maintained by ISO/IEC JTC 1/SC 27, that specifies the requirements for establishing, implementing, maintaining and improving an ISMS. Its strength lies in the fact that it does not prescribe technology: it requires a management system in the style of ISO 9001 (plan, do, check, act), with an information security risk analysis driving the decisions.
The structure of the standard is divided into mandatory clauses, from 4 to 10: context of the organization, leadership, planning (including risk treatment), support, operation, performance evaluation and improvement. These clauses are complemented by Annex A, a catalogue of controls that the organization must review and select with justification.
2.1. The ISMS context in ISO 27001 certification
The first step towards ISO 27001 certification is understanding the context: which interested parties affect the organization, what their requirements are and what is included or excluded in the ISMS scope. Defining the scope is a strategic decision: an overly broad scope makes the project more expensive; an overly narrow one can reduce the commercial value of the ISO 27001 certification. The usual approach is to start with the area that brings the most value, such as the services offered to large or regulated clients.
Why do companies make this investment? For three complementary reasons: the contractual requirement (many large and regulated clients demand the certificate to sign), the commercial advantage (the certificate opens tenders and agreements where otherwise you would not even be considered) and the operational improvement (the ISMS reduces incidents, disciplines suppliers and orders the change process). The three reasons usually combine, and it is wise to define them at the start of the project because they determine the scope, the budget and the urgency of the ISO 27001 certification.
3. Annex A and the statement of applicability
Annex A of the standard is the control list that serves as the reference for the ISMS. In the 2013 version there were 114 controls grouped into 14 domains; the 2022 version reorganized them into 93 controls and 4 main themes. The following table summarizes the mapping between both versions, a critical point for organizations migrating their ISO 27001 certification.
| Annex A ISO 27001:2013 (domains) | Annex A ISO 27001:2022 (themes) |
|---|---|
| Information security organization, asset management, access control, cryptography, physical and environmental security, operational security, acquisition of systems, supplier relations, compliance | Organizational controls (37) |
| Human resource security | People controls (8) |
| Physical and environmental security | Physical controls (14) |
| Operational security, communications, acquisition, development and maintenance of systems | Technological controls (34) |
The organization must produce its statement of applicability (SoA): the document that justifies, control by control, whether each Annex A control applies or not and how it is implemented. The SoA is the most audited documentary evidence in the ISO 27001 certification process. It is also mandatory under clause 6.1.3 of the standard: without it, the ISMS lacks the traceability between risks, controls and implementation status that auditors review first during ISO 27001 certification. An extract could look like this:
STATEMENT OF APPLICABILITY (extract)
------------------------------------
A.5.1 Information security policies APPLIES (corporate policy v3.1)
A.5.15 Access control APPLIES (access policy, RBAC)
A.7.7 Remote working APPLIES (remote working guide 2026)
A.8.5 Secure authentication APPLIES (MFA on all access)
A.5.11 Return of assets NOT APPLICABLE (no asset reuse)
Justification: system aligned with ISO 27001:2022
Fig. 1 – Extract of a statement of applicability for ISO 27001 certification.
The statement of applicability must be reviewed periodically and whenever the environment changes: new technology, new site, new services or new legal requirements. A widespread mistake is freezing the SoA after ISO 27001 certification; surveillance auditors expect to see justified changes, not a static copy of the first year. Document every review with date, reasons and approval of the ISMS owner.
4. ISMS implementation phases
ISMS implementation usually follows a 6 to 12 month project. The following table summarizes the typical roadmap towards ISO 27001 certification, with the activities and duration of each phase.
| Phase | Key activities | Duration |
|---|---|---|
| 1. Initial analysis | Gap analysis, scope, identification of requirements | 3-4 weeks |
| 2. ISMS design | Policies, risk analysis, treatment and SoA | 6-8 weeks |
| 3. Implementation | Control deployment, procedures, training | 3-6 months |
| 4. Internal audit | Internal audit and management review | 3-4 weeks |
| 5. Certification | Stage 1 audit, stage 2 audit and certificate | 6-10 weeks |
The key to this phase is the risk analysis: the standard requires documenting the methodology, the risk acceptance criteria and the treatment plan. Organizations that outsource this work usually do it well; those that improvise discover during the stage 2 audit that their ISMS is a set of documents with no real relationship to the risks.
Although the roadmap looks linear, ISMS implementation requires keeping three fronts in parallel: the documentation (policy and procedures), the real operation of the selected controls and staff awareness. ISO 27001 certification is not achieved with documents alone: auditors ask employees about their responsibilities and verify that training has been delivered and recorded. That is why an ISMS owner with real dedication and a security committee that periodically reviews the project status should be appointed from the beginning.
5. The ISO 27001 certification process: stage 1 and stage 2 audits
ISO 27001 certification is granted by an accredited certification body (in Spain, usually accredited by ENAC), which performs a two-stage process. Stage 1 is a documentation and preparation review: it verifies that the SoA exists, that the risk analysis is sound and that the ISMS is ready for in-depth auditing. Stage 2 is the on-site audit: the auditors check the real operation of the system, interview staff and review evidence of the selected controls.
If the stage 2 audit detects non-conformities, the organization has a deadline to correct them before the certificate is issued or conditioned. Afterwards, the certificate is valid for three years, with annual surveillance audits and a renewal audit at the end of the cycle. Maintaining ISO 27001 certification requires the same discipline as achieving it: auditors pay special attention to whether continuous improvement is real or merely documentary.
In practice, the surveillance audits are where most certificates fail or are restricted: organizations let the ISMS drift, forget periodic internal audits or stop reviewing risks. A pragmatic recommendation is to plan the internal audit calendar for the whole three-year cycle at the moment of certification, so that the annual surveillance audits always find an up-to-date system behind the ISO 27001 certification.
6. Costs, timelines and common mistakes
The cost of ISO 27001 certification depends on the scope, the number of employees and the previous maturity. As a reference, a complete project for a company of 50 to 150 employees usually costs between 15,000 and 40,000 euros including consulting, and certification with annual surveillance audits adds between 6,000 and 15,000 euros per year. Realistic timelines are 9 to 15 months from start to certificate.
The three most common mistakes that delay ISO 27001 certification are: starting to document without doing the risk analysis, defining an unrealistic scope, and contracting certification without prior consulting under the false expectation that the certification body will “help” you comply (it will not: it certifies). You should also distrust express ISO 27001 certification offers: no serious management system is implemented in two months, and the same applies to surveillance audits: treat them as quality gates, not as threats.
To choose a certification body, check that it is accredited by ENAC or another member of EA (European co-operation for Accreditation), request proposals from two or three bodies with references in your sector and review the available audit schedule. The ISO 27001 certification body must not advise you during implementation: the separation between consulting and certification is a requirement of impartiality. If they offer the combined package, get the independence of the team confirmed in writing.
7. Conclusion
ISO 27001 certification is a demanding project but with clear returns: access to international tenders, trust from clients and suppliers, and an orderly, measurable security management. The path goes through a real ISMS, an honest risk analysis and a justified statement of applicability, not through accumulating templates. If your organization wants to move forward, remember that ISO 27001 certification is not the finish line: it is the start of a continuous improvement cycle that turns security into a business capability. If you start now, plan the project with margin for the unexpected: the most common delays are not in technology, but in the availability of the key people.
Related articles: the value of ISO 27000 series certification for your company and the ISMS PDCA cycle in audit and certification.
To go deeper, consult the official documentation of ISO 27001 on iso.org, the accredited bodies of ENAC and the guides of CCN-CERT.
If you are considering this project, Jaymon Security helps companies prepare for and pass the process towards ISO 27001 certification with a pragmatic approach and results oriented towards auditable evidence.
Need help with ISO 27001 certification?
At Jaymon Security, we help organizations protect their systems. From security audits to SIEM/SOC implementation, our expert team designs custom solutions.
Contact us for a free infrastructure assessment.

