A Practical Guide to ISO/IEC 27001:2022 Implementation
What actually goes into building a certifiable Information Security Management System, from scoping to the certification audit.
The short version
- ISO 27001 certifies a management system, not a product. What gets audited is whether your ISMS runs, not whether your security tooling is impressive.
- Scope is the first decision and the hardest to reverse. Narrow enough to manage, broad enough that customers accept it.
- The Statement of Applicability is the document auditors scrutinize most, because it records which of the Annex A controls you applied and why you excluded the rest.
- Certification runs through two audits: Stage 1 reviews your documentation, Stage 2 tests whether the ISMS operates as documented.
What is ISO 27001 certification?
ISO/IEC 27001:2022 is an international standard for information security management. Certification means an accredited body has audited your organization and confirmed that you operate an Information Security Management System, or ISMS, meeting the standard's requirements. The distinction that trips up most first-time implementers is that ISO 27001 certifies a management system rather than a set of technical controls. An organization with modest tooling and a disciplined, well-evidenced ISMS will certify. An organization with excellent tooling and no management system will not.
Start with scope, not controls
The most common mistake in ISO 27001 projects is jumping straight to controls before the ISMS scope is defined. Your scope determines which systems, locations, and business units the certification actually covers, and it should be narrow enough to manage but broad enough to be credible to customers and auditors. A scope covering one product line and the team that builds it is defensible. A scope that excludes the systems your customers actually touch will be questioned during the sales conversations the certificate was meant to unblock.
Risk assessment drives everything else
ISO 27001 is a risk-based standard. Your risk assessment methodology, and the resulting risk treatment plan, determines which of the Annex A controls are actually relevant to your organization. This is documented in your Statement of Applicability, one of the most scrutinized documents in the certification audit. Auditors are less interested in whether you reached the same conclusions they would have, and more interested in whether your methodology is consistent, repeatable, and actually applied rather than reverse-engineered after the fact.
What changed in the 2022 revision?
The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes: organizational, people, physical, and technological. Eleven controls are new, including threat intelligence, information security for cloud services, data leakage prevention, and secure coding. Organizations certified against the 2013 version had a transition period to move across. If you are implementing for the first time, work from the 2022 structure directly and ignore the older mapping tables, which mostly add confusion.
Core documentation you'll need
- Information security policy and supporting sub-policies
- Risk assessment methodology and risk register
- Statement of Applicability (SoA)
- Risk treatment plan
- Internal audit program and records
- Management review records
- Corrective action and nonconformity records
- Evidence of competence and awareness training
How long does ISO 27001 certification take?
For a small to mid-sized organization starting without an existing management system, a first certification commonly runs somewhere in the range of six to twelve months from kickoff to the Stage 2 audit. The variables that move that number most are scope size, how much policy documentation already exists, and whether the organization can produce several months of operating evidence for controls that need it. Certification bodies generally want to see the ISMS actually running for a period before Stage 2, which sets a practical floor on the timeline regardless of how quickly you write documentation.
What does the certification path look like?
- Gap analysis against the current state of your ISMS
- Risk assessment and Statement of Applicability
- Control implementation and evidence collection
- Internal audit and management review
- Stage 1 audit (documentation review)
- Stage 2 audit (implementation review, on-site or remote)
- Surveillance audits, typically annually, with recertification on a three-year cycle
Where implementations usually go wrong
- Scope defined to be easy to certify rather than useful to customers, which surfaces later in security questionnaires
- A risk assessment written once and never revisited, so the risk register no longer matches the business
- Policies copied from a template and never reconciled with how the organization actually operates
- Internal audit treated as a formality, which means Stage 2 becomes the first real test of the ISMS
- No named owner for the ISMS after certification, so the management system decays before the first surveillance audit
Need hands-on help with this?
See how our ISO 27001 Implementation engagement works.
Ready to put this into practice?
Reading the guide is the easy part. If you want practitioners who have run these implementations to scope the work with you, start with a free consultation.