Getting certified to ISO 27001 means passing a two-stage certification audit with an accredited certification body, preceded by your own internal audit, and followed by annual surveillance audits. Here’s how the process works and how to prepare.

Start with your own internal audit
Before the certification body arrives, ISO 27001 requires you to run your own internal audit (clause 9.2) across the whole system, followed by a management review. This is your dress rehearsal. An independent internal audit finds the gaps before the external auditor does, which is the single best way to avoid surprises at certification.
Stage 1: the readiness review
Stage 1 is mostly a documentation review. The auditor checks that your ISMS is designed correctly: your scope, information security policy, risk assessment and treatment, Statement of Applicability, and evidence that internal audit and management review have happened. They’re confirming you’re ready for Stage 2 and flagging anything that needs fixing first.
Stage 2: the implementation audit
Stage 2 is the main event. The auditor tests whether your system is actually implemented and effective, not just documented. They’ll sample records, interview staff, and check that your selected controls are operating in practice. Any gaps are raised as nonconformities (minor or major), which you close out before the certificate is issued.
Surveillance and recertification
Certification lasts three years, with annual surveillance audits to confirm you’re maintaining the system, and a full recertification audit at the end of the cycle. Keeping your internal audits, management reviews and records current through the year is what keeps surveillance audits painless.
How to prepare, and common nonconformities
The issues that most often trip organisations up are a Statement of Applicability that doesn’t match reality, risk assessments that aren’t kept up to date, missing or superficial internal audits, and controls that exist on paper but generate no records. Prepare by making sure every selected control produces evidence, your internal audit covers the whole system, and your management review is genuine rather than a formality. A gap analysis beforehand is the cheapest way to find these issues early.
Frequently asked questions
How long does ISO 27001 certification take?
For most small to mid-sized organisations, three to six months from starting the system to passing Stage 2, depending on how much is already in place. See our cost and timeline guide for details.
Who can certify us?
An accredited certification body. We’re independent of the certifier, so we prepare you for the audit and can recommend appropriately accredited bodies, but we don’t mark our own homework.
Speak with an experienced ISO auditor
Preparing for an ISO 27001 audit? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











