What are you actually certifying?

ISO/IEC 27001 is about how an organisation manages information security. The scope matters: a particular service or entity being certified does not automatically cover everything the company does. ISO publishes the standard; independent certification bodies carry out certification.

Before choosing a date, explain why you need it, what will be included and who can make decisions. A customer deadline can start the conversation. It cannot supply the missing people, time or operating evidence.

Prepare things you can show

My starting folder would contain a clear perimeter, the important systems and information, named owners, the main risks and what the team is doing about them. Then actual examples: access reviews, a leaver’s access being removed, a recovery test, a supplier assessment, an incident handled and followed up.

A simple test: take one written rule and ask someone to walk through the last time they used it. If the document says monthly reviews but nobody can find one, the useful job is fixing the practice. Renaming the document “final-v7-approved” will not help.

Leave room to find problems

Plan an internal audit, management review and time to address the gaps before the certification assessment. Use the applicable standard and a qualified practitioner to check the full requirements, including the risk treatment plan and statement of applicability. This note is a preparation route, not an exhaustive compliance checklist.

The goal is not to perform security for a visiting auditor. It is to have a way of working that survives a busy month, a new starter and a real incident. A certificate can provide assurance about that management system. It does not make an organisation unhackable.

Further reading