Skip to content
atlas

Certification

Also known as: ISO 27001 certification

Formal proof from an approved outside body that an organisation's security meets a published standard such as ISO 27001.

Draft - this entry has not been reviewed yet.

Formal

A certificate issued by an officially approved certification body after an outside audit in two stages shows that an ISMS meets every requirement of ISO 27001; it runs for three years, kept alive by yearly follow-up audits. ISO 27002 is guidance only and cannot be certified against.

In plain English

Like a driving test - you may already drive carefully, but only the examiner's pass gives you a licence that strangers will trust.

In practice

Several municipalities require ISO 27001 certification in a tender for hosting their case systems, so a Danish hosting company books a certification body, passes both audit stages and attaches the certificate to its bid.

Why it matters

Customers cannot inspect every supplier themselves, so they rely on the certificate - but it proves that a working system exists, not that a breach cannot happen.

Technical deep dive

ISMS certification rests on a three-layer conformity assessment chain. ISO does not certify anyone. National accreditation bodies, operating under ISO/IEC 17011 and in Europe under Regulation (EC) 765/2008 (in Denmark DANAK), accredit certification bodies; the certification bodies audit and certify organisations. A certification body for ISO/IEC 27001 must meet ISO/IEC 17021-1:2015, the generic requirements for bodies certifying management systems, plus ISO/IEC 27006-1:2024, which adds ISMS-specific rules on auditor competence, audit time and the audit process. Accredited certificates are recognised internationally through the IAF Multilateral Recognition Arrangement; certificates from unaccredited bodies are legal but carry little weight in tenders and supplier assessments.

Initial certification is a two-stage audit. Stage 1 reviews the ISMS documentation, scope, risk assessment and Statement of Applicability and evaluates readiness, including whether internal audit and management review have been performed. Stage 2, normally on-site or partly remote, tests whether the ISMS is implemented and effective by sampling evidence across clauses 4-10 and the Annex A controls declared applicable. Audit time is calculated from tables in ISO/IEC 27006-1 based mainly on the number of persons doing work under the organisation's control, adjusted for complexity and the number of sites. Major nonconformities must be corrected and verified before the certificate is issued; minor ones need an accepted corrective action plan.

The certificate is valid for three years. Surveillance audits take place at least annually, the first within twelve months of the certification decision, and each covers a subset of the ISMS plus fixed items such as internal audit, management review, corrective actions and use of the certification mark. A recertification audit before expiry starts a new cycle. Serious findings in a surveillance audit can lead to suspension or withdrawal. The 2013 edition could no longer be certified after 31 October 2025, so current certificates are against ISO/IEC 27001:2022.

The most important thing to read on a certificate is its scope. An organisation can certify a single data centre, product line or department, so a supplier's certificate may not cover the service actually purchased; the certificate should also reference the version of the SoA. Certification of an ISMS is also different from certification of persons under ISO/IEC 17024 (for example lead auditor credentials), from product certification such as Common Criteria or the EU EUCC scheme under the Cybersecurity Act, and from assurance reports such as ISAE 3402 or SOC 2, which describe control operation over a period rather than conformity to a management-system standard. Likewise, NIS2 Art. 24 lets member states require ICT products, services or processes certified under European cybersecurity certification schemes; it does not concern ISO 27001 certification of the entity itself.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Compliance
  3. →Security policy
  4. →Threat
  5. →Asset
  6. →Audit
  7. →Vulnerability
  8. →Impact
  9. →Likelihood
  10. →Risk
  11. →Risk management
  12. →Information security management system (ISMS)
  13. →Certification

Relationships

Don't confuse with
Compliance
Used with
ISO 27001

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022 - Information security management systems - Requirements · ISO/IEC
  • ISO/IEC 27006-1:2024 - Requirements for bodies providing audit and certification of ISMS · ISO/IEC

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.