An ISO 27001 project involves management, IT, HR, procurement and day-to-day operations. Use these steps to agree an owner, outcome and decision point for each stage. Start with the ISO 27001 guide if you are still deciding whether the standard fits your customers' requirements.
1. Define the purpose, scope and ownership
Record the customer requirement or organisational objective behind the project. Then describe the services, locations, systems, teams and suppliers within scope. A certificate should clearly correspond to the services a customer receives.
Management should set the direction, resources and responsibilities. Appoint one coordinator, but assign substantive actions to the people who know the processes. The result is a defined project with decision-makers and allocated time.
2. Compare current practices with the standard
Identify what already works and what is missing. During the initial assessment, look at both implementation and evidence: a written procedure without an owner or records is not yet a demonstrably effective process. Use ISO/IEC 27001:2022 and the applicable amendments as your reference. View the official ISO publication.
Assess risks using consistent criteria, select controls and record who approves the treatment and residual risks. Connect the risk assessment, treatment plan and Statement of Applicability. These are interrelated elements, not separate form-filling exercises. BSI explains these connections in its self-assessment.
Turn the findings into an action list with priorities, owners and the evidence required. This shows which actions need attention first and which depend on a supplier or management decision.
3. Develop controls and gather evidence
For each control, agree what someone will do, how often and where the result will be kept. Reuse existing records, such as tickets, HR arrangements and supplier assessments. Do not store sensitive customer data in a generally accessible audit file.
Practical parts of the evidence file include the scope, policies, risk assessment, treatment plan, Statement of Applicability and records of checks. The ISO 27001 checklist helps you record the owner, status and evidence for each part.
4. Assess internally and discuss the findings
Plan an internal audit and management review. The internal audit should examine design and operation; record findings and follow-up. Management reviews the results and decides on the improvements and resources needed. These activities form part of the recurring evaluation of the ISMS. See chapters 9 and 10 of the BSI implementation guide.
Ensure the auditor can assess objectively and does not audit their own implementation work. Explore our internal audit support and agree the scope, independence, reporting and follow-up in advance. An internal audit does not provide a certificate.
5. Obtain independent certification and maintain the system
A certification audit has two stages. Stage 1 assesses the system's design and readiness; stage 2 examines implementation and evidence. Agree with the certification body which records and interviewees are needed. BSI describes the certification process.
The certification body decides on the certificate; DCA and ISO itself do not. Check whether the body is accredited for the intended standard and scope. ISO explains certification and accreditation. Find the body in the RvA register.
After the audit, plan follow-up of findings, periodic checks and future audits. Certification is not the endpoint of managing the system. Keep changes to services, systems and suppliers within normal working arrangements.
How much internal time and support are needed?
There is no reliable standard number of internal hours for every organisation. Budget time for interviews, gathering information, adapting processes, implementing controls, checks and decision-making. Allocate this across the coordinator, management and process owners. Also allow time for remedial actions.
DCA can support the initial assessment, planning, development and audit preparation, or carry out agreed implementation work. You provide organisational knowledge, carry out the agreed actions and remain responsible for formal decisions. Record the allocation for each work package as part of implementation support.
Support starts at 4 hours per week, at rates from €120 per hour: an average of €2,080 per month excluding VAT. Software, internal hours and external certification are separate budget items. See the prices and calculator and the ISO 27001 cost breakdown.
Frequently asked questions
Which documents should you prepare?+
Start with the scope, policies, risk assessment, treatment plan and Statement of Applicability. Add evidence of implementation, internal audits, management review and improvement actions. The standard and your scope determine the further detail required.
How long does ISO 27001 certification take?+
The duration depends on your starting point, scope, internal capacity and improvements. Plan after an initial assessment and agree audit availability with the certification body; support does not include a guaranteed completion time.
Who decides on the certificate?+
An independent certification body assesses the ISMS and decides on certification. DCA supports preparation and the delivery of agreed work.
Sources for this article
- ISO: ISO/IEC 27001:2022 and amendmentsAccessed on 19 September 2026
- BSI: ISO/IEC 27001:2022 implementation guideAccessed on 19 September 2026
- BSI: ISMS self-assessmentAccessed on 19 September 2026
- BSI: certification processAccessed on 19 September 2026
- ISO: certification and accreditationAccessed on 19 September 2026
- Dutch Accreditation Council (RvA): accredited bodiesAccessed on 19 September 2026
Explore this topic further
This is general guidance and does not replace an assessment of your situation or the official standard.

