Subject: the ISO/IEC 27001 certification arc, end to end

They will tell you what the standard requires. They will sell you a platform that tracks what the standard requires. Then you sit in your first Stage 2 interview, an auditor asks one of your engineers to walk through how a change reaches production, and you realise none of that prepared either of you for the room.
So we wrote the guide we wanted on our first one. It is called What to Expect When You’re Expecting an ISO 27001 Audit, it is 26 illustrated pages, and yes, it is shaped like a pregnancy guide.
Why we wrote it
The joke is load-bearing. Both processes run about a year. Both involve strangers reading your documents. Both are full of appointments with professionals who use vocabulary nobody explained. And both are enormously improved by someone telling you which of the alarming things are normal.
That last part is the whole point. The standard is nineteen pages of careful, joyless prose describing what must be true without ever describing what will happen to you. The gap between those two things is where every first certification gets painful, and it is a gap nobody writes for.
The one idea
A gap found at Stage 1 is routine. The same gap found at Stage 2 is a nonconformity.
Same finding. Same words in the same report. Routine part of the process, or the thing standing between you and a certificate, depending almost entirely on when it turns up.
Stage 1 is a documentation review: the certification body is checking whether your management system is designed. Stage 2 evaluates implementation, including effectiveness, which means the auditor stops reading about the system and starts testing whether it ran. Most of the painful outcomes we have watched are not security problems. They are right-thing-at-the-wrong-moment problems.
The thing you cannot fake
At Stage 2 your auditor picks a period, pulls a sample of records from it, and traces each one end to end. Access reviews, change approvals, incident tickets, joiners and leavers, supplier reviews, backups.
Which means a control that started operating three weeks ago has three weeks of evidence. No document, no policy quality and no explanation makes an auditor sample a period that does not exist. Operating history is the one input you cannot create retrospectively, and it is the reason the gap between Stage 1 and Stage 2 matters more than almost any decision you make inside it.
What surveillance actually checks
The certificate runs three years, with a surveillance audit in year one, another in year two, and recertification in year three. The common assumption is that surveillance is where effectiveness finally gets tested. It is not. Stage 2 already did that. The difference is the period: Stage 2 judged you on the months you had, with a deadline in the room making everyone careful, and surveillance judges a whole year in which nobody was watching.
Alongside a rotating subset of controls, ISO/IEC 17021-1 clause 9.6.2.2 sets a fixed list that gets covered every time: internal audits and management review, the actions you took on the previous audit’s nonconformities, complaints handling, whether the system is achieving the objectives you set for it, progress on continual improvement, continuing operational control, any changes, and correct use of the certification mark.
Most of that list is the management system rather than the individual controls, which is the opposite of where most teams put their preparation. The controls still get sampled, so this is a reason to prepare for both rather than a reason to relax about the technical half.
What’s inside
Five phases, each running the same shape: what is happening, what you may be feeling, what your auditor is actually doing, the questions you are too embarrassed to ask, and the one thing per phase serious enough to stop and deal with.
- Conception. Standing up the ISMS. Scope, policy, risk method and the Statement of Applicability, in the one phase nobody is watching.
- The First Scan. The internal audit. What Clause 9.2 actually requires, and why independence is not a formality.
- The Twelve-Week Appointment. Stage 1, the documentation review, and why most of it is spent away from the 93 Annex A controls.
- Delivery. Stage 2. Sampling, evidence, what your engineers will be asked, and what a major nonconformity really costs.
- The Fourth Trimester. Certification, surveillance, and the quiet administrative drift that follows a deadline being removed.
It is written for the person inside the organisation who owns the programme. Usually someone who volunteered, inherited it, or was in the wrong meeting.


