Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
/var/www/traztech.ca/html/blog/post.php on line 12748
22; color:
Warning: Undefined array key "Compliance" in /var/www/traztech.ca/html/blog/post.php on line 12748
;">Compliance

How to Get ISO 27001: A Step-by-Step Guide

ISO 27001 certification proves to customers, regulators, and partners that your information security management system (ISMS) meets an internationally recognized standard. For Canadian companies selling into Europe, the UK, or other markets where ISO 27001 is the default ask, it opens doors that a SOC 2 report alone doesn't. But the path from "we need this" to a certificate in hand is longer and more procedural than most teams expect. Here's what it actually looks like, step by step.

Step 1: Scope the ISMS

Before you touch a single control, decide what's actually being certified. Is it one product, one business unit, or the whole company? Getting the scope right matters more than people think: too broad and you're documenting systems that have nothing to do with your customer's risk; too narrow and the certificate doesn't cover what your sales team is promising in contracts.

This step also includes a context and stakeholder analysis, which sounds bureaucratic but is really just answering: who relies on our data being secure, and what do they expect from us? Get this on paper early because auditors will ask for it.

Step 2: Run a gap assessment

ISO 27001's Annex A lists 93 controls across organizational, people, physical, and technological categories. Most companies starting from scratch have some of these already, informally, through existing IT and security practices. A gap assessment maps what you have against what the standard requires and tells you honestly how far away you are.

This is the step where a lot of Canadian companies underestimate the work. Having a firewall and an access control policy isn't the same as having a documented, repeatable, audited process for managing them. The gap assessment is also where you'll flag Canadian-specific overlap: if you handle personal information, your ISMS needs to account for PIPEDA obligations, and if you operate in or sell to Quebec, Law 25's stricter consent and breach notification requirements need to be built into your policies, not bolted on afterward.

Step 3: Conduct a formal risk assessment

ISO 27001 is built around risk management, not a fixed checklist. You need to identify information security risks (data breach, insider threat, vendor compromise, and so on), assess their likelihood and impact, and decide how you'll treat each one: mitigate, accept, transfer, or avoid.

The output is a risk treatment plan and a Statement of Applicability (SoA), which lists every Annex A control and whether it applies to you, and if not, why. The SoA is one of the first documents an auditor will read, so it needs to hold up to scrutiny.

Step 4: Build and implement your controls

This is the longest phase. For each applicable control, you need a documented policy, an implemented process, and evidence that it's actually being followed. Typical work here includes:

  • Access control and identity management policies, enforced technically, not just written down
  • Asset inventory and classification
  • Vendor and third-party risk management
  • Incident response and business continuity plans
  • Security awareness training for staff
  • Logging, monitoring, and change management procedures

Most teams find the documentation burden heavier than the technical work. ISO 27001 wants a mandatory set of documents (policy, scope, risk assessment, SoA, risk treatment plan, objectives, and more), and each one needs version control and management approval, which is where a lot of first-time efforts stall out.

Step 5: Run internal audits and a management review

Before you bring in an external certification body, ISO 27001 requires you to audit yourself. An internal audit checks whether the ISMS is actually operating the way your documentation says it does, and it has to be done by someone independent of the process being audited (which is why smaller teams often bring in outside help for this step).

Findings from the internal audit feed into a formal management review, where leadership signs off on the state of the ISMS and commits resources to fix anything that's broken. Skipping or rushing this step is one of the most common reasons companies fail their external audit.

Step 6: Stage 1 and Stage 2 external audits

Certification happens through an accredited certification body, not through traztech or any consultant, we can prepare you for it but we can't issue the certificate ourselves.

The external audit happens in two stages:

  • Stage 1 is a documentation review. The auditor checks that your ISMS documentation is complete and that you're ready for a full assessment. This usually surfaces gaps you'll want to close before Stage 2.
  • Stage 2 is the real test. The auditor interviews staff, reviews evidence, and confirms controls are operating as documented, over a period of time, not just on the day of the audit. This is why you typically need three to six months of operating evidence before Stage 2 can even be scheduled.

Pass both stages and the certification body issues your ISO 27001 certificate, valid for three years, with surveillance audits (lighter-touch check-ins) required annually to keep it active.

Realistic timelines

For a company starting with little to no formal security program, six to twelve months from kickoff to certificate is a realistic range. Companies that already run a mature security function with documented policies can sometimes compress this to four to six months. The variables that move the timeline most are how much of the risk assessment and documentation work is starting from zero, how many locations or product lines are in scope, and how fast leadership can commit time to reviews and sign-offs.

Rushing the process rarely pays off. Certification bodies will fail a Stage 2 audit if there isn't enough operating history to demonstrate controls are actually working, not just written down.

Where a partner actually helps

Most of the delay in ISO 27001 projects isn't technical, it's process: knowing what the auditor actually wants to see, avoiding rework on documentation that gets rejected at Stage 1, and running the internal audit independently instead of having a team member mark their own homework. An experienced readiness partner has been through the certification body's process enough times to know where companies typically stumble, and can run the gap assessment, risk assessment, and documentation build in parallel with your team instead of in sequence.

For Canadian companies specifically, having someone who already understands how PIPEDA and, where relevant, Quebec's Law 25 map onto ISO 27001's control set saves you from building two separate compliance programs that should really be one. Our ISO 27001 implementation service is built around exactly this: readiness work that gets you to a clean Stage 2 audit without carrying documentation debt into year two. It sits alongside our broader compliance advisory work for companies juggling ISO 27001 against SOC 2, PIPEDA, or other frameworks at the same time.

Ready to start?

If you're weighing ISO 27001 against SOC 2, or trying to figure out how much of your existing security work already counts toward certification, talk to us before you commit budget to a certification body. Get in touch and we'll walk through your scope, timeline, and where the real gaps are.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on the unglamorous side of building a startup. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation