ISO 27001 certification proves to customers, regulators, and partners that your information security management system (ISMS) meets an internationally recognized standard. For Canadian companies selling into Europe, the UK, or other markets where ISO 27001 is the default ask, it opens doors that a SOC 2 report alone doesn't. But the path from "we need this" to a certificate in hand is longer and more procedural than most teams expect. Here's what it actually looks like, step by step.
Step 1: Scope the ISMS
Before you touch a single control, decide what's actually being certified. Is it one product, one business unit, or the whole company? Getting the scope right matters more than people think: too broad and you're documenting systems that have nothing to do with your customer's risk; too narrow and the certificate doesn't cover what your sales team is promising in contracts.
This step also includes a context and stakeholder analysis, which sounds bureaucratic but is really just answering: who relies on our data being secure, and what do they expect from us? Get this on paper early because auditors will ask for it.
Step 2: Run a gap assessment
ISO 27001's Annex A lists 93 controls across organizational, people, physical, and technological categories. Most companies starting from scratch have some of these already, informally, through existing IT and security practices. A gap assessment maps what you have against what the standard requires and tells you honestly how far away you are.
This is the step where a lot of Canadian companies underestimate the work. Having a firewall and an access control policy isn't the same as having a documented, repeatable, audited process for managing them. The gap assessment is also where you'll flag Canadian-specific overlap: if you handle personal information, your ISMS needs to account for PIPEDA obligations, and if you operate in or sell to Quebec, Law 25's stricter consent and breach notification requirements need to be built into your policies, not bolted on afterward.
Step 3: Conduct a formal risk assessment
ISO 27001 is built around risk management, not a fixed checklist. You need to identify information security risks (data breach, insider threat, vendor compromise, and so on), assess their likelihood and impact, and decide how you'll treat each one: mitigate, accept, transfer, or avoid.
The output is a risk treatment plan and a Statement of Applicability (SoA), which lists every Annex A control and whether it applies to you, and if not, why. The SoA is one of the first documents an auditor will read, so it needs to hold up to scrutiny.
Step 4: Build and implement your controls
This is the longest phase. For each applicable control, you need a documented policy, an implemented process, and evidence that it's actually being followed. Typical work here includes:
- Access control and identity management policies, enforced technically, not just written down
- Asset inventory and classification
- Vendor and third-party risk management
- Incident response and business continuity plans
- Security awareness training for staff
- Logging, monitoring, and change management procedures
Most teams find the documentation burden heavier than the technical work. ISO 27001 wants a mandatory set of documents (policy, scope, risk assessment, SoA, risk treatment plan, objectives, and more), and each one needs version control and management approval, which is where a lot of first-time efforts stall out.
Step 5: Run internal audits and a management review
Before you bring in an external certification body, ISO 27001 requires you to audit yourself. An internal audit checks whether the ISMS is actually operating the way your documentation says it does, and it has to be done by someone independent of the process being audited (which is why smaller teams often bring in outside help for this step).
Findings from the internal audit feed into a formal management review, where leadership signs off on the state of the ISMS and commits resources to fix anything that's broken. Skipping or rushing this step is one of the most common reasons companies fail their external audit.
Step 6: Stage 1 and Stage 2 external audits
Certification happens through an accredited certification body, not through traztech or any consultant, we can prepare you for it but we can't issue the certificate ourselves.
The external audit happens in two stages:
- Stage 1 is a documentation review. The auditor checks that your ISMS documentation is complete and that you're ready for a full assessment. This usually surfaces gaps you'll want to close before Stage 2.
- Stage 2 is the real test. The auditor interviews staff, reviews evidence, and confirms controls are operating as documented, over a period of time, not just on the day of the audit. This is why you typically need three to six months of operating evidence before Stage 2 can even be scheduled.
Pass both stages and the certification body issues your ISO 27001 certificate, valid for three years, with surveillance audits (lighter-touch check-ins) required annually to keep it active.
Realistic timelines
For a company starting with little to no formal security program, six to twelve months from kickoff to certificate is a realistic range. Companies that already run a mature security function with documented policies can sometimes compress this to four to six months. The variables that move the timeline most are how much of the risk assessment and documentation work is starting from zero, how many locations or product lines are in scope, and how fast leadership can commit time to reviews and sign-offs.
Rushing the process rarely pays off. Certification bodies will fail a Stage 2 audit if there isn't enough operating history to demonstrate controls are actually working, not just written down.
Where a partner actually helps
Most of the delay in ISO 27001 projects isn't technical, it's process: knowing what the auditor actually wants to see, avoiding rework on documentation that gets rejected at Stage 1, and running the internal audit independently instead of having a team member mark their own homework. An experienced readiness partner has been through the certification body's process enough times to know where companies typically stumble, and can run the gap assessment, risk assessment, and documentation build in parallel with your team instead of in sequence.
For Canadian companies specifically, having someone who already understands how PIPEDA and, where relevant, Quebec's Law 25 map onto ISO 27001's control set saves you from building two separate compliance programs that should really be one. Our ISO 27001 implementation service is built around exactly this: readiness work that gets you to a clean Stage 2 audit without carrying documentation debt into year two. It sits alongside our broader compliance advisory work for companies juggling ISO 27001 against SOC 2, PIPEDA, or other frameworks at the same time.
Ready to start?
If you're weighing ISO 27001 against SOC 2, or trying to figure out how much of your existing security work already counts toward certification, talk to us before you commit budget to a certification body. Get in touch and we'll walk through your scope, timeline, and where the real gaps are.
Choosing a certification body, and the accreditation trap
The certification body you pick determines whether the certificate is worth anything to your buyer. Anyone can print a document with "ISO 27001" on it. What matters is that the body issuing it is accredited by a recognized national accreditation body, and that the accreditation mark appears on the certificate itself. In Canada that is the Standards Council of Canada. In the US it is ANAB. In the UK it is UKAS. All of them are members of the International Accreditation Forum, which is why a UKAS-marked certificate is accepted by a German buyer without argument.
Unaccredited certificates are cheaper and faster, and they get rejected. We have watched a procurement team at a European buyer look up a certification body in the IAF public database, find nothing, and reopen the security review that the certificate was supposed to close. If you are certifying because a customer asked, ask that customer whether they have an approved list of certification bodies before you sign with one. Some enterprise buyers do.
The second thing to check is the audit day allocation. Certification bodies are bound by IAF MD 5, which sets minimum auditor days based on the number of people in scope and the complexity of the ISMS. A quote that is dramatically below the others usually means the body has computed fewer days than the mandatory duration table allows, and that gets caught in their own internal review or at their next accreditation surveillance. A quote that is dramatically above usually means they have counted your entire headcount rather than the personnel actually inside the ISMS scope. Both are worth challenging, in writing, before you sign.
What the 2022 revision changed, and why old templates fail
ISO/IEC 27001:2022 reorganized Annex A from 114 controls in fourteen domains down to 93 controls in four themes, and it introduced eleven controls that did not exist in the 2013 version. Those new ones are where first-time certifications now stumble, because they are the controls that nobody had a policy for already: threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
If you buy a policy template pack, check its publication date and check whether it addresses those eleven by name. Plenty of packs still circulating were written against the 2013 annex and were relabelled rather than rewritten. An auditor reading your Statement of Applicability against the 2022 control numbering will see the mismatch on the first pass, and you will spend Stage 1 rewriting documents rather than closing real gaps.
Threat intelligence, control 5.7, catches people out most often. Auditors are not asking you to buy a threat intelligence feed. They are asking how information about relevant threats reaches someone who can act on it, and what that person did with it last quarter. A documented monthly review of vendor advisories, CVE feeds relevant to your stack, and sector alerts, with dated notes and the decisions that followed, satisfies the control. An unused subscription to an expensive platform does not.
Nonconformities: what happens when Stage 2 does not go cleanly
Most companies do not fail Stage 2 outright. They receive findings, and the findings have grades. A minor nonconformity is an isolated lapse against a requirement, and you typically get 60 to 90 days to submit a root cause analysis and corrective action plan, with evidence, before the certificate is issued. A major nonconformity is a total absence of a required process, or a systemic breakdown across several instances, and it blocks the certificate until it is closed and, in some cases, until the auditor returns for a follow-up visit at your cost.
The findings we see repeat across engagements are boringly consistent. Management review minutes that do not cover every input clause 9.3 requires. An internal audit programme that audited the easy clauses and skipped the ones the company was weakest on. A risk treatment plan with owners and no dates. Access reviews performed but not evidenced, because someone eyeballed a user list in a meeting and nobody wrote down what changed. Supplier records that list vendors but hold no assessment of any of them. None of these are technical problems. All of them are the kind of thing that gets fixed in an afternoon if you know to look before the auditor does.
The corrective action write-up matters more than founders expect. Auditors are trained to reject a corrective action that only fixes the instance they found. If the finding is one missing access review, "we performed the review" is not a closure. "We performed the review, we identified that the calendar reminder was owned by someone who left, we moved ownership to a role rather than a person, and here are the three subsequent reviews" is.
Year two and year three are the part nobody budgets for
The certificate runs on a three-year cycle. Year one is the initial certification. Years two and three are surveillance audits, usually one to two days each, and they sample a subset of controls plus the mandatory clauses. Year four is recertification, which is closer in effort to the original Stage 2. Surveillance audits are lighter, but they are not lenient, and the most common reason a company gets a nonconformity in year two is that the ISMS stopped running the day the certificate arrived.
The recurring obligations are specific and dated. At least one internal audit covering the whole ISMS across the cycle. At least one management review with the clause 9.3 inputs. A refreshed risk assessment. Updated Statement of Applicability if anything in scope changed. Evidence of the operational controls running at whatever cadence you committed to in your own policies, which is why we tell clients to write "quarterly" only where they will actually do it quarterly. Your own policy is the standard the auditor holds you to. Promising monthly access reviews and delivering three a year is a self-inflicted nonconformity.
This is the work that a shared evidence workspace makes survivable. We give clients a free traztech Workspace to hold the control register, evidence, and review dates in one place, so the second-year audit is a matter of exporting what already happened rather than reconstructing it from Slack.
Cost drivers, in the order they actually move the number
Scope headcount is the biggest lever, because certification body pricing keys off personnel in scope. Reducing scope from the whole company to the product organization and the systems that support it can cut audit days meaningfully, provided the reduced scope still covers what your contracts promise. Number of physical sites is second, since each additional location can pull in extra sampling, though remote-first companies with no server rooms usually argue this down successfully. Number of distinct product lines or cloud tenancies is third. Whether you need ISO 27017, 27018, or 27701 alongside the base certificate is fourth, and those add-ons are cheaper bought in the same audit visit than bolted on a year later.
On the readiness side, the cost driver is how much of clauses 4 through 10 exists today. Annex A control work is usually less effort than teams expect, because most of the technical controls are half-built already. The management system clauses are usually more effort, because almost nobody has a documented internal audit programme, a management review cadence, or measurable information security objectives before they start. Budget your time accordingly. Our published fixed-scope pricing exists so you can see the readiness side of that number before a call rather than after.
When you should not pursue ISO 27001
If every buyer asking you hard security questions is American, ISO 27001 is probably the wrong purchase and SOC 2 is the right one. US procurement teams read SOC 2 reports fluently and often treat an ISO certificate as an unfamiliar artifact that needs explaining. Certifying to the standard your buyers do not read is an expensive way to answer a question nobody asked.
If you have one European prospect and the contract is small, ask them directly whether a completed security questionnaire, a recent penetration test report, and a documented set of policies would unblock the deal. Frequently it will, particularly below a certain contract value where their own vendor risk tiering does not demand a certificate. Certification takes six to twelve months. If the deal will not survive that, the certificate does not save it.
If you are pre-product-market-fit and the ISMS would be operated by the same two engineers who are writing the product, wait. An ISMS is a set of recurring commitments, and committing to recurring work you cannot sustain produces a certificate in year one and a nonconformity in year two. Nobody wins that trade.
And if you already employ a security lead with ISMS experience, you likely do not need an external readiness partner for the whole build. Buying an independent internal audit and a Stage 1 dry run is often the better spend, since those are the two pieces your own team structurally cannot do for itself. We are happy to be scoped that narrowly, and we would rather sell that than a full programme you do not need. If you want to talk through which of those shapes fits, get in touch and we will tell you plainly if the answer is none of them.
Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.
ISO 27001 readinessOr talk about a retainer