ISO 27001 certification: process in eight steps from gap analysis to re-audit
The path to ISO 27001:2022 certification can be divided into eight clearly defined steps. We show what is required in the gap analysis, scope, risk assessment, statement of applicability, stage 1 and stage 2 audit and what deadlines you should plan for.
ISO/IEC 27001:2022 is the internationally authoritative standard for information security management systems (ISMS). Since the revision in October 2022 with 93 controls in Annex A and a revised structure in Chapters 4 to 10, it has represented the certification scheme that companies, authorities and auditors follow. The transition period from the previous version ISO/IEC 27001:2013 ended in October 2026. Anyone who re-certifies today or extends a current certificate will only be audited according to the 2022 version. For management, this results in a clear sequence of preparation, internal audit and external assessment by a DAkkS-accredited certification body.
This article describes the process of an initial certification in eight steps, from the gap analysis, scope definition, risk assessment, statement of applicability and implementation of the controls to the stage 1 and stage 2 audit as well as monitoring and re-audit. We name typical timelines, common stumbling blocks and the documents that every DAkkS accredited certification body wants to see. CIVAC is a compliance platform and officer-as-a-service and maps all 93 controls, the risk register, the statement of applicability and the audit documentation in one workspace. You will receive a clear sequence of steps with those responsible, deadlines and an audit trail that will lead to certification in the first attempt. Appointment certificate for the information security officer included, with a two working day SLA instead of the classic two to six weeks.
Key Takeaways
- The process of an ISO/IEC 27001:2022 initial certification is divided into eight phases with clear handovers between preparation, stage 1 and stage 2 audit.
- Statement of Applicability and Risk Register are the central audit artifacts on which every DAkkS accredited certification body bases its audit.
- With standardised templates, a central workspace and an ordered ISB, the initial certification can usually be achieved in six to nine months.
Step 1: Gap analysis against the 93 controls of the 2022 version
The gap analysis compares the current state of the organisation with the 93 controls in Annex A of ISO/IEC 27001:2022 and the requirements from Chapters 4 to 10. For each control, it records the level of implementation (implemented, partially implemented, planned, not applicable), the associated evidence and the open tasks. A reliable gap analysis also includes an initial scope picture, an overview of the most important assets, an initial risk overview and the existing guidelines. It is typically carried out in a two-week sprint, depending on the size of the organisation and number of locations. The effort for medium-sized companies is ten to twenty person days, including interviews and document review.
The gap analysis is not an audit, but a precise preparation tool. It shows which controls are already covered by other frameworks, such as BSI-Grundschutz, NIST CSF or TISAX. A properly conducted gap analysis saves time in the Stage 1 audit and provides the basis for the argument for not using individual controls. CIVAC provides a pre-structured template that references all 93 controls, with mandatory fields for responsible person, status, evidence and deadline. Others run compliance like a filing cabinet. We run it like software. The representative enters into the workspace, the management sees the reporting line, the external auditor receives an export with cross-references to the Transitional Regulations 2026. In two weeks, a reliable picture of the level of maturity is created, on which the following steps are consistently based. The gap analysis is versioned in the workspace so that every progress remains traceable and the maturity progression can be documented to management. The transition to the following steps is also prepared in terms of data technology: Instead of a new table, the scope, risk register and SoA adopt the findings of the gap analysis as the starting value. This eliminates the need to record identical content multiple times. The appointment certificate, signed, filed, verifiable.
Step 2: Scope definition, scope and exclusion of application
The scope of an ISMS is the basis of every certification. According to Chapter 4.3 of ISO/IEC 27001:2022, it describes which areas, locations, products and processes the ISMS covers, which interfaces to third parties exist and which areas are deliberately excluded. The scope text is checked by the Stage 1 auditor and included verbatim in the certificate. A scope definition that is too narrow can later lead to acceptance problems with customers, while a definition that is too broad can lead to unnecessary audit effort. The decisive factor is the business importance and the regulatory expectations of the relevant stakeholder groups, in particular major customers, supervisory authorities and insurers.
In practice, the scope is developed iteratively: first the external requirements are identified (customers, supervisors, suppliers), then the internal risks are prioritised, and finally the exact scope is bindingly determined. CIVAC creates a scope template in the workspace with mandatory fields for locations, business processes, cloud services, sub-processors and excluded areas. The requirements from the NIS 2 implementation in Germany 2026, the GDPR and, if applicable, the EU AI Act are also referenced in the scope. Licence the workspace for your internal representatives, or have our representatives order it. The auditor calls, the evidence is ready. Experience has shown that a clear scope definition is the lever with the best ratio of effort to audit impact because it structures the entire further path. The scope description is referenced in the Statement of Applicability and linked to the risk register so that no inconsistent statements arise. If there are changes in the business model, the scope is updated and proactively displayed to the certification body so that the certificate does not lose its scope. A one-sided scope statement that is understandable without further explanation has the greatest value in the market for sales and supplier verification.
Step 3: Risk assessment and risk treatment plan
The risk assessment according to Chapter 6.1.2 of ISO/IEC 27001:2022 is the heart of the ISMS. It identifies information assets (assets), records threats and vulnerabilities, assesses the probability of occurrence and impact and determines the gross risk. The risk treatment plan describes which risks are avoided, reduced, transferred or accepted, with which controls from Annex A and which organisational or technical measures, with those responsible and deadlines. Both documents are checked by the auditor in Stage 1 and Stage 2; the risk register is updated at least annually or when there are significant changes. Unplanned events such as security incidents, acquisitions or new cloud services also trigger adjustments.
Methodological freedom exists: Qualitative, quantitative or hybrid approaches are permitted as long as they are applied consistently and documented in a comprehensible manner. A five-level assessment of probability and impact with a risk matrix and a risk treatment threshold is common. CIVAC provides a risk register template with mandatory fields for asset, threat, vulnerability, gross risk, measure, residual risk and responsible party. The connection to the 93 controls is marked in the workspace so that each measure refers to the corresponding control. The appointment certificate, signed, filed, verifiable. The management's acceptance decision is also documented and signed in the workspace so that the acceptance of residual risks remains traceable in the audit. A lean risk assessment is often more valuable than a highly detailed one if it is carried out consistently and comprehensibly. The connection to the business continuity plan according to Annex A.5.30 is explicitly drawn so that risks are not only identified but also dealt with operationally. The insurability of cyber risks also often depends on a plausible risk assessment, so this phase is economically relevant beyond the norm.
Step 4: Statement of Applicability and justification of the selection
The Statement of Applicability (SoA) lists all 93 controls from Annex A of ISO/IEC 27001:2022 and states for each control whether it is applied, with what justification and, if necessary, why it is not applied. It references the associated policy, responsible area and evidence. In addition to the risk register, the SoA is the second central audit artifact and is checked in full depth by every DAkkS accredited certification body. In the Stage 2 audit, the SoA serves as a guide for random samples and interviews.
The justification must not be generic. Sentences like 'is used because it makes sense' do not pass an audit. What is expected is a specific reference to the business risk being addressed, as well as the specific measure and associated evidence. Non-applications must be justified particularly carefully, for example because the control simply does not fit the scope (example: physical access controls in a pure cloud setup). CIVAC provides the SoA template with the 93 controls pre-maintained, including example justifications for the respective industry. The link to the risk register and the guidelines is technically established in the workspace, so that a control is never documented in isolation. Audit proof, documented, ISO/IEC 27001:2022 proof. The version management of the SoA is also relevant because any change in the risk profile can trigger an update. Lean but precise SoA maintenance is the ticket to the Stage 2 audit. A central overview shows open reasons, missing evidence and critical gaps so that management can see the level of maturity per control. A hardened extract can also be generated from the SoA for customer and supplier inquiries, which blacks out confidential details and still makes reliable statements.
Step 5: Implementation of the controls and policy landscape
The controls are implemented according to the risk treatment plan. It includes organisational controls (Annex A.5: 37 controls), personnel-related controls (Annex A.6: 8 controls), physical controls (Annex A.7: 14 controls) and technological controls (Annex A.8: 34 controls). Each control is accompanied by a guideline, a process description and evidence. Typical policies are the information security policy, the access control policy, the supplier policy, the cryptography policy, the incident management procedure and the business continuity guidelines. There are also configuration, patch and logging standards for operational IT.
The implementation takes between three and six months, depending on the level of maturity. Training for all employees in accordance with Annex A.6.3 is mandatory, as are internal audits in accordance with Chapter 9.2 and management reviews in accordance with Chapter 9.3. CIVAC provides 490 ready-to-use audit templates, including policy templates, internal audit plans and management review protocols. The appointed Information Security Officer (ISB) works in the workspace, the management sees the reporting line, the external auditor receives the implementation status as an export. Deadline begins as soon as we become aware of it. The platform's EU data residency ensures that sensitive ISMS documents remain in the EU. This creates a consistent track from the requirement to the measure to the proof, which an external auditor checks in hours, not weeks. Awareness training is carried out with a quiz module and evidence list so that the effectiveness of the training can be demonstrated in the audit using verifiable results. Supplier management according to Annex A.5.19 to A.5.23 is also anchored in the workspace with templates for security requirements, contracts and periodic assessments. This means there are no gaps between your own work and purchased work. The integration with ITSM tools, IAM systems and SIEM platforms is also stored in the workspace with interface documentation so that technical measures are managed consistently with organisational specifications.
Step 6: Internal audit and management review before Stage 1
Before the certification body carries out the Stage 1 audit, an internal audit and a management review are mandatory. The internal audit according to Chapter 9.2 ISO/IEC 27001:2022 systematically checks the effectiveness of the ISMS according to an audit plan across all relevant areas. Auditor is an independent person, often an external lead auditor with IRCA qualifications or an internal auditor with demonstrable independence from the subject matter of the audit. Results are classified as observations, indications or deviations, documented and accompanied by corrective actions. Sound internal audit preparation measurably reduces findings in the external audit.
The management review according to Chapter 9.3 is a board issue, not a compliance appointment. Management evaluates the suitability, adequacy and effectiveness of the ISMS based on inputs such as audit results, risk updates, performance indicators, incidents and improvements. It decides on resources, adjustments to the scope and strategic decisions. CIVAC provides the templates for internal audits and management reviews with mandatory fields for inputs, assessments and resolutions. The representative works in the workspace, the management signs the protocol digitally using eIDAS, the external auditor sees the verifiable governance. Audit proof, documented, ISO/IEC 27001:2022 proof. Both steps are the last internal gates before the Stage 1 audit and are explicitly requested by the auditor. Weak preparation in this phase regularly leads to minor deviations; strong preparation lays the foundation for a smooth main audit. We recommend completing the internal audit at least six weeks before Stage 1 so that corrective actions can be effectively implemented and assessed in the management review. A complete test run with a mock inspection is also possible and measurably increases the likelihood of a main audit with few findings. The management then receives a summary with the level of maturity for each area so that strategic decisions can be made before Stage 1.
Step 7: Stage 1 and Stage 2 audit by the certification body
The certification audit takes place in two stages. In the Stage 1 audit (readiness audit), the DAkkS-accredited certification body checks the ISMS documentation, the scope, the statement of applicability, the risk register, the guidelines, the internal audit and the management review. It identifies gaps and makes recommendations that must be closed before Stage 2. Stage 1 takes one to three audit days depending on the size and is often carried out remotely. Common findings include incomplete SoA justifications, generic risk descriptions or missing evidence of awareness. There are usually four to eight weeks between Stage 1 and Stage 2 in which the findings are addressed.
In the Stage 2 audit (main audit), the audit team checks the operational effectiveness. Employees are interviewed on site, tickets are randomly tracked, access areas are visited and incident logs are reviewed. Stage 2 takes three to ten audit days, depending on the scope. Results are classified as major deviation, minor deviation or observation. Major deviations must be closed within a period of time set by the certification body, which is usually 30 to 90 days. CIVAC supports with audit preparation templates, interview guides for employees and a deviation tracking list that is maintained in the workspace with the person responsible and the deadline. The auditor calls, the evidence is ready. Licence the workspace for your internal representatives, or have our representatives order it. The initial certification is usually successful in the first attempt, without an extension round by the audit body. Short-term training for the interviewed employees on the audit questions is also prepared in the workspace. A well-run kick-off meeting on the first day of Stage 2 reduces friction and enables efficient sampling by the audit body. A clear distribution of roles with the audit supervisor, spokesperson and person responsible keeps the audit running smoothly and avoids unnecessary waiting times.
Step 8: Surveillance audits and re-audit in a three-year cycle
The certificate issued is valid for three years. In the first two years, a surveillance audit takes place, which checks part of the scope and reacts to changes in the ISMS. In the third year, the re-audit follows, which treats the full scope like an initial audit, but requires less effort because many artifacts have already been established. In the event of major changes to the scope, organisation or risk profile, the company informs the certification body in advance. It responds with adapted audit planning and, if necessary, a special audit.
Between the audits, the obligation for continuous improvement in accordance with Chapter 10 ISO/IEC 27001:2022 remains. Incidents are analysed, corrective measures are implemented, the risk register is updated, training is repeated, internal audits are carried out annually and the management review is carried out at least once a year. CIVAC calendars all duties in the workspace and provides timely reminders. This creates a living ISMS that is not activated during the audit and deactivated after the audit, but rather assumes a continuous function in the organisation. A central overview shows open items, due dates and those responsible at a glance. Audit proof, documented, ISO/IEC 27001:2022 proof. Deadline begins as soon as we become aware of it. If desired, CIVAC takes on the role of ISB externally and delivers the reports directly to your management without you having to build up additional internal capacity. It is possible to change the certification body every three years, but should be well prepared so that the audit trail and tracking of findings remain seamless. CIVAC supports the handover with standardised export packages so that the new position can start without any friction. Interconnection with other frameworks such as TISAX, SOC 2 or PCI DSS is also possible via the common data backbone, so that multiple audits can be handled efficiently.
How CIVAC accompanies the certification: Workspace, ISB order, audit templates
CIVAC is a compliance platform and officer-as-a-service that maps all eight steps of ISO/IEC 27001:2022 certification in one system. In the workspace you will find the gap analysis template, the scope template, the risk register, the statement of applicability with the 93 controls pre-maintained, the policy landscape, the templates for internal audit and management review, the stage 1 and stage 2 preparation documents and 490 ready-to-use audit templates. Deadlines, audit dates and repeat training courses are calendared, the reporting line to management is stored in the organisational chart, and EU data residency is technically enforced. The template set also includes integration with GDPR, NIS-2 and the EU AI Act.
Licence the workspace for your internal representatives, or have our representatives order it. In the second model, we provide an information security officer with ISO 27001 lead auditor qualification, take over the appointment with a certificate and catalogue of tasks and deliver quarterly reports directly to your management. The CIVAC SLA of two working days for taking up a role replaces the classic initiation process of two to six weeks. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. We confirm receipt on the same working day and provide an initial assessment with a schedule, ISB appointment certificate and gap analysis offer within the standard SLA. If you initially only need a sanity check to see whether your setup is certifiable in the first attempt, a brief description of your organisation is sufficient. We respond with an assessment and the next three concrete steps towards initial certification, with clear responsible persons and milestone planning. In this way, the standard text becomes an operational plan that leads to a certificate in six to nine months. If you wish, we can also coordinate the selection and commissioning of the DAkkS-accredited certification body, so that you can concentrate on operational development.
FAQ
How long does an ISO 27001:2022 initial certification take?
Typically six to nine months, depending on the level of maturity. An already established security organisation can be certified in four to six months, while a greenfield organisation needs more like nine to twelve months. CIVAC delivers templates and orders for the ISB in two working days, so that operational preparation can start early. The schedule is maintained in the workspace with milestones and reported to management.
What is the difference between Stage 1 and Stage 2 audit?
The Stage 1 audit checks the documentation and audit readiness of the ISMS and identifies gaps before the main audit. It typically lasts one to three days and is often conducted remotely. The Stage 2 audit checks the operational effectiveness on site with interviews, random samples and inspections. Depending on the scope, it takes three to ten days and ends with the auditors' certification recommendation.
What role does the Statement of Applicability play?
The Statement of Applicability is the central audit artifact after the risk register. It lists all 93 controls from Annex A of ISO/IEC 27001:2022 with application status, justification, responsible area and evidence. The certification body examines the SoA in full and uses it as a guide for random samples. Generic justifications or blanket non-applications regularly lead to major deviations in the Stage 2 audit.
Do all 93 controls from Annex A have to be applied?
No, not every control is applicable to every scope. However, non-application must be justified concretely and comprehensibly, for example because the content of the control does not fit the business model. General justifications are objected to in the audit. CIVAC provides example justifications for each industry in the SoA template, so that the reasoning is audit-proof and consistent and no rework is required in the Stage 1 audit.
How much does an ISO 27001 certification cost in Germany?
The costs vary greatly with scope, number of locations and complexity. The pure certification costs of the accredited body are typically between 10,000 and 50,000 euros over three years. There are also internal expenses and, if necessary, external advice. CIVAC significantly reduces internal effort through templates, an ordered ISB and a central workspace with EU data residency. The return comes primarily from audit preparation and finding avoidance.
How quickly can CIVAC provide an ISB for certification?
The CIVAC SLA is two working days from receipt of your request at info@civac.de to the first draft of the appointment certificate. The classic market takes two to six weeks. You can licence the workspace in parallel and supplement the external ISB order later, for example for Stage 1 preparation or to accompany the re-audit in the third year. This way you remain flexible in terms of time.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.