ISO 27001 Certification Services

We build and run the security management system your auditor certifies, so Stage 2 is a review and not a gamble.

ISO 27001 certification services cover two separate jobs, and one firm is not allowed to do both. An accredited certification body runs the audit and issues the certificate. An implementation partner builds and operates the information security management system that gets audited. Consilien does the second job. We scope the system, close the control gaps, run the internal audit, and stay in the room through Stage 2.

Two very different companies show up when you search for this

A customer sent you a security questionnaire. Or an insurer did. Or a European partner asked for a certificate before renewal, and now a contract everyone assumed was closed is sitting on someone's desk.

So you searched. And what came back was two entirely different industries wearing the same label.

One group is accredited certification bodies. Firms like A-LIGN, Schellman, NQA, SGS, and Intertek, accredited in the US by ANAB or IAS. They audit you. They issue the certificate. That is the entire product.

The other group builds the thing that gets audited. Consultancies, managed IT and security firms, and platform vendors. Consilien sits here.

Here is the part almost nobody puts on their website. Those two groups are legally separated. ISO/IEC 17021-1, the standard every accredited certification body has to operate under, says in clause 5.2.5 that "the certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy."

Read that again if you skimmed it. Your auditor cannot build your program. Not will not. Cannot.

Accredited certification body Implementation partner (Consilien)
What they doAudit your program, issue and maintain the certificateScope, build, document, and operate the program
What they are barred fromConsulting on the system they audit (ISO/IEC 17021-1, cl. 5.2.5)Issuing a certificate. We have no accreditation and never will
Who they answer toANAB, UKAS, or IASYou
When you engage themOnce the system has been running and you have evidenceMonth one, before scope is set
What you walk away withA certificate valid for 3 yearsA working security program, and the evidence that proves it ran
Cost of picking wrongYou pay for an audit you failYou certify a scope you cannot actually maintain

You need both. You just cannot buy them from the same place.

Speak to a compliance expert about which half of that table you are actually shopping for. This page sits inside Consilien's compliance practice, which is a standalone offering here and not something bundled into a managed IT contract.

What ISO 27001 actually certifies, and what it does not

ISO 27001 certifies a management system, not a company and not a product. An accredited auditor reviews how you identify information risk, decide what to do about it, document those decisions, and prove the process ran. The certificate covers the scope you defined. Nothing outside that boundary is certified.

That last sentence is where a lot of money gets wasted. Companies scope in three sites and 400 people because it sounds more impressive, then spend two extra quarters and roughly $60K proving controls for a warehouse the customer never asked about.

The version matters too. Every first-time certification now runs against ISO 27001:2022. The transition window from the 2013 edition closed on October 31, 2025, and 2013 certificates went invalid on that date. If someone hands you a policy template pack, check the control numbering before you pay for it. Plenty of 2013-era documentation is still circulating, and it maps to a structure that no longer exists.

The 2022 edition reorganized Annex A from 114 controls in 14 domains down to 93 controls across four themes.

37

Organizational

Policies, roles, supplier relationships, and how information risk gets decided and owned.

8

People

Screening, terms of employment, awareness training, and what happens when someone leaves.

14

Physical

Perimeters, entry controls, equipment siting, clear desk, and secure disposal.

34

Technological

Access control, cryptography, logging, network segmentation, and secure development.

If you want the plain-language version before you go further, our blog covers what ISO 27001 covers end to end.

One thing we see a lot. Leadership assumes ISO 27001 is an IT project because the word security is in it. Then Phase 1 opens, and it turns out HR owns 8 of the controls, facilities owns 14, and procurement owns most of the supplier clauses. IT owns roughly a third of the standard. Not the whole thing.

Where this gets hard if you actually make something

Almost every ISO 27001 guide on the internet was written for a software company. Cloud-only scope, 40 engineers, everything in AWS, no building to speak of. The advice is fine. It is also useless if you run a plant.

At this stage the questions usually sound like this.

Does the shop floor count?

Are our contract manufacturers in scope, and who audits them?

What do we do about the machine controllers running Windows 7 that the vendor will not let us patch?

The badge reader logs only go back 30 days. Is that a finding?

Fourteen Physical controls that a SaaS company handles with a WeWork badge and a locked closet turn into a real workstream when you have a receiving dock, a visitor log, a server room next to the paint line, and equipment that predates the internet.

The operational technology boundary is usually the harder call. Production systems that cannot be patched, cannot be scanned during a run, and cannot go down. Excluding them entirely looks clean on a Statement of Applicability and falls apart the moment an auditor asks how a compromised HMI cannot reach the ERP. Including them without a segmentation plan is worse. The honest answer is a defined boundary, a documented compensating control set, and a risk treatment decision that leadership actually signed.

That is the work. It is not glamorous and it does not come out of a template.

Consilien has been doing IT and compliance for manufacturers, distributors, and food processors since 2001. If your compliance pressure is broader than one framework, our manufacturing IT compliance services page covers the wider picture. Security leadership sits underneath all of it, and where there is no internal program owner that role gets filled through our vCISO support rather than left as a gap you discover during Stage 2.

What a Consilien ISO 27001 engagement covers

Not every item below applies to every company, and we will tell you which ones do not before you sign anything.

  • Scope and boundary definition. Which entities, sites, systems, and people are in. More importantly, which are out, and the defensible reason why.
  • Risk assessment and a risk treatment plan tied to real business impact, not a spreadsheet of theoretical threats.
  • Statement of Applicability. All 93 controls, each one justified as included or excluded, with implementation status. Unjustified exclusions are one of the most common audit findings, and they are entirely preventable.
  • The policy and procedure set, written against the 2022 structure. Yours, not a rebadged template.
  • Control implementation across the four themes, including the technical work our engineering team does directly.
  • Internal audit. Run by someone independent of the people who built the system, because your certification body will check that.
  • Management review, scheduled and minuted. Auditors ask for the minutes.
  • Certification body selection and coordination. We help you shortlist accredited bodies, read the quotes, and we are in the room for Stage 1 and Stage 2.
  • Surveillance-year support in years 2 and 3, so year two is not a fire drill.

The honest calendar

Every vendor gives you a timeline. Most of them quietly delete one phase.

Phase What happens When Why it cannot be compressed
1. Scope and gap assessmentBoundary set, risk assessment run, gap list built against all 93 controlsMonths 1 to 2Rushing scope is what causes a re-audit later
2. BuildPolicies, procedures, control implementation, Statement of ApplicabilityMonths 2 to 5Controls have to be real, not documented intentions
3. Operate and evidenceThe system runs. Internal audit and management review completedMonths 5 to 8Auditors expect roughly 3 months of evidenced operation before Stage 2
4. Stage 1, Stage 2, and year twoDocumentation review, then the full audit. Certificate issuedMonths 8 to 11Stage 1 and Stage 2 are typically 4 to 8 weeks apart
1

Scope and gap assessment

We set the certification boundary, run the risk assessment, and build the gap list against all 93 Annex A controls. Months 1 to 2.

2

Build

Policy and procedure set written against the 2022 structure, controls implemented across the four themes, and a Statement of Applicability with every inclusion and exclusion justified. Months 2 to 5.

3

Operate and evidence

The system runs and generates proof. Internal audit and management review completed. This is the phase competitors delete from the timeline. Months 5 to 8.

4

Stage 1, Stage 2, and year two

Stage 1 documentation review, then the Stage 2 audit run by an accredited body. Certificate issued, then surveillance support in years 2 and 3. Months 8 to 11.

Phase 3 is the one that disappears from sales decks.

It should not. NQA and ISMS.online both put the same items at the top of the nonconformity list year after year. No completed internal audit. No management review. A Statement of Applicability with exclusions nobody justified. A risk assessment that does not connect to the controls it supposedly drove. Every one of those is a Phase 3 failure, and none of them can be fixed the week before Stage 2, because what is missing is time on the clock.

So when a provider tells you 8 weeks to certified, they are either excluding the audit from that number or they are setting you up to buy a second audit.

Proof

25 years. Consilien has been operating since 2001, independently owned the whole time.

Compliance work here is not a side product of a managed IT contract. It is a standalone practice, and some of it runs long. Interactive Health, a consumer products company in Long Beach, has been a compliance consulting and managed IT client since August 2010. That is roughly 14 years of keeping one company aligned to security standards through audits, staff turnover, and at least three generations of infrastructure.

"Consilien is a quality IT partner that has done a great job keeping our business up and running." Charles Warren, Financial Analyst, Interactive Health. Clutch-verified, 5.0

99% customer satisfaction, referenced in Consilien public profiles.

And the commitment that matters most on a page like this one. Our standard agreement runs 3 years with a 1-year opt-out at 60 days notice. Compliance vendors do not usually offer that, because a multi-year lock-in is how a lot of them make the economics work. We would rather earn year two.

For context on how fast this market moved, the ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, up from 48,671 in 2023. Nearly double in a single year. That is why your customers started asking.

Who this is for, and who it is not

You are a strong fit if you are:

  • A company with 20 to 500 users where a customer, insurer, or EU or UK partner has asked for the certificate in writing.
  • In manufacturing, distribution, food processing, professional services, real estate management, or media and creative.
  • Running more than one site, or a mix of office and production environments.
  • Already holding SOC 2, or pursuing it, and you want the control overlap worked out once instead of twice.
  • Without a full-time security program owner internally.

You are probably not the right fit if:

  • You have a full-time CISO and a staffed GRC team. You do not need an implementation partner. You need an accredited auditor, and you should go straight to one.
  • Your contract actually names NIST 800-171 or CMMC. Read it again before you spend a dollar on ISO 27001.
  • You need a certificate in under 90 days. Nobody can do that honestly, and we will not take the engagement.
Two paths illustration showing ISO 27001 implementation partner versus accredited certification body

Which framework is the contract actually asking for?

Before you commit a budget, go read the clause. We have watched companies spend two quarters on the wrong standard because someone forwarded a questionnaire without reading the contract behind it.

ISO 27001 SOC 2 NIST 800-171 / CMMC
Who asks for itInternational customers, EU and UK partners, insurersUS enterprise buyers, mostly SaaS and services procurementDoD primes, federal contracts with DFARS clauses
What it provesA functioning security management system, certifiedControls operated effectively over a periodImplementation of 110 specified controls
Who assessesAccredited certification bodyLicensed CPA firmSelf-assessment plus SPRS, or a C3PAO
OutputA certificate, valid 3 yearsAn attestation reportA score and, at Level 2, a certification
Rough first-year cost$15K to $200K depending on size$30K to $150K or moreVaries by boundary size

Full breakdowns live on the SOC 2 readiness, NIST 800-171, and CMMC compliance pages. If you are weighing the first two specifically, we wrote up how the two overlap in detail.

Not sure which one your customer means? Send us the questionnaire or the contract clause, and we will tell you what it actually requires before you spend anything. Speak to a compliance expert.

What buyers push back on

The price. First-year ISO 27001 runs roughly $15,000 to $50,000 for companies under 50 users, $50K to $150K in the 50 to 250 range, and $100,000 to $200,000 or more above that. Annual maintenance after year one lands somewhere around $6K to $25K. Now compare it to the alternative. A failed Stage 2 means re-audit fees at $1,500 to $2,200 per auditor day, another remediation cycle, and a contract that stays parked for another two quarters. The expensive version of ISO 27001 is the one you do twice.

Trust. We cannot certify you. That is not modesty, it is structural, and it is worth understanding what it does to our incentives. A firm that both prepares you and audits you has a reason to move you toward an audit date. We do not have one. The only thing we get out of pushing you into Stage 2 unprepared is a client who fails and blames us correctly.

Fit. If ISO 27001 is not what your contract requires, we will say so in the first call and point you at the right page. That call costs you nothing and it has saved a few companies a very expensive quarter.

Complexity, and what we need from you. Someone internally has to own decisions. Not do the work, own the decisions. Scope, risk appetite, and control ownership are business calls and an outside firm cannot make them for you. Budget roughly 2 to 4 hours a week from that person during Phases 1 and 2, less afterward.

The commitment. 3-year agreement, 1-year opt-out, 60 days notice. If year one goes badly, you leave.

Magnifying glass over a security shield with a checkmark, representing ISO 27001 audit evidence review

Common questions about ISO 27001 certification

How long does ISO 27001 certification take?


Most companies reach certification in 8 to 11 months from kickoff, with a realistic range of 6 to 12 depending on scope and starting maturity. The compressible parts are documentation and remediation. The part that cannot be compressed is the operating window before Stage 2, where auditors expect roughly 3 months of evidence that the system actually ran.

Get your ISO 27001 scope defined before the contract deadline moves

A stalled renewal costs you the contract. Nine months of preparation followed by a failed Stage 2 costs you the contract and the year. Both are avoidable, and the fix starts with a scoping conversation, not a purchase order.