ISO 27001

ISO/IEC 27001 certification: from gap analysis to audit

Understand each stage of ISMS implementation: scope, risk management, controls and internal audit, so you can approach certification with confidence.

ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). Certification can provide a competitive advantage in procurement and a solid foundation for NIS2 and DORA compliance. Here is the route to certification and the pitfalls that can delay a project.

What is ISO 27001, and who benefits?

ISO 27001 is a management framework. It establishes a system for identifying, treating and continually reviewing risks, rather than prescribing a particular technology. It is valuable for organisations that:

  • need to demonstrate information security to customers and partners;
  • require certification for tenders or public procurement;
  • want a solid foundation for NIS2 or DORA;
  • seek structured, auditable security operations.

What are the stages of certification?

1. Define the scope

Identify the organisational units, sites, systems and information assets covered by the ISMS. A scope that is too broad or too narrow can undermine the project.

2. Conduct a gap analysis

Assess the current position against the standard. The results provide a prioritised action list and a realistic timetable.

3. Establish risk management

Complete risk assessments and a risk treatment plan, selecting Annex A controls in proportion to the risks. Document the Statement of Applicability (SoA).

4. Develop documentation and implement it

Create policies, procedures and records. More importantly, put them into operation so that daily practice reflects what is documented.

5. Complete internal audit and management review

An independent internal audit assesses how the system operates, followed by formal management review. Both are prerequisites for certification readiness.

6. Undergo the Stage 1 and Stage 2 certification audits

Stage 1 examines documentation and readiness. Stage 2 assesses actual operation. A successful process leads to certification.

How long does an ISO 27001 project take?

Implementation typically takes 4–9 months, depending on size and maturity. Realistic planning and internal resources make a substantial difference. In practice, putting the documentation into operation takes longer than writing it.

What does the preparation fee cover?

Preparation usually includes advisory work and support during the certification audit:

  • gap analysis, risk management design and the SoA;
  • policies and procedures;
  • internal audit and management review support;
  • awareness training;
  • support during Stage 1 and Stage 2.

The independent certification body’s fees are separate and invoiced by that body.

What are the most common pitfalls?

  • An unnecessarily broad scope that makes certification harder and more expensive.
  • Unused documentation that daily operations do not follow.
  • Missing or superficial internal audits and management reviews.
  • Underestimating ongoing maintenance, including subsequent surveillance audits.

How does it relate to NIS2?

An ISO 27001 ISMS provides a strong foundation: risk management, controls and documentation overlap significantly. You must still check Hungarian applicability, security classifications, notification and audit obligations separately. The certificate does not replace a NIS2 audit.

The certificate is evidence of a working, auditable management system within its stated scope. Legal compliance must be demonstrated separately.

How zemITis helps

Our ISO 27001 Lead Auditors guide ISMS implementation from gap analysis through successful certification, then support ongoing maintenance. Explore our ISO/IEC 27001 service and fee calculator.

Next steps

Build a management system that works.

Scope, risk management, documentation and audit preparation. Explore our ISO 27001 service and plan your route to certification with us.