Certification audit process
From application review to annual surveillance, every stage is structured, independent, and documented.
Preparation is key
Our team will guide you through the process and set the stage for your initial audit. As your conformity auditor, we will not offer consultation or implementation services. Complade can explain the standard and the certification process but will not engage on specifics of your environment.
Initial certification
- Application intake: Complete the online application. Scope, audit time, plan and contract details are determined.
- Agreement: Review the mutual NDA, certification terms, audit plan and invoice.
- Stage 1: The auditor reviews the management system and supporting evidence, then reports readiness findings.
- Stage 2: Implementation and effectiveness are tested remotely or in person.
- Corrective action: The client responds to identified gaps.
- Certification decision: A separate reviewer examines the complete audit package.
Surveillance and recertification
During Years 1 and 2, annual surveillance audits verify that the security program remains active and compliant. A full ISO/IEC 27001 recertification audit follows in Year 3.
Surveillance must be completed within 9 to 12 months of initial certification. If it is not completed by the 12-month mark, the certificate may be temporarily suspended. If the process is not completed within 6 months of suspension, the certificate will be withdrawn.
How long does it take?
Quick answer: approximately 6 weeks in the fastest audit-ready ISO/IEC 27001 scenario.
Timing depends on organization size, complexity, readiness, auditor availability, clarifications, and whether nonconformities must be resolved.
Not ready yet?
Seek assistance from an implementer; Complade cannot provide implementation help. Much like an accountant cannot audit their own financial records, an implementer responsible for an ISMS cannot independently certify their own work.
