ISO/IEC 27001:2022 CertificationInformation Security Management

ISO 27001 certification protects your information and your clients’ data with an information security management system (ISMS).

Stage 1 & Stage 2 auditsSurveillance auditsOnline verification
ISOCertified
management system
About the Standard

What is ISO/IEC 27001:2022?

ISO/IEC 27001 helps organisations manage information security risks through policies, processes and controls that protect the confidentiality, integrity and availability of information, including cyber security.

Who is it for?

  • IT and technology companies
  • Finance and professional services
  • Organisations handling client data
  • Suppliers to government and large enterprises
Start Your Certification
Structure of the Standard

Key Requirements (Clauses 4–10)

ISO/IEC 27001:2022 follows the common high‑level structure shared by ISO management system standards, making it easy to integrate with other standards.

4

Context of the organisation

Understand internal and external issues and interested parties.

5

Leadership

Top management commitment, policy and responsibilities.

6

Planning

Risks, opportunities and measurable objectives.

7

Support

Resources, competence, awareness and documented information.

8

Operation

Planning and control of the processes that deliver results.

9

Performance evaluation

Monitoring, internal audit and management review.

10

Improvement

Corrective action and continual improvement.

Certification Process

How to Get ISO/IEC 27001:2022 Certified

1

Application

Submit an application with details of your organisation, sites, scope and standard(s).

2

Quotation & agreement

We review the application, confirm audit duration and send a quotation and certification agreement.

3

Stage 1 audit

Review of your documentation and readiness for the Stage 2 audit.

4

Stage 2 audit

On‑site audit to evaluate the implementation and effectiveness of your management system.

5

Certification decision

Independent review of audit results and, once any non‑conformities are closed, certificate issue.

6

Surveillance audits

Periodic audits to confirm your system continues to meet the standard while you are certified.

7

Recertification

A recertification audit before your certificate expires to renew your certification.

Training for Your Team

Awareness, internal auditor and lead auditor courses for ISO/IEC 27001 and other standards.

View ISO courses

Verify a Certificate

Check whether a certificate issued by SRA is valid.

Verify now

Rules & Regulations

Read the conditions that apply to certified clients.

Read the rules
FAQ

Frequently Asked Questions

It depends on your organisation’s size, complexity and readiness. After reviewing your application we will give you a clear timeline.

Certificate validity depends on the type of certification and the scheme requirements. The validity period is confirmed in your certification agreement and shown on your certificate, and certification is maintained through surveillance audits.

Yes. It can be audited together with other ISO management system standards in an integrated audit.