AIセキュリティ

ISO/IEC 27001 Certification Complete Guide — Stage 1 Through Surveillance: Where Teams Trip on the Full Path

Published2026-05-20Updated2026-07-06Ryuta Hamamoto

A chronological walkthrough of ISO/IEC 27001:2022 certification—Stage 1, Stage 2, surveillance, and year-3 recertification.

ISO/IEC 27001 Certification Complete Guide — Stage 1 Through Surveillance: Where Teams Trip on the Full Path
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

“Stage 1 is in two weeks. What else do we do?” When supporting certification, I always get that question. The earlier ISMS intro (What is ISMS?) covered the big picture. This piece is what happens at each step of the real certification process—and where teams fall.

ISO/IEC 27001:2022 is the baseline for all new certifications after the transition deadline from the 2013 edition ended October 31, 2025 (see JIPDEC). This article assumes May 2026 practice.

Certification lifecycle — the 3-year cycle

Year Audit type Content Effort (mid-size firm)
Year 1 Initial certification (Stage 1+2) Document + on-site 3–5 auditor-days
Year 2 Surveillance Sample controls + PDCA check 2–3 auditor-days
Year 3 Surveillance + recertification Full control re-evaluation 3–4 auditor-days

Stage 1 to Stage 2 is usually 1–3 months. Fix Stage 1 nits before Stage 2—the classic path.

Executives who think “once certified, it gets easy” have it backward. The three-year cycle after go-live is the main event. Serious surveillance findings can suspend or withdraw the certificate. I have seen year-2 surveillance nearly derail a site because “training records only exist for year one.”

Stage 1 — five document-review focus points

Stage 1 is document-heavy (on-site or remote), half day to one day. Focus:

1. Scope validity
Scope document must name org units, sites, processes, and information assets. A third party must see clear boundaries—“contracted development at XX Co.” style.

2. Policy alignment
Top-management signed approval; policy content linked to business issues. Template reuse shows here.

3. Risk assessment process and Statement of Applicability
Methodology documented; SoA lists all 93 Annex A controls as applicable / not applicable with reasons. SoA is among the most important documents.

4. Risk treatment plan
Accept / reduce / transfer / avoid—written.

5. Internal audit and management review evidence
At Stage 1 you generally need at least one of each already done. Last-minute paper trails get spotted in minute quality.

A common field failure: thin “not applicable” reasons. For A.6.7 (remote working) writing only “no such work” collapses when the auditor asks whether a remote-work ban policy exists and whether anyone actually works from home.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Stage 2 — what they look at on site

Stage 2 is on-site (hybrid common), 2–4 days.

Day 1: Opening + top-management interview
Plan confirmation and direct interview of leadership—“What is your top information security risk?” “How much budget do you put into ISMS?” I know firms that put a proxy when the CEO was away and had to redo Stage 2.

Middle days: Department interviews and walkthroughs
IT, HR, admin, engineering, sales in scope. Server-room / archive access logs, screen-lock settings, secure disposal—in the flesh.

Final day: Findings draft and closing
Nonconformities and observations shared formally at closing.

Typical Stage 2 findings:

  1. Training coverage gaps: new hires trained; mid-career hires, temps, on-site contractors not
  2. Access reviews missing: leaver accounts still live
  3. Hollow management review: minutes say “no objection” with no leadership decision trail
  4. No supplier evaluation: contracts exist; annual security reviews do not
  5. Suspected backfilled records: Excel education logs with visible last-minute edit history

If I had to pick one Stage 2 risk I see most, it is the leadership interview. Documents can look fine. A CEO who cannot name the top risk in their own words is a different problem.

Surveillance and recertification — “certified and done” is the riskiest posture

Surveillance once a year samples the scope, follows prior findings, and samples controls. An observation left open often upgrades to a nonconformity next year.

Year-3 recertification is near initial-cert volume: all controls re-evaluated; three years of records on the table. Scattered files create a “year-three hell.” From year one I recommend strict record directory structure and naming.

Major nonconformities I have seen in surveillance:

  • Risk assessment never refreshed after year one (related to planning/risk requirements)
  • Internal auditor was the IT security manager auditing their own department (independence failure)
  • Management review skipped two years running (leadership / review requirements)

All can lead to suspension risk.

Cost and effort reality — mid-size case study

What executives care about most. Typical mid-size firm (200–500 employees, ~50 in scope):

Year-one total: ¥3.8–6.0M

Item Ballpark
Consulting ¥2.0–3.5M
Certification body (Stage 1+2 + registration) ¥1.2–1.8M
Internal effort (0.5 FTE × 6 months) ¥0.6–1.0M equivalent

Annual maintenance after year one: ¥1.0–1.8M

Item Ballpark
Certification body (surveillance) ¥0.6–1.0M
Internal maintenance effort ¥0.4–0.8M equivalent

Plus internal training content, external courses, internal auditor credentials (CISA, ISMS auditor trainee, etc.).

In my experience, more than half of teams that “cut consulting and go solo” call a consultant in a panic just before Stage 1. Starting with a seasoned partner often lowers total cost—not sympathy for IT, pure economics.

WARP SECURITY — clearing the last wall before audit

Many readers will feel Stage 2 interview prep is the anxiety peak. The most common TIMEWELL ask: “Documents are ready. Will leadership freeze in interviews?”

WARP SECURITY is an implementation-lab program for the last ~two months before certification—two days of applied drills:

  • Writing SoA correctly — how to justify “not applicable” with confidence across 93 controls
  • Management review scripts — 30 minutes that produce next-quarter priorities, not rubber stamps
  • Stage 2 interview Q&A — ~20 real auditor question patterns rehearsed against your firm
  • Interpreting new controls under AI use — placing ChatGPT-class tools under A.5.23 (cloud) and A.8.28 (secure coding)

That last point is the one I care about most. ISO/IEC 27001:2022 locked before ChatGPT’s mass adoption. Reading clauses literally does not yield modern AI-risk interpretation. WARP SECURITY bridges standard text and current AI threats hands-on.

Details: WARP SECURITY.

Latest as of July 2026

Because ISO/IEC 27001:2022 predated mass generative AI, AI-related control interpretation is supplemented from external guidelines. As of July 2026, a primary reference is AI Business Guidelines v1.2 published March 31, 2026 by MIC/METI (METI). Citing such guidance when generative AI appears in risk assessment and SoA tends to make auditor explanations land more cleanly—my current view. For control design of AI use itself: Governed enterprise AI agents.

Key takeaways — make certification a start, not an end

  • 3-year cycle; surveillance and recertification test field strength more than Stage 1+2
  • Stage 1 focus: scope, policy, risk assessment, SoA, internal audit records—template reuse gets caught
  • Stage 2 core: direct top-management interview and department walkthroughs—avoid proxy-only leadership
  • Year-one total for mid-size often ¥3.8–6.0M; maintenance ~¥1.0–1.8M/year
  • 2022 new controls (A.5.7, A.5.23, A.8.11, A.8.12, A.8.23, A.8.28, etc.) need AI/cloud-era interpretation

I want certification positioned as the starting line where security operations catch a global baseline, not a finish line. The gap between “thinner than year one” at recertification and “operations exceed the standard” is set in the first six months’ seriousness. Build the record habit before you celebrate the certificate.

Related: ISMS beginner’s guide, ISO/IEC 42001 AIMS beginner’s guide, ISMAP explained.

References

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles