Hello, this is Ryuta Hamamoto from TIMEWELL.
“Stage 1 is in two weeks. What else do we do?” When supporting certification, I always get that question. The earlier ISMS intro (What is ISMS?) covered the big picture. This piece is what happens at each step of the real certification process—and where teams fall.
ISO/IEC 27001:2022 is the baseline for all new certifications after the transition deadline from the 2013 edition ended October 31, 2025 (see JIPDEC). This article assumes May 2026 practice.
Certification lifecycle — the 3-year cycle
| Year | Audit type | Content | Effort (mid-size firm) |
|---|---|---|---|
| Year 1 | Initial certification (Stage 1+2) | Document + on-site | 3–5 auditor-days |
| Year 2 | Surveillance | Sample controls + PDCA check | 2–3 auditor-days |
| Year 3 | Surveillance + recertification | Full control re-evaluation | 3–4 auditor-days |
Stage 1 to Stage 2 is usually 1–3 months. Fix Stage 1 nits before Stage 2—the classic path.
Executives who think “once certified, it gets easy” have it backward. The three-year cycle after go-live is the main event. Serious surveillance findings can suspend or withdraw the certificate. I have seen year-2 surveillance nearly derail a site because “training records only exist for year one.”
Stage 1 — five document-review focus points
Stage 1 is document-heavy (on-site or remote), half day to one day. Focus:
1. Scope validity
Scope document must name org units, sites, processes, and information assets. A third party must see clear boundaries—“contracted development at XX Co.” style.
2. Policy alignment
Top-management signed approval; policy content linked to business issues. Template reuse shows here.
3. Risk assessment process and Statement of Applicability
Methodology documented; SoA lists all 93 Annex A controls as applicable / not applicable with reasons. SoA is among the most important documents.
4. Risk treatment plan
Accept / reduce / transfer / avoid—written.
5. Internal audit and management review evidence
At Stage 1 you generally need at least one of each already done. Last-minute paper trails get spotted in minute quality.
A common field failure: thin “not applicable” reasons. For A.6.7 (remote working) writing only “no such work” collapses when the auditor asks whether a remote-work ban policy exists and whether anyone actually works from home.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Stage 2 — what they look at on site
Stage 2 is on-site (hybrid common), 2–4 days.
Day 1: Opening + top-management interview
Plan confirmation and direct interview of leadership—“What is your top information security risk?” “How much budget do you put into ISMS?” I know firms that put a proxy when the CEO was away and had to redo Stage 2.
Middle days: Department interviews and walkthroughs
IT, HR, admin, engineering, sales in scope. Server-room / archive access logs, screen-lock settings, secure disposal—in the flesh.
Final day: Findings draft and closing
Nonconformities and observations shared formally at closing.
Typical Stage 2 findings:
- Training coverage gaps: new hires trained; mid-career hires, temps, on-site contractors not
- Access reviews missing: leaver accounts still live
- Hollow management review: minutes say “no objection” with no leadership decision trail
- No supplier evaluation: contracts exist; annual security reviews do not
- Suspected backfilled records: Excel education logs with visible last-minute edit history
If I had to pick one Stage 2 risk I see most, it is the leadership interview. Documents can look fine. A CEO who cannot name the top risk in their own words is a different problem.
Surveillance and recertification — “certified and done” is the riskiest posture
Surveillance once a year samples the scope, follows prior findings, and samples controls. An observation left open often upgrades to a nonconformity next year.
Year-3 recertification is near initial-cert volume: all controls re-evaluated; three years of records on the table. Scattered files create a “year-three hell.” From year one I recommend strict record directory structure and naming.
Major nonconformities I have seen in surveillance:
- Risk assessment never refreshed after year one (related to planning/risk requirements)
- Internal auditor was the IT security manager auditing their own department (independence failure)
- Management review skipped two years running (leadership / review requirements)
All can lead to suspension risk.
Cost and effort reality — mid-size case study
What executives care about most. Typical mid-size firm (200–500 employees, ~50 in scope):
Year-one total: ¥3.8–6.0M
| Item | Ballpark |
|---|---|
| Consulting | ¥2.0–3.5M |
| Certification body (Stage 1+2 + registration) | ¥1.2–1.8M |
| Internal effort (0.5 FTE × 6 months) | ¥0.6–1.0M equivalent |
Annual maintenance after year one: ¥1.0–1.8M
| Item | Ballpark |
|---|---|
| Certification body (surveillance) | ¥0.6–1.0M |
| Internal maintenance effort | ¥0.4–0.8M equivalent |
Plus internal training content, external courses, internal auditor credentials (CISA, ISMS auditor trainee, etc.).
In my experience, more than half of teams that “cut consulting and go solo” call a consultant in a panic just before Stage 1. Starting with a seasoned partner often lowers total cost—not sympathy for IT, pure economics.
WARP SECURITY — clearing the last wall before audit
Many readers will feel Stage 2 interview prep is the anxiety peak. The most common TIMEWELL ask: “Documents are ready. Will leadership freeze in interviews?”
WARP SECURITY is an implementation-lab program for the last ~two months before certification—two days of applied drills:
- Writing SoA correctly — how to justify “not applicable” with confidence across 93 controls
- Management review scripts — 30 minutes that produce next-quarter priorities, not rubber stamps
- Stage 2 interview Q&A — ~20 real auditor question patterns rehearsed against your firm
- Interpreting new controls under AI use — placing ChatGPT-class tools under A.5.23 (cloud) and A.8.28 (secure coding)
That last point is the one I care about most. ISO/IEC 27001:2022 locked before ChatGPT’s mass adoption. Reading clauses literally does not yield modern AI-risk interpretation. WARP SECURITY bridges standard text and current AI threats hands-on.
Details: WARP SECURITY.
Latest as of July 2026
Because ISO/IEC 27001:2022 predated mass generative AI, AI-related control interpretation is supplemented from external guidelines. As of July 2026, a primary reference is AI Business Guidelines v1.2 published March 31, 2026 by MIC/METI (METI). Citing such guidance when generative AI appears in risk assessment and SoA tends to make auditor explanations land more cleanly—my current view. For control design of AI use itself: Governed enterprise AI agents.
Key takeaways — make certification a start, not an end
- 3-year cycle; surveillance and recertification test field strength more than Stage 1+2
- Stage 1 focus: scope, policy, risk assessment, SoA, internal audit records—template reuse gets caught
- Stage 2 core: direct top-management interview and department walkthroughs—avoid proxy-only leadership
- Year-one total for mid-size often ¥3.8–6.0M; maintenance ~¥1.0–1.8M/year
- 2022 new controls (A.5.7, A.5.23, A.8.11, A.8.12, A.8.23, A.8.28, etc.) need AI/cloud-era interpretation
I want certification positioned as the starting line where security operations catch a global baseline, not a finish line. The gap between “thinner than year one” at recertification and “operations exceed the standard” is set in the first six months’ seriousness. Build the record habit before you celebrate the certificate.
Related: ISMS beginner’s guide, ISO/IEC 42001 AIMS beginner’s guide, ISMAP explained.






