In this article you can read which errors often delay an ISO 27001 journey, which steps are required and how you assess where your organisation is. I base this overview on questions and bottlenecks that I encounter during audits and guidance sessions.

What ISO 27001 certification requires of you (and when you really need it)

The difference between compliance and an official certificate

Working by the NEN-EN-ISO 27001 standard without external validation, we call compliance. You set up an information security management system, conduct risk analyses and record processes, but there is no third party that will assess this. An official ISO 27001 certificate requires an audit by an accredited certification body, which formally confirms that your system meets the standard. In procurement and business contracts, external evidence is increasingly a tough condition.

Compliance without a certificate is valuable as an internal framework, but it rarely convinces a client or supervisor. He wants independent evidence. In compliance you assess the application itself; With certification, an approved institution shall give an external assessment of the ISMS. The relationship with the GDPR also plays a role in this: a well-designed information security management system supports at the same time the demonstrable compliance with privacy legislation, as security measures and processing records support the same processes.

Which sectors feel the most pressure

For SME suppliers in production chains and logistics, certification is increasingly a contractual obligation imposed on customers or clients. Healthcare configurations and youth support providers are faced with requirements from the Health and Youth Inspectorate, which expect demonstrable compliance with ISO 27001 or the health-specific standard NEN 7510.

Childcare organisations regularly receive questions from municipalities about how they handle data from children and parents. Public organisations are partly covered by national cybersecurity legislation and European NIS2 obligations; consult current laws, regulations or advice of the NCSC for specific applicability. A well-designed information security management system is the basis for demonstrable compliance in all these cases.

The five errors that slow or fail most of the routes

Error 1: define the scope too wide or too narrow

Scope determination is the most underestimated step in the whole process. A scope that is too wide makes the project unmanageable. A scope that is too narrow gives the auditor cause for critical questions about what was left out and why. A recognizable example: a healthcare institution that includes its entire ICT environment in the scope, while one department or one system is the logical starting point. Start small and controlled, and build from there.

Error 2: treat documentation as a paper tiger

The auditor does not just want to see that there are documents; he wants proof that those documents live in the organisation. Policy that has been established a long time ago and has not been revised since then is a non-conformity that is waiting to happen. The standard requires that policies are kept up to date and documented on a regular basis. This is directly linked to the obligation to carry out internal audits and management assessments: where those are missing or not documented, the auditor shall lack evidence that the system is being actively maintained.

Error 3: Undervalue the Applicability and Supplier Management Statement

Many organisations complete the Declaration of Applicability (SoA) as a mandatory form, without taking the content seriously. Any exclusion of an Annex A measure must be substantiated by a reason that reflects risks, scope or legal obligations. "We're not doing this" is not a valid argument. The same applies to supplier management: the auditor expects evidence that supplier risks have been assessed, including periodic reviews and contractual security requirements, not only a list of names.

Error 4: late or under-involve top management

ISO 27001 certification requires demonstrable management involvement, as set out in Chapter 5 of the Standard. Management or management should define the policy, assign responsibilities and carry out the management assessment. Organisations that treat certification as an IT project, without board-level embedding, are stuck in the phase 2 audit. Involve management or management at baseline assessment; this prevents delay later in the journey.

Error 5: lack of evidence of implementation despite policy

Having policies is not enough. Auditors also verify whether those policies are demonstrably followed. Access reviews that were not performed, internal audits that were planned but never completed, and nonconformities that were recorded but not followed up can all prevent certification. Evidence of implementation is at least as important as the documentation itself.

From baseline assessment to ISO 27001 certification: a realistic roadmap

Steps 1 to 3: Set up baseline assessment, gap analysis and ISMS

The journey to ISO 27001 certification starts with a baseline assessment which maps the current situation: What's already there, what's missing, and where are the biggest risks? A gap analysis then reveals the distance to the standard and gives priorities for the follow-up steps. Based on this, you define the ISMS scope, define the risk assessment methodology, work out the mandatory policy documents and complete the Applicability Statement. Kynexis Information Security provides independent baseline assessments and gap analyses, translating findings into a prioritized roadmap so that organisations know where to start and what results most.

Steps 4 and 5: internal audit and the external certification audit in two phases

Before the external auditor arrives, you must have conducted an internal audit and conducted a management review. The external certification audit is carried out in two phases. In phase 1, the auditor shall assess the documentation and determine whether the organisation is ready for the review. In phase 2, it is checked whether the system actually works as documented, through interviews with employees, samples and process observations. For an average SME starting from scratch, six to nine months is a realistic time frame. The total cost for the first year, including guidance and audit costs, is generally between €10,000 and €25,000; The exact amount depends on the size of the organisation, scope and starting position compared to the standard.

Checklist ISO 27001 certification: which documents and evidence the auditor really controls

Compulsory documents

Without the following documents, you will not be able to pass the certification audit:

  • The established ISMS scope, formally documented
  • Information security policy, current and approved by management
  • The risk assessment methodology
  • The Risk Treatment Plan
  • The fully substantiated Declaration of Applicability (SoA)
  • The documented information security objectives

The auditor not only checks whether these documents exist, in accordance with the requirements of clauses 4 to 10 of the NEN-EN-ISO/IEC 27001, but also whether they are up-to-date, approved by management and monitored internally. A common flaw: The SoA is present but contains exclusions without any justification.

Process certificates

In addition to policy documents, the auditor expects registrations that prove that the system is actively used:

  • Results of risk analyses carried out
  • Internal audit results
  • Management review reports
  • Evidence of competence and awareness training
  • Records of nonconformities and the corresponding corrective actions

This often raises a problem: the policy is in place, while evidence of implementation is lacking. Make sure you can submit a dated registration for each mandatory activity.

Addressing supplier management

Supplier reviews are a separate focus. Make sure you can demonstrate that supplier risks have been periodically re-evaluated, that contracts contain security requirements and that evaluations have been documented. A list of names without further justification is not sufficient for the auditor.

A practical checklist for your certification audit

Documentation and policy: what you need to have in order at least

  • ISMS scope formally established and documented
  • Information security policy up-to-date, approved by management and internally communicated
  • Declaration of Applicability fully completed, with justification per measure
  • Risk analysis performed by documented methodology
  • Risk treatment plan active and maintained
  • Information security objectives documented and measurable

Processes and evidence: what the auditor is testing in practice

  • Internal audit carried out and documented, including follow-up of findings
  • Management assessment conducted with a recorded report
  • Supplier assessments up-to-date, with contractual security requirements and periodic evaluations
  • Employee awareness is detectable through training, e-learning or awareness sessions
  • Non-conformitys recorded and remedial action demonstrably monitored

Have a pilot audit or preliminary assessment carried out before the official certification audit takes place. That gives you the chance to resolve remaining shortcomings without having a direct impact on your certificate.

What an independent partner contributes to a successful journey

From gap analysis to implementation guidance

An independent consultant adds an objective look and experience with certification audits. A good gap analysis sets priorities based on risk, not on what is easiest to arrange. Guidance in policy formulation, correct completion of the Statement of Applicability and the organisation of supplier management not only saves time, but also prevents you from being surprised months later in the audit.

Kynexis Information Security guides SMEs, healthcare organisations, childcare organisations and public-sector bodies throughout the journey towards ISO 27001 certification. Findings are always translated into a practical roadmap with clear priorities and ownership for each measure.

Board-level reporting that really works

A technical audit report is valuable when the organisation can use it to make decisions. Board members need a clear overview of risks, the status of each ISMS requirement, priorities and responsibilities. Management-focused reporting enables executive and supervisory boards to make informed decisions and embed the ISMS throughout the organisation. Kynexis translates the technical evidence into information the board and executive management can act on. Would you like to know what that could look like for your organisation? Discuss your question directly with me.

Conclusion: certification succeeds in execution, not on intention

ISO 27001 certification rarely fails due to lack of ambition. Failed on execution: a scope that is incorrect, documentation that is not kept, evidence that is missing, management that is late in coming. Those mistakes are known and avoidable, provided you recognise them in time.

Use the roadmap and checklist in this article as a starting point for your own preparation. Always start with a baseline assessment. Without a clear picture of where you are now, realistic planning is not possible and you risk doing months of work in the wrong order. The cost of a thorough baseline assessment outweighs the loss of time and money that a failed certification audit entails.