An independent, third-party certification body · operating to ISO/IEC 17021-1:2015
Verify a Certificate ↗·Global · Remote & on-site·EN
Certification
Home/Standards/ISO 27001
Information Security · ISMS

ISO 27001

The world’s benchmark for information security. We audit your ISMS against ISO/IEC 27001 and, on the evidence, issue certification — independently of the audit team.

ISO/IEC 27001:2022 Basis · ISO/IEC 27006-1 Scheme · ISO/IEC 27006-1 Duration · ISO/IEC 27006-1
ISO 27001 ISMS
What we certify

We audit your information security management system — and decide on the evidence

ISO/IEC 27001:2022 sets the requirements for an information security management system (ISMS): managing information risk through a system of controls covering people, processes and technology, selected against a documented risk assessment.

As an independent certification body, Skyeblanc Certification audits your information security management system against ISO 27001 and, where the evidence supports conformity, issues certification. We do not design, document or improve your system — that separation is a requirement of ISO/IEC 17021-1 and is exactly what gives an ISO 27001 certificate its meaning.

Certification is delivered under ISO/IEC 27006-1, with the certification decision made by an independent decision-maker who did not conduct your audit.

The audit

Your ISO 27001 audit, stage by stage

The same defined path for every applicant — the certification decision held independent of the audit team.

01

Stage 1

A readiness review of your documented ISMS, scope and objectives, and audit planning.

02

Stage 2

On-site or ICT-assisted assessment of the ISMS in operation against ISO 27001.

03

Decision

An independent decision-maker reviews the evidence and grants — or declines — certification.

04

Surveillance

Annual surveillance audits, then a full recertification at year three renews the cycle.

See the full certification process →
Audit duration

What determines your audit time

Audit duration for ISO 27001 is determined per ISO/IEC 27006-1 — never a flat rate. The main factors:

Effective headcount

The number of people — including shifts and part-time — is the primary driver of audit duration.

Sites & locations

How many sites and where. Multi-site sampling follows IAF MD1.

Scope & complexity

The range of activities and processes within your certified scope.

Shift patterns

Operations across multiple shifts can extend on-site audit time.

Existing certification

Transfers from another accredited body are reviewed under IAF MD2.

Delivery mode

On-site or ICT-assisted remote auditing per IAF MD4, matched to risk.

Fees are fixed for the defined audit programme. A fixed fee covers the audit; it never buys an outcome — certification is granted only on the evidence, by an independent decision-maker.

Applicability

Who ISO 27001 is for

ISO/IEC 27001 applies to any organisation that holds or processes valuable information. We routinely audit across:

Information technologySoftware & SaaSFinancial servicesTelecomsHealthcareGovernmentProfessional servicesData centresBPO
Related schemes

Often certified alongside ISO 27001

Begin certification

Apply for ISO 27001 certification

Tell us your scope, sites and employee numbers, and we'll return a fixed-fee audit quotation with the programme and timeline.

Prefer pricing first? Request an audit quotation →
No consultancy is offered or implied — Skyeblanc Certification audits and certifies only.