
IAR Accredited
IAR-112, USA
120+ Certificates
Issued since 2014 · verifiable online
Independent Decisions
Decision-makers separate from the audit team
Remote & On-site
Audits per IAF MD 4
ISO/IEC 27001:2022 Certification
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS) — a risk-based framework for protecting the confidentiality, integrity and availability of information. Company Certification International (CCI) audits and certifies ISMS implementations under our IAR-112 accreditation, with certificates verifiable online.
Who needs ISO 27001 certification?
- SaaS, cloud and technology companies whose enterprise customers require it before signing
- Finance, healthcare, BPO and professional-services organizations handling sensitive or regulated data
- Suppliers bidding into government contracts or into already-certified supply chains
- Telecom, IT-managed-services and data-centre operators
- Any organization that needs to demonstrate a working information security management system to a customer, insurer or regulator
Business benefits
- A structured, auditable way to identify and treat information-security risk
- A common answer to customer and vendor-risk security questionnaires
- Fewer duplicated one-off customer security audits once you can point to a current certificate
- A documented basis for meeting contractual, insurance or regulatory expectations around data protection
- A structure that scales as headcount, sites and systems grow
Certification requirements
ISO/IEC 27001:2022 certification requires your organization to operate an ISMS that includes: a defined scope and information-security policy; a risk assessment and risk-treatment process; a Statement of Applicability against the Annex A controls; management commitment and defined roles and responsibilities; an internal audit programme; and management review of the ISMS. Your organization — or a consultant of your choosing — designs, implements and documents the ISMS; CCI's role is independent certification, not implementation.
How certification works
Stage 1 audit
A documentation and readiness review: CCI checks that your ISMS scope, policy, risk assessment, Statement of Applicability and core documentation are in place and ready for a Stage 2 assessment, and identifies any gaps before it's scheduled.
Stage 2 audit
An assessment of the ISMS in operation — evidence that the controls in your Statement of Applicability are implemented and effective, that internal audits and management review have taken place, and that the system reflects real day-to-day practice rather than documentation alone.
Certification decision
Following a successful Stage 2 audit, an independent certification decision is made by CCI personnel who were not involved in conducting the audit — in line with the impartiality requirements of ISO/IEC 17021-1 — and your certificate is issued.
Annual surveillance and the three-year cycle
Certificates are valid for three years. Annual surveillance audits confirm the ISMS continues to operate effectively between certification decisions, with a full recertification audit at the end of the three-year cycle.
Remote and on-site audits
Stage 1, Stage 2 and surveillance audits can be delivered remotely, on-site, or as a blend of both, in line with IAF MD 4 guidance on the use of information and communication technology in auditing. Which mix suits your organization depends on your sites, systems and the scope of certification — we'll agree this with you before scheduling.
What affects your quotation
Audit duration and fees depend on factors including your employee count, the number of sites in scope, the complexity of the systems and data covered by the ISMS, whether the audit is delivered remotely or on-site, and whether you're certifying ISO 27001 alongside another standard (see our integrated management system certification page). Request a quote using the form on this page for figures specific to your organization.
Accreditation route
CCI issues ISO 27001 certificates under our IAR-112 accreditation (International Accreditation Registrar, USA). Where a buyer or tender specifically requires certification under a Global ACI MRA (formerly IAF MLA) signatory accreditation, CCI can coordinate that certification through our partner certification body instead — see CCI IAR certification vs. MRA-recognized certification for how the two routes differ and which one fits your situation.
Why certify with Company Certification International
CCI carries out ISO 27001 certification audits against a structured, independent process, with every certificate publicly verifiable. CCI does not provide management-system consultancy, documentation drafting or implementation support. Engaging ISOXPERT Management & IT Consultants — an independent consulting and technology firm under common ownership with CCI — any other consultant, or no consultant, has no bearing on any certification decision.
Frequently asked questions
How long does ISO 27001 certification take? Typically 6–8 weeks from application to certification decision, subject to your organization's readiness for Stage 1.
How much does ISO 27001 certification cost? Cost depends on your employee count, sites and scope. Request a fixed quote using the form on this page.
What's the difference between Stage 1 and Stage 2? Stage 1 checks your ISMS documentation and readiness; Stage 2 assesses whether the ISMS is actually operating as documented. Both must be completed before a certification decision.
Can our audits be fully remote? Often yes, subject to IAF MD 4 criteria and the nature of your scope — we'll confirm the right mix of remote and on-site audit time when we scope your certification.
Can we transfer an existing ISO 27001 certificate to CCI? Yes — see our transfer of ISO certification page for how transfer audits work.
Does CCI provide ISO 27001 consultancy or documentation help? No. CCI's role is independent certification only; consultancy is a separate service delivered by separate companies, and using one has no bearing on your certification decision.
Get Certified
Free consultation & quotation
Ready to get ISO/IEC 27001:2022 Certification?
Talk to our team for a scoping discussion and a clear certification quotation — or verify an existing CCI certificate.
