ISO/IEC 27001:2022 Certification

IAR Accredited

IAR-112, USA

120+ Certificates

Issued since 2014 · verifiable online

Independent Decisions

Decision-makers separate from the audit team

Remote & On-site

Audits per IAF MD 4

ISO/IEC 27001:2022 Certification

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS) — a risk-based framework for protecting the confidentiality, integrity and availability of information. Company Certification International (CCI) audits and certifies ISMS implementations under our IAR-112 accreditation, with certificates verifiable online.

Who needs ISO 27001 certification?

  • SaaS, cloud and technology companies whose enterprise customers require it before signing
  • Finance, healthcare, BPO and professional-services organizations handling sensitive or regulated data
  • Suppliers bidding into government contracts or into already-certified supply chains
  • Telecom, IT-managed-services and data-centre operators
  • Any organization that needs to demonstrate a working information security management system to a customer, insurer or regulator

Business benefits

  • A structured, auditable way to identify and treat information-security risk
  • A common answer to customer and vendor-risk security questionnaires
  • Fewer duplicated one-off customer security audits once you can point to a current certificate
  • A documented basis for meeting contractual, insurance or regulatory expectations around data protection
  • A structure that scales as headcount, sites and systems grow

Certification requirements

ISO/IEC 27001:2022 certification requires your organization to operate an ISMS that includes: a defined scope and information-security policy; a risk assessment and risk-treatment process; a Statement of Applicability against the Annex A controls; management commitment and defined roles and responsibilities; an internal audit programme; and management review of the ISMS. Your organization — or a consultant of your choosing — designs, implements and documents the ISMS; CCI's role is independent certification, not implementation.

How certification works

Stage 1 audit

A documentation and readiness review: CCI checks that your ISMS scope, policy, risk assessment, Statement of Applicability and core documentation are in place and ready for a Stage 2 assessment, and identifies any gaps before it's scheduled.

Stage 2 audit

An assessment of the ISMS in operation — evidence that the controls in your Statement of Applicability are implemented and effective, that internal audits and management review have taken place, and that the system reflects real day-to-day practice rather than documentation alone.

Certification decision

Following a successful Stage 2 audit, an independent certification decision is made by CCI personnel who were not involved in conducting the audit — in line with the impartiality requirements of ISO/IEC 17021-1 — and your certificate is issued.

Annual surveillance and the three-year cycle

Certificates are valid for three years. Annual surveillance audits confirm the ISMS continues to operate effectively between certification decisions, with a full recertification audit at the end of the three-year cycle.

Remote and on-site audits

Stage 1, Stage 2 and surveillance audits can be delivered remotely, on-site, or as a blend of both, in line with IAF MD 4 guidance on the use of information and communication technology in auditing. Which mix suits your organization depends on your sites, systems and the scope of certification — we'll agree this with you before scheduling.

What affects your quotation

Audit duration and fees depend on factors including your employee count, the number of sites in scope, the complexity of the systems and data covered by the ISMS, whether the audit is delivered remotely or on-site, and whether you're certifying ISO 27001 alongside another standard (see our integrated management system certification page). Request a quote using the form on this page for figures specific to your organization.

Accreditation route

CCI issues ISO 27001 certificates under our IAR-112 accreditation (International Accreditation Registrar, USA). Where a buyer or tender specifically requires certification under a Global ACI MRA (formerly IAF MLA) signatory accreditation, CCI can coordinate that certification through our partner certification body instead — see CCI IAR certification vs. MRA-recognized certification for how the two routes differ and which one fits your situation.

Why certify with Company Certification International

CCI carries out ISO 27001 certification audits against a structured, independent process, with every certificate publicly verifiable. CCI does not provide management-system consultancy, documentation drafting or implementation support. Engaging ISOXPERT Management & IT Consultants — an independent consulting and technology firm under common ownership with CCI — any other consultant, or no consultant, has no bearing on any certification decision.

Frequently asked questions

How long does ISO 27001 certification take? Typically 6–8 weeks from application to certification decision, subject to your organization's readiness for Stage 1.

How much does ISO 27001 certification cost? Cost depends on your employee count, sites and scope. Request a fixed quote using the form on this page.

What's the difference between Stage 1 and Stage 2? Stage 1 checks your ISMS documentation and readiness; Stage 2 assesses whether the ISMS is actually operating as documented. Both must be completed before a certification decision.

Can our audits be fully remote? Often yes, subject to IAF MD 4 criteria and the nature of your scope — we'll confirm the right mix of remote and on-site audit time when we scope your certification.

Can we transfer an existing ISO 27001 certificate to CCI? Yes — see our transfer of ISO certification page for how transfer audits work.

Does CCI provide ISO 27001 consultancy or documentation help? No. CCI's role is independent certification only; consultancy is a separate service delivered by separate companies, and using one has no bearing on your certification decision.

Get Certified

Free consultation & quotation

Standard(s) Required — tick one, or several for an IMS

We respond within 24 hours

Ready to get ISO/IEC 27001:2022 Certification?

Talk to our team for a scoping discussion and a clear certification quotation — or verify an existing CCI certificate.

ISO/IEC 27001:2022 Certification | Company Certification International