Certification of Information Security Management Systems (ISMS) According to ISO/IEC 27001
Your Expert for Questions:
Information Security Ensures Trust
We live in a digital and networked world today. Protecting information therefore presents a major challenge for companies. An integrated Information Security Management System (ISMS) helps protect the confidentiality, integrity, and availability of information within a company. It ensures that risks are identified, assessed, and minimized, for example, to protect against cyberattacks and data loss. This strengthens the trust of customers and business partners and fulfills legal requirements.
Companies can demonstrate their responsible handling of sensitive information and data, for example, through independent certification of their information security management system. The ISMS is audited according to the internationally recognized standard ISO/IEC 27001 and certified for compliance with the criteria for standard conformity using a sample procedure.
ISMS Certification: Your Benefits at a Glance:
Improving Information Security
ISO/IEC 27001, an internationally recognized standard for information security, provides a comprehensive framework for identifying, assessing, and managing risks and opportunities. Implementing this standard helps you continuously improve your information security processes and procedures and identify and remediate vulnerabilities.
Increase trust and credibility
With ISO/IEC 27001 certification, you can increase the trust placed in you and your credibility with customers, partners and stakeholders by demonstrating that you have taken appropriate measures to protect information.
Compliance With Legal and Regulatory Requirements
ISO/IEC 27001 certification helps you comply with data protection requirements and other legal and regulatory requirements.
Overview of ISMS Certification
Normative requirements for the ISMS
The requirements for certification of the information security management system are specified in the ISO/IEC 27001:2022 standard. This standard describes how a company or organization can ensure confidentiality, integrity, and availability of information. The standard consists of the following sections:
- Scope
- Normative references
- Terms
- Context of organization
- Leadership
- Planning
- Support
- Operations
- Evaluation of performance
- Improvement
These sections correspond to the “high-level structure” and are uniform within the currently valid management systems to enable different management systems to be integrated within the company. To achieve ISO/IEC 27001 certification, an organization needs to show compliance with all requirements specified in the standard. This is done through an independent review of the documentation and an on-site audit of the implementation and effectiveness of the ISMS.
Challenges for Companies
ISO/IEC 27001 certification is a challenging task for any company, as it involves a comprehensive information security management system (ISMS) that ensures that the company’s sensitive data and information is protected from cyberattacks, data loss, or unauthorized access.
Some of the specific challenges that companies must address when achieving ISO/IEC 27001 certification include:
- Comprehensive documentation: The company must create and maintain comprehensive documentation of all relevant information security policies, procedures, and controls.
- Implementation of security measures: The company must implement a comprehensive information security management system and implement security measures such as access controls, network security, security monitoring, emergency management, and employee training.
- Resources: The company must allocate sufficient resources to effectively operate and maintain the ISMS, including financial resources, employee training, and technical infrastructure.
- Compliance: The company must ensure that all legal requirements, including data protection and security requirements, are met and that it is state-of-the-art.
- Internal audits and reviews: The company must conduct regular internal audits and reviews to ensure the ISMS is effective and that all security controls are functioning correctly.
- External certification audit: The company must undergo an external certification audit by an independent third party to demonstrate that it meets the requirements of ISO/IEC 27001.
These challenges require a comprehensive analysis of business processes and continuous improvement of the information security management system to ensure the company is always up to date, and its systems and processes are continuously improved.
Important Documents for an ISMS
Various documents are required for ISO/IEC 27001 certification. Here are some of the mandatory documents:
- Information Security Policy: This document describes the objectives and principles for information security in your organization.
- Risk Assessment and Treatment Plan: This is a document that describes your risk assessment and treatment processes. It should include how you identify threats, assess risks, plan and implement treatment measures, and measure the effectiveness of these measures.
- Security Concept: A documentation of the protective measures taken to address the risks identified in the risk assessment.
- Security Policies and Procedures: A documentation of the policies and procedures the organization follows to ensure that information security is maintained.
- Business continuity plan: A documentation of the procedures to be initiated in the event of a security breach or security incident.
- Training Documentation: A documentation of the training measures employees has undergone information security.
- Statement of Applicability (SoA): This document describes which ISO/IEC 27001 controls you have implemented and which you have not. It should also explain your reasons for not implementing certain controls.
- Internal Audits: You must conduct internal audits to ensure that your information security management system processes are functioning properly. Documentation of audit reports, audit steps, corrective actions, traceability, and audit evidence should be collected.
- Logs and Records: Documentation of audit logs, security events, and other records that document the operation and monitoring of the information security system.
- Management Reviews: Your top management, which is usually senior management, should regularly evaluate the effectiveness of your information security management system and make appropriate decisions. Documentation of evaluations, feedback, and decisions should be collected.
These documents are just a few examples of the type of documentation required for ISO/IEC 27001 certification. The exact documents required may vary depending on the company’s situation.
Other important standards from the ISO/IEC 2700x family
ISO/IEC 27001 certification refer to the international standard for information security management systems (ISMS) and require organizations to meet certain standards and requirements. Here are some of the key standards to consider when preparing for ISO/IEC 27001 certification:
- ISO/IEC 27002: This standard provides guidelines for selecting, implementing, and managing security measures and controls that can be used as part of an ISMS.
- ISO/IEC 27003: This standard specifies the framework for planning and implementing ISMS projects.
- ISO/IEC 27004: This standard describes how an organization can establish a system for measuring, monitoring, and reporting performance related to its ISMS.
- ISO/IEC 27005: This standard describes how to conduct information security risk assessments and risk management.
- ISO/IEC 27006: This standard specifies the requirements for organizations conducting ISMS certification audits.
- ISO/IEC 27701: This standard specifies the requirements for a data protection management system (DPMS), which can be part of an ISMS.
These standards are important for ISO/IEC 27001 certification because they support organizations in establishing and implementing effective ISMS.
What are the changes for companies under the new ISO/IEC 27001:2022 standard?
The updated standard makes it more process-oriented and easier to integrate into a company’s day-to-day process landscape. The standard has not been completely revised, but relevant changes have been incorporated.
The most notable change was made in Appendix A. Each measure is classified into 5 attributes:
- Control type (preventive, detective, corrective)
- Information security characteristics (confidentiality, integrity, availability)
- Cybersecurity concepts (identify, protect, detect, respond, recover)
- Operational capabilities (asset management, threat & vulnerability management, legal aspects & compliance, information security event management)
- Security domains (governance & ecosystem, protection, defense, resilience)
In section 6.1.3 c), the “measure objectives” have been deleted, and the term “measure” has been editorially corrected to the new term “information security measure”. In section 6.1.3 d), ambiguities were eliminated by changing the wording.
In the previous version of ISO/IEC 27001, 114 measures were listed in 14 sections. In the new revision ISO/IEC 27001:2022, this number has been reduced to 93 measures in 4 sections, of which 11 measures have been newly formulated, 24 measures have been merged with previous measures, and 58 measures have been updated in content. Based on this, the structure was reviewed and rearranged.
ISO/IEC 27001:2022-10 replaces the previous version from 2013. The transition period is a total of three (3) years or 36 months. This transition period ends on October 31, 2025. Detailed information on the requirements is provided in IAF MD 26:2022. An initial certification audit is usually conducted directly according to the new requirements of ISO/IEC 27001:2022. For existing certifications, the certificate must be reviewed and confirmed for the new revision in a “transition audit,” which can be a surveillance audit, a recertification audit, or a special audit for the transition or takeover audit. An additional on-site audit time of no less than 0.5 working days (TW) must be scheduled for the additional requirements.
Certificates issued according to ISO/IEC 27001:2013 that were not converted in a transition audit will automatically expire on October 31, 2025. Starting May 1, 2023, DAkkS will conduct the assessments for the accreditation conversion. After confirmed assessment and updated issue of the accreditation certificates, the certification body may conduct transition audits according to the new revision ISO/IEC 27001:2022.
Our expertise, your advantage
The Path to Your ISMS Certification
Your company should prepare accordingly for ISMS certification so that it can be completed with as little cost and time as possible.
Key prerequisites for the certification of information security management systems are:
- Compliance with the ISMS with the requirements of ISO/IEC 27001
- Appropriate information security expertise among all involved
- The company’s ability to complete the certification process in a time- and cost-efficient manner.
ISO/IEC 27001 certification follows a standardized process. It generally looks like this:
Implementation Phase
In this phase, you must first ensure that you meet all the requirements for certification. This includes having implemented an information security management system (ISMS) that meets the requirements of the standard. You should also have conducted a risk analysis and documented how you manage risks that could affect confidentiality, integrity, or availability of information.
Pre-audits (dry runs) have proven to be a useful tool in preparing for certification. During a pre-audit, an external service provider can review and assess the implementation of your company’s existing requirements and the management system under consideration at your headquarters and locations regarding the desired ISO/IEC 27001 certification, as well as identify any weaknesses in compliance with the standard. While specific areas will be examined, a comprehensive audit comparable to an initial certification will not be conducted.
Important: PwC Certification Services GmbH itself does not offer any consulting or pre-audits for the implementation of your management system.
Initial Certification Audit – Stage 1
If you are ready, you can apply for certification to us as an accredited certification body. During the Stage 1 audit, an auditor approved by us (at least partially on-site) will assess whether your company is fundamentally ready for the Stage 2 audit. This will include, for example, checking whether your ISMS documentation complies with the requirements of ISO/IEC 27001.
If any weaknesses are identified during the audit, they must be analyzed and remedied with appropriate corrective measures. You have a specific deadline within which to implement these measures.
Initial Certification Audit – Stage 2
Once you have successfully implemented the corrective actions, the Stage 2 audit will be conducted. This always includes an on-site audit and covers all relevant locations of the organization to be certified. In addition to reviewing the documentation, the auditor will conduct interviews with employees to review the processes and procedures of the implemented ISMS in accordance with the requirements of ISO/IEC 27001.
Assessment and certification decision
The certification body assesses and decides compliance with the requirements and, if necessary, corrective actions resulting from the audit. You will receive a certificate valid for three years once all standard requirements are met.
Surveillance audits
To review the effectiveness of the ISMS and ensure that it continues to meet the requirements of the standard, surveillance audits are carried out regularly. These usually take place annually. The first surveillance audit after initial certification must have been conducted within 12 months of the certification decision. The optimal time to plan the surveillance audit is the day and month of the certificate expiry date minus three (3) months. A time window of minus (-) three (3) months and plus (+) three months can be chosen flexibly around this date to take into account the size of your company, the scope, the complexity of your management system with your products, services and processes as well as your stated level of effectiveness of your management system – taking into account factors such as the time of year and opportunities for certification due to, for example, temporary construction sites or activities.
Recertification
After three years, you must undergo recertification to ensure you continue to meet the requirements of the standard. The recertification audit must be fully completed before the certification audit; otherwise, an initial certification audit with Stages 1 and 2 will be required.
Our expertise, your advantage
PwC Certification Services as an accredited certification body.
Information security management system certifications may only be conducted by certification bodies accredited by the national accreditation body according to DIN EN ISO/IEC 17021-1. PwC Certification Services is one such certification body accredited by the DAkkS (German Accreditation Body) (accreditation number: D-ZM-16030-02-02) and is therefore your competent certification partner for standard-compliant verification of your ISMS by an independent and neutral third party. Further information about our accreditations and authorizations can be found here.
Documents for download

Valid Certificates
Our certificates inspire trust! They confirm our clients’ compliance with the underlying norms and standards, thus creating added value for marketing their services in the global marketplace. Certification grants the right to refer to the certificates we have been awarded according to established rules. This helps our clients and protects the PwC brand.
More about our valid certificates


