TL;DR: The process spans scoping, risk treatment, training, evidence collection, audits, and surveillance over a three-year cycle, with most organisations taking 6 to 12 months to reach certification, according to StrongDM's guide on ISO 27001 certification. The harder problem is not paperwork but proving that access governance, supplier oversight, and audit evidence still hold up as the environment changes.
At a glance
What this is: This is a practical guide to the ISO 27001 certification process, with the central finding that certification depends on documented scope, risk treatment, evidence, and continuous review rather than a one-time compliance exercise.
Why it matters: For IAM, IGA, PAM, and NHI teams, the article matters because ISO 27001 turns access control into an auditable governance discipline that must remain provable across users, suppliers, systems, and changing operational conditions.
Context
ISO 27001 certification is often treated as a document-heavy compliance project, but the standard is really an information security management system exercise. That means access control, supplier oversight, training evidence, and ongoing monitoring all have to be coordinated as part of one governed programme.
For identity teams, the practical gap is that certification asks not only whether access policies exist, but whether they can be justified, tracked, and revalidated during audit. That puts IAM, IGA, and privilege governance into the same control plane as risk treatment and continuous improvement.
The article’s own framing is typical of many ISO 27001 guides: it is broad, operational, and focused on process mechanics rather than deep control design. The governance challenge is therefore in how organisations evidence access decisions, not in whether they can name the standard’s clauses.
Key questions
Q: What breaks when ISO 27001 scope is too narrow?
A: A narrow scope can leave critical systems, suppliers, or access paths outside the ISMS, which weakens both security coverage and audit credibility. It may look efficient in the short term, but the organisation then has to explain why material risk was excluded. That mismatch often becomes the audit finding.
Q: Why does access governance matter during ISO 27001 audits?
A: Access governance matters because auditors are testing whether privilege decisions are documented, justified, and still accurate when the environment changes. If entitlements, exceptions, or supplier access are not traceable, the organisation may have controls on paper but not in practice. The result is weaker evidence for certification and a higher chance of remediation findings.
Q: What are the most common ISO 27001 access-control mistakes?
A: The most common mistakes are treating access as an IT admin issue, excluding too much from scope, and failing to maintain evidence for reviews, approvals, and revocations. Another recurring failure is assuming supplier access can be handled informally. ISO 27001 expects repeatable governance, not one-time clean-up work.
Q: Should organisations link IAM controls to ISO 27001 certification evidence?
A: Yes. IAM controls become much easier to defend when they are tied to the ISMS scope, the Statement of Applicability, and the organisation’s risk treatment records. Certification is not just about having controls, but about proving that identity decisions were made consistently and can be revalidated during surveillance audits.
Technical breakdown
What ISO 27001’s ISMS structure means for access governance
ISO 27001 is built around an information security management system, or ISMS, which ties policy, risk treatment, control selection, and monitoring into one auditable system. The access-control relevance is not limited to Annex A. Access decisions must align with the organisation’s scope, risk appetite, and evidence trail. That makes identity governance part of the management system, not a separate technical function. Clauses 4 through 10 require organisations to define context, leadership, planning, support, operation, performance evaluation, and improvement, so access control only passes scrutiny when it is documented as part of that lifecycle.
Practical implication: treat access governance as an ISMS control domain, not a standalone admin task.
Why the Statement of Applicability is an access-control test
The Statement of Applicability, or SoA, is the bridge between risk assessment and implemented controls. It records which Annex A controls are in scope, which are excluded, and why. For access governance, that matters because auditors are looking for consistent rationale, not just a list of enabled settings. If access-related controls are missing from the SoA, or if they are listed without a credible basis in risk and scope, the ISMS becomes harder to defend. In practice, the SoA is where identity governance decisions become auditable evidence rather than informal policy intent.
Practical implication: map access, privilege, and supplier-access controls explicitly into the SoA with a defensible inclusion or exclusion rationale.
How continuous monitoring changes certification from point-in-time to ongoing
ISO 27001 does not end at the stage 2 audit. Surveillance audits and recertification mean the organisation must show that controls still work after the first assessment, not only during preparation. That is especially relevant to access governance because entitlements drift, roles change, suppliers rotate, and evidence can decay quickly. The article’s maintenance phase points to a core truth: continuous improvement is part of the standard, so access control evidence must stay current enough to survive recurring review. This is where operational discipline becomes the difference between passing once and remaining certifiable.
Practical implication: build recurring access reviews, evidence capture, and control testing into the certification operating rhythm.
NHI Mgmt Group analysis
ISO 27001 certification is really an evidence discipline, not a documentation exercise. The guide makes clear that the standard demands scoping, risk treatment, training, and ongoing monitoring, but the audit question is whether those decisions remain provable. For identity programmes, that shifts the focus from having access policies to proving that access governance is consistently applied. Practitioners should treat every access decision as audit evidence in waiting.
The access-governance gap in ISO 27001 programmes is usually not control absence but control ambiguity. Teams often know they need access control, but they do not define which identities, suppliers, systems, and exceptions sit inside the certifiable boundary. That creates weak points in the Statement of Applicability and in the audit trail. The practical conclusion is that scope discipline is an identity control, not just a project management task.
Annex A access controls only matter when they are anchored to lifecycle governance. The standard’s control model spans people, assets, suppliers, and operations, which means identity decisions have to survive change across onboarding, role shifts, third-party access, and offboarding. This is where IAM and IGA become certification infrastructure rather than supporting tools. Teams that cannot show lifecycle consistency will struggle to show control consistency.
Continuous certification pressure exposes weak entitlement governance faster than policy reviews do. Surveillance audits force organisations to demonstrate that access controls still work after implementation, which makes stale permissions, undocumented exceptions, and missing recertification cycles visible. That is why access review cadence, evidence capture, and supplier-access oversight are not peripheral to ISO 27001. They are the mechanisms that keep the management system credible.
ISO 27001 is converging with identity governance maturity, not replacing it. The standard does not create new access principles, but it does force organisations to operationalise existing ones with traceable scope, repeatable risk treatment, and measurable oversight. That means certification readiness is increasingly a proxy for access governance maturity. Practitioners should expect auditors to test the consistency of the whole identity lifecycle, not just the written policy set.
What this signals
Scope discipline is the first identity control in ISO 27001. If the access boundary is too narrow, important identities and supplier paths sit outside the certifiable system. If it is too broad, the programme becomes hard to evidence and harder to maintain. The practical challenge is to align access scope with what the business can actually govern.
Statement of Applicability thinking should be extended to identity governance. The useful question is not just which Annex A controls exist, but which access, privilege, and supplier decisions can be defended under audit. That makes entitlement governance part of the management system design, not a separate cleanup activity.
Access reviews only matter when they produce durable evidence. Recertification, surveillance audits, and corrective actions all depend on records that can be traced back to real decisions. Teams that cannot prove who approved access, when it changed, and why it stayed or went will struggle to sustain certification over time.
For practitioners
- Define the certifiable access boundary List the users, systems, suppliers, and privileged paths that truly fall inside the ISMS so scope matches audit reality.
- Write the Statement of Applicability around access decisions Document which Annex A access-related controls apply, why they apply, and what evidence will prove they are operating.
- Tie access review cadence to surveillance audits Schedule recurring entitlement reviews and preserve the records that show who approved, revoked, or accepted each exception.
- Harden supplier access governance Track third-party access paths, contract changes, and offboarding decisions so supplier relationships do not outlive their authorisation.
- Turn training and evidence into a repeatable control Capture attendance, role definitions, monitoring results, and corrective actions in a form that can survive stage 1 and stage 2 review.
Key takeaways
- ISO 27001 certification is as much about governed access evidence as it is about policies, clauses, and audit paperwork.
- The biggest failure mode is usually unclear scope and weak justification for which identities, suppliers, and access paths are inside the ISMS boundary.
- Teams that connect IAM, access reviews, supplier oversight, and evidence retention to the certification cycle are better positioned to pass and keep passing audits.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access Control | ISO 27001 access control is central to the certification process discussed here. |
| A.5.18 — Access Rights | The article’s focus on reviews, scope, and ongoing maintenance maps to access-right governance. | |
| A.5.8 — Information security in project management | The certification process is presented as a managed programme with scope, planning, and controls. | |
| Recommendation — Document and enforce access control decisions within the ISMS scope and evidence them for audit. Review and recertify access rights on a recurring basis and retain the approval trail. Embed security requirements into the certification project so access evidence is planned from the start. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article repeatedly returns to proving and maintaining entitlement governance. |
| Recommendation — Align entitlement management and review cycles to the ISMS evidence set. | ||
Key terms
- Information Security Management System: An information security management system is the operating structure an organisation uses to manage security policies, controls, responsibilities, and evidence. Under ISO 27001, it is the framework auditors assess, but its real strength depends on whether access, logging, and remediation work consistently in practice.
- Statement of Applicability: A Statement of Applicability lists the security controls an organisation has selected, excluded, or adapted for its ISMS. It matters because it forces explicit justification, which makes audit discussions easier and exposes weak control decisions that were previously implied or undocumented.
- Surveillance Audit: A surveillance audit is a recurring review used to confirm that certification controls remain effective between renewal cycles. It is not a one-time checklist. Organisations must show continued control operation, corrective action, and evidence quality, or they risk non-conformance and loss of certification.
- Risk Treatment Plan: A Risk Treatment Plan records how identified risks will be handled through mitigation, avoidance, transfer, or acceptance. In ISO 27001, it is a governance artifact that shows why a control exists and how the organisation expects it to reduce exposure.
Deepen your knowledge
NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org