Quick Answer
ISO 27001:2022 certification — the international standard for Information Security Management Systems (ISMS) — typically takes 6–12 months for small-to-medium organizations with full commitment. The process passes through eight stages: gap analysis, risk assessment, the Statement of Applicability, control implementation, training, internal audit, Stage 1 and Stage 2 certification audits, then annual surveillance. The 2022 version contains 93 Annex A controls in 4 themes (down from 114 controls in the 2013 version), and since October 31, 2025, 2013-version certificates are no longer valid. The certificate is valid for 3 years with annual surveillance audits.
What Is ISO 27001?
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS) — a systematic, risk-based framework for managing information security. Unlike a technical checklist, ISO 27001 governs how an organization builds governance, assesses risk, selects relevant controls, and improves them continuously.
ISO 27001 certification is issued by an accredited certification body after an organization proves — through independent audit — that it operates an ISMS meeting all requirements of the standard. The current version, ISO/IEC 27001:2022, was published in October 2022, and since October 31, 2025, all certificates against the 2013 version are no longer valid.
An ISMS, Not Just an 'IT Certificate'
ISO 27001 spans people, processes, and technology. It requires top management commitment, documented risk assessment, and a continual improvement cycle (Plan-Do-Check-Act) — not merely installing firewalls and antivirus.
Why Do Organizations Need ISO 27001 Certification?
For many organizations in Indonesia, ISO 27001 has shifted from a 'nice to have' to a business prerequisite: government tenders, enterprise contracts, and financial sector regulations increasingly require it explicitly.
70,000+
Active ISO 27001 certificates worldwide
ISO Survey
USD 4.4M
Global average cost of a single data breach
IBM Cost of a Data Breach
Oct 31, 2025
Transition deadline — 2013-version certificates are no longer valid
IAF Resolution
Customer & Partner Trust
BusinessA certificate from an independent auditor is objective proof that your information security is managed seriously — far more convincing than self-declared claims.
Tender & Contract Prerequisite
BusinessState-owned enterprises, financial institutions, and multinationals increasingly require ISO 27001 in procurement and vendor assessment processes.
Regulatory Compliance
ComplianceAn ISO 27001-based ISMS becomes the foundation for PDP Law, OJK, and electronic system operator compliance — one framework serving many regulatory obligations.
Reduced Incident Risk
SecuritySystematic risk assessment forces the organization to find and address weaknesses before they are exploited — lowering both incident frequency and impact.
Operational Efficiency
OperationsDefined policies, roles, and processes reduce chaos during incidents, speed up onboarding, and eliminate duplicated controls.
Competitive Advantage
BusinessIn an increasingly security-conscious market, certification is a real differentiator — especially for SaaS providers, fintechs, and managed service providers.
ISO 27001:2022 vs 2013 — What Changed?
The biggest change in the 2022 version is in Annex A: from 114 controls across 14 domains to 93 controls across 4 themes. Eleven new controls were added to address the modern threat landscape — cloud, threat intelligence, and data leakage.
The 11 New Controls in the 2022 Version
A.5.7 Threat Intelligence, A.5.23 Cloud Services Security, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering, and A.8.28 Secure Coding.
| Aspect | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Annex A control count | 114 controls | 93 controls (consolidated) |
| Control structure | 14 domains (A.5–A.18) | 4 themes: Organizational, People, Physical, Technological |
| New controls | — | 11 new controls, including Threat Intelligence, Cloud Security, Data Masking, DLP, Web Filtering, and Secure Coding |
| Control attributes | None | 5 attributes (control type, InfoSec properties, cybersecurity concepts, operational capabilities, security domains) |
| Main clauses (4–10) | HLS structure | Minor adjustments — harmonized with Annex SL |
| Transition status | Invalid since October 31, 2025 | The only certifiable version |
Standard Structure: Clauses 4–10
The mandatory requirements of ISO 27001 live in Clauses 4 through 10 — all of which must be met without exception. Annex A is a reference: controls are selected based on risk assessment results and declared in the Statement of Applicability (SoA).
- 1
Clause 4 — Context of the Organization
Understanding internal/external issues and interested parties' needs, and clearly defining the ISMS scope.
- 2
Clause 5 — Leadership
Top management commitment, the information security policy, and assignment of roles, responsibilities, and authorities.
- 3
Clause 6 — Planning
Risk assessment, the risk treatment plan, the Statement of Applicability, and measurable information security objectives.
- 4
Clause 7 — Support
Resources, personnel competence, awareness, communication, and control of documented information.
- 5
Clause 8 — Operation
Executing the risk treatment plan and day-to-day operational controls — this is where the ISMS 'lives'.
- 6
Clause 9 — Performance Evaluation
Monitoring and measurement, internal audits, and periodic management reviews.
- 7
Clause 10 — Improvement
Handling nonconformities, corrective actions, and continual improvement of the ISMS.
Annex A: 93 Controls in 4 Themes
The 2022 Annex A groups its 93 controls into four more intuitive themes. Not every control must be implemented — but every exclusion must be justified in the Statement of Applicability based on risk assessment results.
Organizational (37 controls)
A.5Policies, roles and responsibilities, threat intelligence, asset management, information classification, supplier security, cloud security, and business continuity readiness.
People (8 controls)
A.6Employee screening, terms of employment, awareness and training, disciplinary process, post-employment responsibilities, NDAs, remote working, and incident reporting.
Physical (14 controls)
A.7Physical security perimeters, physical access control, office and facility security, physical monitoring, clear desk, equipment security, and secure media disposal.
Technological (34 controls)
A.8Endpoint protection, privileged access, cryptography, backups, logging and monitoring, vulnerability management, DLP, web filtering, secure coding, and network security.
The End-to-End Certification Process
The journey to certification typically passes through the following eight stages. The duration of each depends on organization size, scope complexity, and the maturity of existing controls.
Gap Analysis & Scope Definition
Compare the current state against ISO 27001:2022 requirements, then define the ISMS scope — which business units, locations, systems, and services fall within certification coverage.
Risk Assessment & Risk Treatment Plan
Identify information assets, threats, and vulnerabilities; assess likelihood and impact; then decide risk treatment: mitigate, transfer, avoid, or accept.
Statement of Applicability (SoA)
The key document declaring which Annex A controls are implemented (with their implementation status) and which are excluded, with justification.
Control Implementation & ISMS Documentation
Implement controls per the risk treatment plan and produce the mandatory documentation:
- The information security policy and its supporting policies
- Operational procedures, technical standards, and work instructions
- Evidence of execution: log reviews, access reviews, testing results
Awareness & Training
All personnel in scope must understand the policies and their role in the ISMS. External auditors almost always interview staff across functions to test exactly this.
Internal Audit & Management Review
An internal audit of all standard requirements and implemented controls, followed by a management review. Findings must be addressed before the certification audit — both are mandatory prerequisites.
Stage 1 & Stage 2 Certification Audits
Stage 1: the auditor assesses ISMS documentation readiness. Stage 2: the auditor tests implementation effectiveness in practice — interviews, observation, and evidence sampling. Passing Stage 2 means the certificate is issued.
Surveillance & Recertification
The certificate is valid for 3 years with annual surveillance audits. In year three, a full recertification audit takes place. The ISMS must stay alive — not be revived only when audits approach.
Timeline & Cost Components
The most common questions: how long, and how much? The answer depends on organization size and starting maturity — but the following framework offers a realistic planning baseline.
Cost Components to Budget For
Certification body fees (Stage 1, Stage 2, and annual surveillance audits), consultant fees (optional but accelerating), technical remediation investment (tooling, hardening), personnel training, and internal team time. Audit fees are generally calculated in man-days determined by the number of personnel in scope.
| Phase | Estimated Duration | Notes |
|---|---|---|
| Gap analysis & scoping | 2–4 weeks | The clearer the scope, the more efficient the entire process |
| Risk assessment & SoA | 3–6 weeks | Depends on the number of assets and processes in scope |
| Control implementation & documentation | 2–6 months | The longest phase — driven by existing control maturity |
| ISMS operation (evidence collection) | 2–3 months | Auditors need proof the ISMS has been running, not freshly created |
| Internal audit & management review | 2–4 weeks | Must be completed, with follow-ups, before Stage 1 |
| Stage 1 + Stage 2 certification audits | 4–8 weeks | Including time to close minor findings |
| Typical total | 6–12 months | Small-to-medium organizations with full commitment |
Common Mistakes That Derail Certification
Certification failure patterns tend to repeat. Recognizing them early saves months of effort and re-audit costs.
A Paper-Only ISMS
Policies copied from templates without reflecting actual practice. Auditors test implementation — beautiful documents without execution evidence are a major finding.
An Overly Broad Scope
Including the entire organization in a first certification makes the project unmanageable. Start with the most critical business unit or service, then expand gradually.
No Top Management Support
ISO 27001 requires active leadership — not just a signature. Without an executive sponsor, resource allocation and process changes stall.
A Box-Ticking Risk Assessment
Risk assessments performed merely to satisfy requirements produce controls disconnected from real threats — and experienced auditors spot this immediately.
Insufficient Operational Evidence
An ISMS that has only run for two weeks before the audit. Auditors need a track record: monthly log reviews, periodic access reviews, incident reports, and management review minutes.
Treating the Certificate as the Finish Line
Annual surveillance tests consistency. An ISMS abandoned after the certificate is issued will fail its first surveillance — and the certificate can be suspended.
Tips for Certification Success
Secure an Executive Sponsor from Day One
Make information security a management agenda item with clear KPIs. Leadership commitment is an explicit Clause 5 requirement.
Start with a Realistic Scope
Choose a scope that is meaningful to the business yet manageable — for example, the flagship service customers ask about most.
Integrate with Other Compliance Obligations
Map ISO 27001 controls to the PDP Law, OJK regulations, and SOC 2 simultaneously. One control set serving many obligations is far more efficient.
Automate Evidence Collection
Use GRC tooling to manage the risk register, SoA, and control evidence — drastically reducing manual workload before audits.
Train Your Own Internal Auditors
In-house internal audit competence keeps the improvement cycle running without constant reliance on external parties.
Run the ISMS for at Least 2–3 Months Before the Audit
Give controls time to generate sufficient operational evidence — this is what auditors look for in Stage 2.
Choose an Accredited Certification Body
Ensure the certification body is accredited (KAN or international accreditation such as UKAS/ANAB) so your certificate is recognized by global customers.
Closing
ISO 27001 is not the end goal — it is a framework for managing information security with discipline and continuity. The certificate is a byproduct of an ISMS that genuinely runs; organizations that understand this order of things end up with both.
With the 2013-version transition deadline behind us and market demands continuing to rise, the best time to begin the ISO 27001:2022 journey is now. Start with an honest gap analysis — from there, the entire roadmap becomes clear and measurable.
Before signing an implementation contract, it helps to understand the full cost breakdown of ISO 27001 certification in Indonesia first. If you want guidance from gap analysis through to audit, that is what our GRC services cover.
Already Have Security Controls? You're Closer Than You Think
Many organizations turn out to be running 40–60% of Annex A controls without realizing it — they simply lack documentation and measurement. A professional gap analysis maps your objective starting position and builds a realistic set of priorities.
The ISO 27001 certification journey is far faster and more efficient with the right guidance. Cloudsphere supports your organization from gap analysis, ISMS documentation, and control implementation through to certification audit support.
Frequently Asked Questions
What is ISO 27001 certification?
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS) — a systematic, risk-based framework for managing information security spanning people, processes, and technology. Certification is issued by an accredited certification body after an organization proves through independent audit that it operates an ISMS meeting all requirements of the standard. The current version, ISO/IEC 27001:2022, was published in October 2022 and is the only certifiable version.
How long does ISO 27001 certification take?
A typical total of 6–12 months for small-to-medium organizations with full commitment. The breakdown: gap analysis and scoping 2–4 weeks, risk assessment and SoA 3–6 weeks, control implementation and documentation 2–6 months (the longest phase), ISMS operation for evidence collection 2–3 months, internal audit and management review 2–4 weeks, and Stage 1 plus Stage 2 certification audits around 4–8 weeks.
How much does ISO 27001 certification cost?
The cost components include certification body fees (Stage 1, Stage 2, and annual surveillance audits), consultant fees (optional but accelerating), technical remediation investment such as tooling and hardening, personnel training, and internal team time. Audit fees are generally calculated in man-days determined by the number of personnel in scope — so the broader the scope, the higher the cost.
What is the difference between ISO 27001:2022 and the 2013 version?
The biggest change is in Annex A: from 114 controls across 14 domains to 93 controls across 4 themes (Organizational, People, Physical, Technological). Eleven new controls were added, including Threat Intelligence, Cloud Security, Data Masking, DLP, Web Filtering, and Secure Coding. Since October 31, 2025, all 2013-version certificates are no longer valid — the 2022 version is the only certifiable one.
What are the stages of the ISO 27001 certification process?
There are eight stages: (1) gap analysis and scope definition, (2) risk assessment and risk treatment plan, (3) the Statement of Applicability, (4) control implementation and ISMS documentation, (5) awareness and training, (6) internal audit and management review, (7) Stage 1 (documentation readiness) and Stage 2 (implementation effectiveness) certification audits, then (8) annual surveillance and recertification. The certificate is valid for 3 years with annual surveillance audits and a full recertification audit in year three.
What common mistakes cause ISO 27001 certification to fail?
The most frequent mistakes: a paper-only ISMS (policies copied from templates without execution evidence — a major finding), an overly broad scope in the first certification, no active top management support, a box-ticking risk assessment, and insufficient operational evidence because the ISMS has only run for two weeks before the audit. Run the ISMS for at least 2–3 months before the audit so controls generate sufficient operational evidence, and remember that an ISMS abandoned after the certificate is issued will fail its first surveillance.
Related Templates & Checklists
Supporting material to act on what this article covers. Free — one email, once.
ISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
Download freeStatement of Applicability (SoA) Template — ISO 27001:2022
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
Download freeISO 27001 Internal Audit Checklist
A complete ISMS internal audit guide with verification points for every clause and control.
Download freeAbout the Author
Cloudsphere Consulting Team
GRC & Compliance
Cloudsphere's GRC consulting team, guiding Indonesian organizations to ISO 27001 certification and PDP Law compliance from gap analysis through audit.
Share Article
Related Topics
Related Articles
GRC Software
GRC Software in Indonesia: Must-Have Features, Options Compared, and Pricing (2026)
August 15, 2026
ISO 27001 Cost
ISO 27001 Certification Cost in Indonesia: Full Breakdown, Price Ranges, and How to Save
July 11, 2026
Indonesia PDP Law
Indonesia PDP Law Compliance: The Complete Guide to Law No. 27 of 2022 for Organizations
July 6, 2026