Skip to content
Certification journey

Your certification journey

What happens from your first enquiry to a certificate, and what you can expect from us at each stage.

  1. 01

    Tell us about your organisation

    You tell us about your organisation, information security management system, proposed certification scope, locations, people and Statement of Applicability.

    We review this information to confirm that the scope is clear and that we have the competence, capacity and impartiality needed to take the work on. If anything is missing or unclear, we will ask for more information before proceeding.

  2. 02

    Review, quotation and agreement

    We determine the audit time required and whether the audit will be conducted remotely, on-site or through a combination of both.

    You receive a clear quotation and certification agreement before audit activity begins. The quotation explains the audit time, fees and any applicable expenses.

    Audits and reports are delivered in English. Using remote methods does not automatically reduce the audit time required.

  3. 03

    Stage 1 — understand and plan

    Stage 1 evaluates whether your ISMS is ready for the main certification audit.

    We review your certification scope, documented arrangements, risk assessment and treatment process, Statement of Applicability, internal audit, management review and relevant operating conditions.

    You receive a Stage 1 report identifying any areas of concern and whether you are ready to proceed to Stage 2. The findings also help us plan the Stage 2 audit.

    If significant changes occur or the Stage 1 information is no longer reliable, some or all of Stage 1 may need to be repeated.

  4. 04

    Stage 2 — see the system working

    Stage 2 evaluates whether your ISMS is implemented, maintained and effective in practice.

    The audit team interviews relevant people, reviews documented evidence, observes activities where appropriate and samples how your controls and processes operate.

    Remote methods may be used where they provide reliable evidence. On-site activity is used where direct observation or access is needed.

    Certification audits are based on sampling. They do not examine every transaction, system, record or security control.

  5. 05

    Findings and corrective action

    At the closing meeting, the audit team explains its conclusions and any findings. You then receive a written audit report.

    If a nonconformity is identified, you have the opportunity to provide correction, cause analysis and corrective action.

    Major nonconformities must be effectively addressed and verified before certification can be granted or renewed. For minor nonconformities, we may accept an appropriate correction and corrective-action plan before the certification decision and verify its effectiveness later.

    The audit team makes a recommendation. It does not grant certification.

  6. 06

    Independent review and decision

    A competent reviewer examines the completed certification file. A separate authorised person who was not part of the audit team makes the certification decision.

    The decision is based on the certification evidence. It is not influenced by sales targets, commercial pressure, payment status or the preference of the audit team.

    If the decision is adverse, we will explain the reasons in writing and tell you how to appeal.

  7. 07

    Receive your certificate

    Following a positive decision, we issue your certificate and add its status and certified scope to our certification register.

    An initial certification cycle lasts no more than three years. Certification remains valid only while the continuing certification requirements are met.

    Certification confirms conformity on a sampling basis and at particular points in time. It is not a guarantee that a security incident, breach or other failure will never occur.

  8. 08

    Keep your certification current

    Surveillance audits take place throughout the certification cycle to confirm that your ISMS continues to operate effectively.

    The first surveillance audit takes place no more than 12 months after the initial certification decision. Further surveillance takes place during the cycle.

    Before your certificate expires, recertification evaluates the continued effectiveness of your ISMS and its performance across the certification cycle. A positive recertification decision begins the next cycle.

    Significant changes, serious or persistent failures, missed required audits or misuse of certification may result in additional review, a special audit, suspension, reduction of scope or withdrawal.

Your rights

Throughout the certification process, you have the right to:

  • receive clear information about the process, scope, audit time, fees and accreditation status before agreeing to proceed;
  • be assessed by competent and impartial personnel;
  • know the proposed audit team and raise a reasoned objection to a team member;
  • have your information protected and used only for legitimate certification purposes;
  • receive an audit plan and written audit report;
  • have findings linked to identifiable requirements and supported by audit evidence;
  • receive a certification decision made independently of the audit team;
  • receive written reasons for an adverse certification decision;
  • respond before suspension or withdrawal where circumstances permit;
  • complain about Calibre or a certification activity;
  • appeal an eligible certification decision free of charge; and
  • receive accurate information about the status and scope of your certification.

What we need from you

Certification is a continuing relationship. We need you to:

  • provide accurate and complete information;
  • give the audit team access to relevant people, sites, systems and records;
  • maintain and continually operate your ISMS;
  • tell us about significant organisational changes and relevant information-security incidents;
  • address nonconformities within the applicable timescale;
  • cooperate with surveillance, recertification and accreditation witnessing; and
  • use your certificate and certification marks accurately.

If you disagree with a decision we have made, you can lodge an appeal, free of charge. If something else has gone wrong, you can make a complaint. Using your certificate and the certification mark is covered in use of marks and symbols.