Skip to main content
RiskZeroCertifiers

Independent certification body · ISO/IEC 27001:2022

ISO 27001 certification your customers can verify.

RiskZero is an independent certification body. We audit your information security management system against ISO/IEC 27001:2022 and issue a certificate that holds up in enterprise procurement, in tenders, and in front of your board.

Quote turnaround
2 business days
Stage 1 availability
Within 4 weeks
Certificate validity
3 years, verifiable

Built for the organisations that get asked for a certificate: the ones holding other people’s data, systems, or money.

How the pieces fit

Three parties, one package, separate people

Most of the ISMS packages we certify are built and attested by SRG and reach us through riskzero.us. We work with both, and we say so. The safeguard is that the people who prepare a package are never the people who audit it or sign the certificate.

  1. 1Build and attest

    SRG

    Helps you scope and build the ISMS, implement and harden the controls, run the penetration test, and write the policies. When the package is complete, SRG attests that it is ready.

    Consultancy and attestation

  2. 2Work together

    riskzero.us

    The platform where the package is assembled, attested, and submitted, and where our auditors examine it. It is how two separate teams work on one package without sharing people.

    Platform

  3. 3Audit and certify

    RiskZero Certifiers

    A separate company with its own auditors, reviewers, and signatories performs Stage 1, Stage 2, and the certification decision on the package. Nobody who prepared it takes part.

    Certifier · this site

SRG’s attestation is an input to Stage 1, never a substitute for it: our auditors form their own view of every package, and the findings do not depend on who prepared it. Read ourimpartiality statement for the rules we apply.

The three-year cycle

What happens, and when

ISO 27001 certification is not a single audit. It is a three-year cycle with defined points where we check the ISMS is still working. Here is the whole thing on one line, starting with the package SRG prepares before it reaches us.

  1. Before

    SRGBuild and attest

    SRG helps you build the ISMS and attests that the package is ready. It is submitted through riskzero.us. RiskZero takes no part in this step.

  2. Month 0

    Stage 1Readiness review

    We review the package: scope, risk assessment, Statement of Applicability, and evidence of internal audit and management review, and confirm you are ready for Stage 2.

  3. Month 1 to 2

    Stage 2Certification audit

    On-site or remote audit of how the ISMS actually operates: interviews, records, sampled controls, and evidence.

  4. Month 2 to 3

    DecisionCertificate issued

    An independent reviewer checks the audit file. Once any nonconformities are closed, your certificate is issued and can be verified with us directly.

  5. Month 12

    Year 1Surveillance audit

    A shorter audit confirming the ISMS is maintained, internal audits and management reviews have happened, and corrective actions are working.

  6. Month 24

    Year 2Surveillance audit

    Second annual check, usually covering the parts of the ISMS not sampled in year one.

  7. Month 36

    Year 3Recertification

    A full audit before the certificate expires. Pass it and a new three-year cycle begins with no gap in certification.

Why RiskZero

What makes a certificate worth having

A certificate is only as credible as the body that issued it. These are the things we do differently, and why they matter to the people who read your certificate.

  • Impartial by design

    We do not consult or implement. Packages reach us through riskzero.us, most prepared and attested by SRG, and nobody who prepared a package audits it, reviews it, or signs the decision. Our only product is an audit opinion on someone else’s work.

  • Auditors who have run an ISMS

    Our auditors come from security and engineering roles. They read infrastructure as code, understand shared responsibility, and know what a real incident log looks like.

  • Fixed fees for the whole cycle

    One proposal covers Stage 1, Stage 2, both surveillance audits, and the decision. Rates are fixed for three years and the working is shown.

  • Findings you can act on

    Every finding names the clause or control, the evidence examined, and why it matters. Reports are written for your board as well as your auditor.

  • Certificates anyone can verify

    Any customer, auditor, or tender evaluator can ask us to confirm the scope, status, and expiry of a certificate we issued. We answer within one business day.

  • Dates when you need them

    Stage 1 dates are usually available within four weeks. We plan backwards from your customer deadline, not forwards from our calendar.

Questions

The questions we get asked first

Straight answers on timing, cost, who does what, and what we will and will not do.

All frequently asked questions
How long does ISO 27001 certification take?
If your ISMS is ready for audit, the certification itself typically takes eight to twelve weeks from contract to certificate: Stage 1, a short gap to fix anything it raises, Stage 2, then an independent certification decision. Building the ISMS before that usually takes three to nine months depending on your starting point.
What does ISO 27001 certification cost?
Audit fees are driven by the number of people and sites in scope and the complexity of your operations, following the IAF MD 5 audit-time rules that all accredited certification bodies must apply. We quote a fixed fee for the full three-year cycle so there are no surprises at surveillance time. See our pricing page for the factors that determine audit time.
Who are SRG and riskzero.us, and how are they related to RiskZero?
SRG is the consultancy that helps organisations build their ISMS and attests that the package is ready; it is the intermediary between the client and us. riskzero.us is the platform on which the package is prepared, attested, submitted, and audited. RiskZero Certifiers is a separate company with its own auditors, reviewers, and signatories. We work with both, we disclose it, and nobody who prepares a package takes part in auditing it or in the certification decision. See our impartiality statement.
Can RiskZero help us implement ISO 27001 and then certify us?
No. A certification body that designs your ISMS cannot credibly audit it, and accreditation rules prohibit it. Implementation is SRG’s work, not ours, and SRG’s attestation is an input to our Stage 1, not a substitute for it. Our auditors form their own view of every package.
Do you audit remotely?
Yes. Remote audits are appropriate for most cloud-first organisations and are conducted using video, screen sharing, and secure evidence exchange. Physical sites such as data centres or offices with physical security controls in scope will normally need at least one on-site visit during the cycle.

Guides and articles

Written by auditors, for the people preparing for one

All resources

Ready to scope your audit?

Tell us about your organisation, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.