All articlesCompliance operations

What a certification audit actually tests

What a certification audit actually tests

In short

  • A control has three states: documented, verified, operated. Most programmes stop at the first two
  • ISO 27001 audits test the ISMS in two stages, then sample annually; sampling is not continuous assurance
  • SOC 2 Type I tests control design at a point in time; Type II tests operation over a period
  • Evidence assembled for an audit describes the organisation on the audit date, not six months later
  • Customer technical reviews increasingly ask operational questions a certificate cannot answer

What is the difference between a documented and an operated security control?

A documented control exists as a written policy or procedure. A verified control has been tested at least once against evidence. An operated control runs continuously, with someone accountable for acting when it fails. Certification audits test documentation thoroughly, verification by sampling, and continuous operation almost not at all.

The distance between a documented control and an operated one is where most certified organisations actually sit. Not because anyone cut corners, but because the certification process was never designed to measure the third state.

A control has three states

Take something concrete: privileged access review.

Documented. A policy says privileged accounts are reviewed quarterly. It names an owner, sets a frequency, defines what counts as privileged. The document is version-controlled and approved.

Verified. Someone produces the last four quarterly review records. An auditor reads them, confirms they exist, checks the dates line up with the stated frequency, and samples a few entries against the directory.

Operated. Privileged accounts are enumerated continuously. When an account gains admin rights outside the change process, something detects it within hours and a named person receives it, triages it, and either approves or revokes. The quarterly review is a summary of a process that was already running, not the process itself.

The three states describe the same control. Only the third one reduces risk between reviews.

What a certification audit actually tests

ISO 27001 certification runs in two stages. Stage 1 reviews the management system documentation: scope, policy, risk assessment, the Statement of Applicability produced under clause 6.1.3. Stage 2 audits implementation: the auditor looks for evidence that the ISMS is functioning and that selected controls are in place. Certification is followed by annual surveillance audits and full recertification on a three-year cycle.

That structure is sound, and it is also sampled. An auditor examines a subset of controls against a subset of evidence on a small number of days. Annex A of ISO 27001:2022 contains 93 controls across four themes: organisational, people, physical and technological. An audit does not test all 93 exhaustively every year. It cannot, and it does not claim to.

SOC 2 is more explicit about the distinction. A Type I report addresses the design of controls at a point in time. A Type II report addresses operating effectiveness across a defined period. The two are not interchangeable, and a customer asking for SOC 2 and receiving a Type I has usually not received what they asked for.

ENS works on a two-year rhythm: certificates carry two years of validity, with an ordinary audit at least every two years and an extraordinary audit where the system changes substantially.

None of these mechanisms is weak. They are periodic by design. Periodic assurance and continuous operation are simply different things, and conflating them is what produces certified organisations that cannot answer a technical question about last Tuesday.

Why documentation drifts

Evidence describes the organisation on the day it was collected.

A screenshot of a firewall rule set proves what the rules were that morning. An access review record proves who held privileges that quarter. A training completion export proves who had completed a module by that date. All valid, all accurate, and all decaying from the moment they are filed.

Meanwhile the organisation moves. New repositories appear. A cloud account is spun up for a project and never decommissioned. Someone leaves and their SaaS access outlives their laptop. A dependency picks up a vulnerability. The staff who wrote the procedure rotate out, and their replacements follow a version that lives in someone's head.

By the next audit, the distance between the documented control and the operating reality has grown for a year. The audit finds some of it. The parts it does not find are not resolved: they are simply not yet observed.

This is the failure mode that a folder of policies cannot address, however well written. Documents record intent. They do not detect drift.

The questions a technical review asks

The practical consequence shows up in enterprise procurement, because the people reviewing you are increasingly not satisfied by the certificate alone.

A security questionnaire or a customer technical review tends to ask things like:

  • How long between a critical vulnerability being published and it being patched across your estate?
  • Who receives an alert at 02:00 on a Sunday, and what happens next?
  • When did you last test your incident response, and what did it find?
  • What is currently exposed on your external perimeter?
  • Show me the last three security incidents and how each was closed.

A certificate answers none of these. It attests that a management system exists and was found conforming when sampled. The questions above ask what the organisation does, continuously, and who is accountable when it does not.

An organisation in the documented state answers with policy extracts. An organisation in the operated state answers with dates, durations and names.

What closing the gap costs

Here the arithmetic is worth doing properly, because the comparison is often framed wrongly.

A compliance platform closes the first state well and part of the second. It centralises policy, maps controls to frameworks, holds evidence, and automates some collection. That is real value and it is not in dispute.

What it does not do is operate. To reach the third state, the same organisation still needs detection and response on endpoints and servers, log collection and correlation, someone monitoring outside working hours, external attack surface visibility, cloud configuration assessment, application and dependency scanning, periodic penetration testing with a defined scope, and a security lead who owns the whole thing and can stand in front of an auditor or a customer.

The honest cost comparison is therefore not one licence against another licence. It is one licence against the full assembled stack: compliance platform, plus SIEM, plus EDR, plus scanning, plus pentest engagements, plus fractional security leadership, plus the internal hours to run and integrate all of it. Priced that way, consolidation usually wins, and the comparison stops being about software at all.

The question to put to any provider is simply which of the three states they cover, and to be sceptical of an answer that does not distinguish between them.

A certificate is worth having. It is evidence that a management system exists and has been examined by someone independent. It is not evidence that anything is watching today. Those are separate claims, and buyers have started asking for the second one.

See which of the three states your programme actually reaches.

Frequently asked questions

Does an ISO 27001 certificate prove controls are working today?

An ISO 27001 certificate attests that an information security management system was found conforming when audited. Audits are periodic and sampled: two initial stages, annual surveillance, recertification every three years. The certificate is evidence of conformity at the time of assessment rather than of control operation on any given day.

What is the difference between SOC 2 Type I and Type II?

A SOC 2 Type I report addresses whether controls were suitably designed at a specific point in time. A Type II report addresses whether those controls operated effectively across a defined period. A customer requesting SOC 2 assurance usually means Type II, and the two reports are not interchangeable.

How many controls does ISO 27001:2022 Annex A contain?

Annex A of ISO/IEC 27001:2022 lists 93 controls across four themes: organisational, people, physical and technological. Annex A is a reference set rather than a mandatory checklist. Organisations select applicable controls based on risk assessment and record the decisions, including exclusions, in the Statement of Applicability.

Why do customers ask for more than a certificate?

Customer technical reviews ask operational questions: patching intervals, who responds to an out-of-hours alert, what is currently exposed externally, how recent incidents were closed. A certificate attests to management system conformity and does not describe day-to-day operation, so these questions require operational evidence instead.

More articles

All articles