ISO27K

ISO 27001 certification in Canada: how it works

ISO 27001 certification means an accredited body audits your information security management system and issues a certificate valid for three years. Here is what that involves in Canada, who accredits the bodies, and how to choose between them.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Getting certified in Canada works the same way it does anywhere else, which is the point of an international standard. You build an information security management system to ISO/IEC 27001:2022, run it long enough to produce records, have it audited in two stages by an accredited certification body, and receive a certificate valid for three years subject to annual surveillance. From a standing start, plan on nine to fifteen months and $40,000 to $110,000 CAD in the first year with outside help.

What is specific to Canada is the accreditation picture and the privacy law sitting underneath. Both are covered below.

What you are actually building

The certificate is issued against a management system, not against a list of security tools. Auditors spend more time on the management machinery than on the controls, which surprises technical teams that arrived expecting a configuration review.

The documents an ISO 27001 auditor will ask for
ArtifactWhy it exists
Scope statementDefines what is certified. This wording goes on the certificate and every buyer reads it.
Information security policyApproved by top management, and the thing clause 5 hangs on.
Risk assessment and treatment planYour identified risks, their owners, and what you decided to do about each.
Statement of ApplicabilityWhich of the 93 Annex A controls apply, which do not, and why. The first document most auditors open.
Asset and information inventoryWhat you hold, where it lives, who owns it.
Supplier register and reviewsWho processes your data and what you checked.
Internal audit recordsClause 9. Must be done by someone independent of the work being audited.
Management review minutesEvidence that leadership looked at the system and made decisions.
Corrective actionsFindings, root causes, and what changed as a result.

The 2022 edition organizes Annex A into 93 controls across four themes: organizational, people, physical and technological. You are not required to implement all of them. You justify inclusion and exclusion in the Statement of Applicability against your risk assessment, and an exclusion with a written reason is a legitimate answer. An exclusion with no reason is a finding.

Accreditation in Canada, and what SCC does

A certificate is only as good as the accreditation behind the body that issued it. Accreditation bodies assess certification bodies against international rules for how certification must be run, including impartiality and audit day requirements, and they recognize each other's work through the International Accreditation Forum multilateral arrangement.

In Canada the national accreditation body is the Standards Council of Canada. SCC accredits certification bodies operating here, and because it is an IAF signatory, certificates issued by bodies accredited by peer members such as ANAB in the United States, UKAS in the United Kingdom or others abroad are recognized in Canada too. You are not obliged to use an SCC-accredited body, and many Canadian companies hold certificates from bodies accredited elsewhere.

Verify accreditation on the accreditation body's register

Certification body websites are marketing. Accreditation body registers are the record. Ask which accreditation body granted the accreditation, for which standard, and under what number, then confirm it on that accreditation body's own public directory. Unaccredited certificates exist, cost less, and fail the moment a serious buyer checks.

The certification process, step by step

From decision to certificate
StepWhat it involvesElapsed time
1. Set the scopeWhich products, environments, sites and legal entities are in. Narrow and defensible beats broad and thin.1 to 3 weeks
2. Gap assessmentCompare where you are against the standard and Annex A. Produces the project plan and the budget.2 to 6 weeks
3. Risk assessmentIdentify risks, assign owners, decide treatment. The input to the Statement of Applicability.3 to 6 weeks
4. Build and remediatePolicies, processes, technical fixes, supplier reviews, training. The long stretch.3 to 8 months
5. OperateRun the system and accumulate records. Two to three months minimum before stage 2 is realistic.2 to 4 months
6. Internal audit and management reviewBoth required before stage 2. The internal audit must be independent.3 to 6 weeks
7. Stage 1 auditDocumentation and readiness review. Expect a list of things to fix.1 to 2 days
8. Stage 2 auditEvidence that the system operates. Interviews, sampling, records.2 to 5 days
9. CertificateIssued once major nonconformities are closed. Valid three years.2 to 8 weeks after stage 2

Steps 4 and 5 overlap in practice, and step 5 is the one that cannot be compressed. An auditor sampling a quarterly access review needs a quarterly access review to have happened. A management system stood up three weeks before stage 2 has three weeks of records and will be told so.

Choosing a certification body

Certification bodies compete on price, sector experience and how they run an audit, and the differences are real. Ask each shortlisted body the same questions.

  • Which accreditation body accredits you for ISO/IEC 27001, and under what certificate number.
  • How many audit days are you proposing for stage 1, stage 2, each surveillance visit and recertification.
  • What is the three-year total, not the year-one price.
  • Will the audit be remote, on site, or mixed, and who pays travel.
  • Has your team audited companies like ours, in our sector and at our size.
  • Are you also accredited for ISO 42001, if we may want to add it later.

One rule overrides preference: an accredited body cannot consult you into shape and then certify you. Impartiality requirements separate those roles. If a firm offers to build your management system and audit it, either the consulting is a separate legal entity with real separation or the certification is not accredited. Use one supplier for readiness and a different accredited body for the audit.

The Canadian pieces that sit alongside

Certification is voluntary and it is not law. Canadian privacy law is, and it applies to your handling of personal information whether or not you certify. Annex A covers the safeguards side of PIPEDA well. It says nothing about consent, stated purposes, retention limits or an individual's right of access, which are separate obligations under PIPEDA or the provincial statute that displaces it in Quebec, British Columbia and Alberta.

Quebec is the one to check early. Law 25 carries its own breach duties, privacy impact assessment requirements and penalties that reach into the millions or a percentage of worldwide turnover, and a management system built only against ISO 27001 does not satisfy it. If you have Quebec customers or staff, scope that work in parallel rather than assuming the certificate covers it.

Two supporting engagements come up in nearly every Canadian certification. An independent penetration test, because Annex A expects technical vulnerabilities to be identified and managed and auditors want to see independent evidence. And an accountable owner for the management system, which in a company without a security executive usually means a fractional CISO holding the clause 5 responsibility.

What happens after certification

The certificate is the start of a cycle. Surveillance audits in years one and two sample parts of the system, and a full recertification audit in year three renews it. Between visits you are expected to keep running internal audits, management reviews, risk reassessment and supplier reviews, and to have records showing you did.

The common failure is treating certification as a project that ended. A surveillance auditor who finds no management review since stage 2, no internal audit and a risk register untouched for eleven months will raise findings that put the certificate at risk. Put the annual calendar in place during the project, not after it.

Compare Canadian certification bodies and consultants

Tell us your scope, headcount and target date and we will connect you with firms that can quote it properly.

Get matched

Common questions

Does the certification body have to be SCC accredited?

No. The Standards Council of Canada is the national accreditation body, but it is a signatory to the International Accreditation Forum arrangement, so certificates from bodies accredited by peer accreditation bodies abroad are recognized in Canada as well. What matters is that the body is accredited by a recognized accreditation body for ISO/IEC 27001 specifically.

How long is an ISO 27001 certificate valid?

Three years, provided you pass surveillance audits in years one and two. A recertification audit in year three renews it for a further three-year cycle.

Can our consultant also certify us?

Not if the certification is to be accredited. Impartiality rules prevent a certification body from auditing a management system it helped build. Plan for two separate suppliers from the beginning.

Do we have to implement all 93 Annex A controls?

No. You select controls based on your risk assessment and record the reasoning for inclusions and exclusions in the Statement of Applicability. Excluding a control because it does not apply to your environment is normal. Excluding one because it was inconvenient, with no documented rationale, is a finding.

Can the audit be done remotely?

Largely yes for a cloud-based company with no significant physical scope, and remote auditing is now common. Bodies still apply limits on how much of an audit can be conducted remotely, and physical controls in a real office or data centre generally need someone to look at them. Confirm the split before you accept a quote, because travel costs ride on it.

We are already SOC 2 audited. Does that shorten this?

It helps materially on evidence and technical controls, which overlap by roughly two thirds. It does not give you the management system, which is what ISO 27001 certifies: scope, risk methodology, Statement of Applicability, internal audit and management review have no SOC 2 equivalent. See how the two compare.