Compliance. Executed.
Executionist draws up the certification file, dates every item against the month you were given — or against the earliest the chain allows — and refuses to close one without its evidence.
Executed is a filing term on this page: an item is executed when it has been entered into the record with the evidence it requires. It does not mean an auditor has accepted it.
ISO/IEC 27001 and ISO 9001, kept the way a registrar keeps a file. You answer an intake — about 18 minutes for ISO/IEC 27001, 13 for ISO 9001. The file is drawn up: the workstreams, the items, the clause each item answers, what done means in the words an auditor uses, the evidence each item requires, an owner, a date, and the chain that runs from the evidence window to the certificate. You do the work. The record holds what was done, by whom, and when.
Access is by invitation and waiting list. Tell us which standard you have been asked for and the month you have been given.
Holding an intake link from us? It opens the same file — continue there.
Scope
What this is
Executionist is a planning and record-keeping instrument for a certification project. It draws up the file from your answers, states what each item requires in the terms the auditor will use, holds the evidence you enter against it, and says in dates whether the target still holds.
An item stands in one of four states — open, in work, executed, not applicable — and it reaches executed only when it is entered into the record with the evidence the item names. Where evidence is required, the product refuses the entry without it, and says so: nothing enters the record without evidence.
It is not a certification body and it issues no certificate. You engage one yourself. The file is what you put in front of it. Whether the work satisfies an audit is decided there, not here. The full boundary is set out below.
For an organisation that has decided to certify to ISO/IEC 27001 or ISO 9001 and will do the work itself. Not for anyone looking for a certificate without the work behind it, and not for anyone expecting evidence to collect itself.
Method
What you do, and what it does
01
You answer the intake. It draws up the file.
About 18 minutes for ISO/IEC 27001. About 13 for ISO 9001. About 26 for both together, because the questions the two standards share are asked once. Answers are kept as you enter them, and the link returns you to where you left off. A copy of the intake record can be sent as a PDF to the address the link was issued to. What comes back is the file: the workstreams, the items with their clause references, an owner and a due date on each, and the audit chain dated to the certificate month you named — or, if that month does not hold, to the earliest date the chain allows.
02
You confirm what does not apply. It re-opens what you reject.
Where your answers support one, the ISO/IEC 27001 file arrives with proposed Statement of Applicability exclusions already drafted, each naming the controls it covers and the justification an auditor would read. Confirm one and it stands. Reject it and those controls return to the plan as work. Some items refuse exclusion outright, and say so: an item the standard requires of every organisation cannot be recorded as not applicable — only done.
03
You do the work and enter the evidence. Gated items do not close without it.
Each item states what done means in the auditor's terms and names the form of evidence that will satisfy it. Evidence is a link you paste or a short attestation you type. Nothing is gathered on your behalf. Where an item is gated it does not close without evidence. Each entry is hashed and timestamped and cannot be edited afterwards; a correction is a new entry standing beside the old one.
04
It keeps the record and states the date.
An event log records who did what and when. Beside it, one sentence of forecast, in dates: whether the target holds at your present pace, and what it would take to hold it. Where a gate governs rather than effort, it says so — that pace is not the constraint, the evidence window closes no earlier than a given week, and Stage 2 cannot come before it. Until there is enough activity to measure, it declines to guess, and says so.
05
You engage a certification body. The file is what you hand over.
Stage 1 and Stage 2 are booked and agreed between you and the body. The plan holds the chain around the dates you give it. Booking lead time is the body's to set; the chain published below assumes none, so add whatever yours turns out to be. After the certificate, the standing obligations continue on the same record.
Specimen
One item, as it is written
Nothing on this page is a mock-up of the file. What follows is a single item from the ISO/IEC 27001 library, reproduced word for word. It carries no conditions — it appears in every ISO/IEC 27001 file drawn up for a first certification.
- Clause
- 4.3
- Workstream
- Scope & Mandate
- Item
- Draft and approve the ISMS scope statement
- Done means
- A scope statement naming the legal entity, the products and services covered, the locations and people included, and the boundaries — approved by the sponsor and referencing the context register. The auditor reads scope against context at Stage 1. A URL to the approved document, or an attestation naming where it lives and who approved it, dated.
- Evidence
- URL to the approved scope statement, or an attestation of approval with date and approver
- Gate
- Evidence required. Cannot be recorded as not applicable.
Items in the ISO/IEC 27001 library carry references to 74 distinct clauses and Annex A controls. In ISO 9001, 38. Every item carries a done-definition of this kind. How many items your own file holds follows from your answers: some items and some workstreams apply only on certain answers, and some arrive instead in a bring-the-existing-practice-onto-the-record form where your answers say the practice is already running.
Standard
ISO/IEC 27001:2022
The standard sets requirements for an information security management system: how an organisation decides which information matters, what could go wrong with it, what will be done about that, who is accountable, and how the organisation checks that what it decided is what actually happens.
The request often does not begin inside the company. It can arrive from a buyer: an enterprise vendor review that will not clear without a current certificate, a tender that lists the standard as a condition rather than a preference, a prime contractor passing the requirement down its supply chain, an acquirer treating its absence as a finding in diligence. A deal, a renewal or a deadline is often attached to the answer before anyone inside has read the standard.
What certification requires
Two things, held together. The first is the documents the standard makes mandatory: the scope of the management system (4.3), the information security policy (5.2), the risk assessment and risk treatment process and their results (6.1.2, 6.1.3, 8.2, 8.3), a Statement of Applicability covering every one of the 93 Annex A controls with a justification for inclusion and for exclusion and the current implementation status (6.1.3 d), security objectives and the plans to achieve them (6.2), evidence of competence (7.2), control of documented information (7.5), records of operational planning and control (8.1), monitoring and measurement results (9.1), the internal audit programme and its results (9.2), management review records (9.3), and records of nonconformities and corrective actions (10.2). The 2024 amendment adds consideration of climate change to the context clauses (4.1, 4.2).
The second is harder, and it is the part most easily left too late. The management system must already be operating and producing records before Stage 2. Documents alone do not certify. Stage 2 is an examination of what the system has done, not of what it intends to do: an internal audit completed and reported, a management review actually held against the inputs listed in 9.3.2, corrective actions raised and worked through, access reviews performed and signed, supplier reviews carried out, incidents logged or a recorded nil return, training delivered and attendance kept. The plan opens the evidence window 13 weeks before Stage 2 for that reason. A company that spends months writing policies and books an audit the following week arrives with nothing operating to show.
How long it takes
We publish no duration band, because we have none of our own to publish: no organisation has yet certified using this product, and figures reported elsewhere are not ours to repeat as fact. What is knowable in advance is what governs the floor. A management system is examined at Stage 2 on the records it has produced, so a period has to elapse and cannot be compressed by working harder. Add the certification body's booking lead time, which sits outside your control. Ask the bodies you approach what theirs is, and the file will hold the chain around the dates they give you.
Four items, reproduced from the library
Quoted from the file. The words below are the library's own.
6.1.3 d
Approve the Statement of Applicability. All 93 Annex A controls dispositioned: applicable with implementation status, or excluded with a justification an auditor will read aloud. Version-controlled, approved, traceable to the risk treatment. Certification bodies ordinarily expect this document complete before Stage 2 is scheduled; the sequencing is theirs to set.
Evidence required · Cannot be recorded as not applicable
9.2
Establish the internal audit programme and run the first touch. A programme covering all clauses and applicable controls, run in two touches: the first audits design and early operation before Stage 1; a scheduled second touch samples operating records before Stage 2. Whoever audits must not have implemented what they audit — an independent internal person, or an external internal auditor.
Evidence required · Cannot be recorded as not applicable
A.8.13
Verify backups and test a restore. Key systems and data backed up on a schedule, and a restore actually performed — the restore test is the item, not the backup. What was restored, when, and the outcome, on record.
Evidence required · Recurs after certification
A.5.18
Access reviews. A dated review of who has access to the systems that matter, exceptions acted on. The dates are what make the review reviewable.
Evidence required · Recurs after certification
- Subject
- Information security management
- Annex A controls
- 93, in 4 themes
- Workstreams in the library
- 14, of which 4 are conditional
- Clauses referenced
- 74
- Recurring after certificate
- 8 obligations
- Intake
- about 18 minutes
Standard
ISO 9001:2015
The standard sets requirements for a quality management system: how an organisation consistently delivers products and services that meet customer and applicable legal requirements, and how it improves the way that is done.
The demand is contractual, and it is often old. A contract manufacturer's largest customer writes certification into the supply agreement at renewal. A construction or engineering firm cannot pass a pre-qualification questionnaire on public work without it. A distributor is told by the brand it represents that uncertified suppliers come off the approved list at the end of the year. A components business selling into automotive, aerospace or medical supply chains finds ISO 9001 is the floor beneath the sector standard the customer really wants. The job often lands with whoever already holds the job files, the complaint log and the supplier list, and who is now asked to make them into a system.
What certification requires
The mandatory records are the scope with any non-applicable requirements justified (4.3), the quality policy (5.2), quality objectives and the plans to achieve them (6.2), documented information supporting the operation of processes (4.4.2), competence records (7.2), records for monitoring and measuring resources including calibration where measurement traceability applies (7.1.5), records of the review of customer requirements (8.2.3.2), design and development records where design is in scope (8.3), evaluation and re-evaluation records for external providers (8.4.1), records of production and service provision including identification and traceability where required (8.5.1, 8.5.2), release records showing who authorised release (8.6), records of nonconforming outputs and their disposition (8.7), monitoring and measurement results including customer satisfaction (9.1.1, 9.1.2), internal audit records (9.2.2), management review records (9.3.3), and records of nonconformity and corrective action (10.2.2). Risk-based thinking (6.1) does not oblige a formal register, but the organisation must be able to show that risks and its own context were considered. The 2024 amendment adds climate change to the context clauses.
The same rule holds here. The system must be operating before Stage 2. Stage 2 asks to see orders reviewed, suppliers evaluated against stated criteria, nonconformities recorded and dispositioned, customer feedback gathered by a defined method, at least one internal audit completed across the processes, and one management review held. A binder of procedures written last month evidences intent and nothing else.
How long it takes
We publish no band here either, for the same reason. What separates fast from slow is knowable in advance. The fast end belongs to companies that already keep good records — job files, purchase orders, inspection sheets, a complaint log — and need those arranged, named and reviewed rather than invented. The slow end belongs to companies where the process lives in one person's head, differs by shift or by site, or where calibration and traceability have to be established from scratch. Multi-site scope adds audit days and coordination.
Four items, reproduced from the library
Quoted from the file, as above.
8.4
Approve and register the suppliers that matter. The suppliers whose failure reaches your customer — approved on stated criteria, listed, and the list actually used when buying.
Evidence required · Cannot be recorded as not applicable
8.7
Control nonconforming output. What happens when work is wrong: identified, segregated or held, dispositioned (rework, concession, scrap), the customer told where it matters, and the record kept.
Evidence required · Cannot be recorded as not applicable
9.1.2
Establish how customer satisfaction is monitored. How you know customers are satisfied — repeat business, reviews, surveys, account conversations — chosen, stated, and producing data leadership actually sees.
Evidence required · Cannot be recorded as not applicable
4.4
Draw the process map. The processes that take an order to a delivered product or service — their sequence, interactions, owners, and the measures that tell you each is working.
Evidence required · Cannot be recorded as not applicable
One trap worth naming. A certificate held by a parent, a sister company or a former trading entity does not cover the business that is tendering. The certificate names a specific legal entity, and the scope line names what that entity was audited for.
- Subject
- Quality management
- Statement of Applicability
- None. That instrument belongs to ISO/IEC 27001.
- Workstreams in the library
- 10, of which 2 are conditional
- Clauses referenced
- 38
- Recurring after certificate
- 5 obligations, 1 of them conditional
- Intake
- about 13 minutes
Combined
Both standards as one engagement
ISO/IEC 27001 and ISO 9001 share a common clause structure and a substantial amount of the same underlying work. Context, leadership commitment, competence, document control, the internal audit programme, management review and corrective action are, in practice, one set of arrangements serving two files.
Where both standards are in scope, the questions the two share are asked once, and 9 shared records are entered once and linked into both files rather than kept twice:
context register · objectives reporting · competence records · training records · document control · internal audit programme · internal audit second touch · management review · corrective actions
The combined intake runs about 26 minutes rather than 31. The audits remain two audits against two standards, and the certification body may or may not combine them. The preparation does not need to be done twice.
Chain
The audit chain, as arithmetic
The chain the plan lays down is fixed, and it is published here so it can be checked. Counting backwards from the certificate:
- Certificate in hand
- the month you named, if the chain reaches it
- Stage 2 audit
- 5 weeks before the certificate
- Stage 1 audit
- 6 weeks before Stage 2
- Internal audit and management review complete
- 4 weeks before Stage 1
- Evidence window opens
- 13 weeks before Stage 2
Evidence window to certificate: 18 weeks, before any booking lead time.
Assumptions
- Estimated back-plan. The actual audit dates are set with your certification body.
- The certificate milestone assumes audit findings close promptly.
- Add the certification body's booking lead time where one is not yet engaged. The chain above assumes none.
If the month you named cannot be reached, the file says so on the first day, before any work has been done, and names what would move it: the lead's hours, the scope, the booking, or the date.
Standing obligations
After the certificate
A certificate runs 3 years, with surveillance audits in the first and second years and recertification before it expires. The obligations that earned it do not stop. An ISO/IEC 27001 file carries 8 recurring obligations forward: access reviews, backup restore tests, awareness training completions, joiner and leaver records, supplier reviews, vulnerability reviews, incident log reviews with a response exercise, and objectives reporting. An ISO 9001 file carries 5: objectives reporting, supplier re-evaluation, training records, complaint log review, and calibration where measuring equipment is in use. Each recurs on the same record, on the same terms, with the same evidence requirement. Those are the records the surveillance year runs on.
Boundaries
What this does not do
It is not a certification body and issues no certificate. Certificates are issued by an independent certification body, accredited by a recognised accreditation body. You engage one yourself, and the body cannot consult on the system it certifies.
It does not collect evidence. There are no integrations, no agents to install, no scanning and no continuous monitoring. Evidence is a link you paste or an attestation you type, entered by a person who knows what they saw.
It does not audit you, and it does not perform your internal audit. Clause 9.2 requires that whoever audits did not implement what they audit. That is a person, not a product.
It makes no claim about the outcome of your audit. Executed means entered into the record with its evidence. It does not mean accepted. The decision belongs to the certification body.
It does not support SOC 2. SOC 2 is not part of the product and is not available. Nothing about it is included in what you would be signing up for, and no date is committed.
It does not do the work. It states what the work is, in the terms the auditor will use, and it refuses to record work that has not been evidenced.
Enquiries
Questions
What does certification cost?
Most of the cost of certification is not software cost. Certification body fees follow a formula rather than a negotiation: audit days are set by the body from headcount and complexity, following the audit-time requirements that bind it — ISO/IEC 27006-1 for ISO/IEC 27001, and the corresponding IAF mandatory document for ISO 9001. The day count follows from that framework rather than from you. We publish no range of our own, because we have no basis for one: ask two or three accredited bodies for a written quotation against the same scope and compare those. Scope is the one figure you control — fewer systems and fewer sites in scope mean fewer audit days. Our own pricing is not settled, and none is published here until it is.
How long does it take?
We publish no band, because we have no basis for one: no organisation has yet certified using this product, and durations reported elsewhere are not ours to repeat as fact. What governs the floor is knowable. A management system is examined at Stage 2 on the records it has produced, and a period that has to elapse cannot be compressed by working harder — the plan opens the evidence window 13 weeks before Stage 2 for that reason. Booking lead time with a certification body sits outside your control as well. A certificate promised in weeks describes a document set, not a management system.
Do I need a consultant?
Not necessarily. Organisations do certify with a clear structure and the discipline to follow it. A consultant compresses the timeline and prevents rework, and costs accordingly. There is one place where outside help is often unavoidable: the internal audit is mandatory, and clause 9.2 requires it to be carried out by someone independent of the work being audited. In a team of 15, that person may not exist. An external internal auditor is the ordinary answer. Executionist does not fill that role.
What will the auditor ask for at Stage 1?
Stage 1 examines documentation and readiness; Stage 2 tests whether the system operates. For ISO/IEC 27001, expect the internal and external issues and interested parties (4.1, 4.2), the scope with its boundaries and justified exclusions (4.3), the approved policy and assigned roles (5.2, 5.3), the risk assessment methodology and criteria (6.1.2), the Statement of Applicability with a justification for every control (6.1.3 d), objectives (6.2), competence and documented information (7.2, 7.5), risk assessment and treatment results (8.2, 8.3), monitoring and measurement (9.1), the internal audit programme with reports and evidence of auditor competence (9.2), management review records (9.3) and the corrective action process (10). A mandatory document that is absent is a finding waiting to be raised; how it would be graded is the auditor's judgement, and clearing it before Stage 2 takes time you have not planned for.
Does it matter which certification body I use?
Accreditation attaches to the certification body, not to the certificate. A certificate from an unaccredited body cannot be upgraded retrospectively; replacing it means certifying again from the beginning, and buyers who check may treat it as no certificate at all. Transfer between accredited bodies is possible through a formal transfer review. Before you sign, confirm the body's accreditation on the public register of its accreditation body — UKAS in the United Kingdom, ANAB in the United States, and their national equivalents elsewhere. Reluctance to name an accreditation body is worth treating as a warning. One change worth knowing: the international recognition arrangements formerly run by IAF and ILAC have been consolidated. Confirm the current arrangement, and the status of any accreditation you are relying on, with the accreditation body itself.
Can a company be “ISO certified”?
No. The phrase is common but inaccurate. ISO states on its own site that it is not involved in certification and does not issue certificates. The accurate form is that an organisation is certified to ISO/IEC 27001 by a named certification body, which is accredited by a named national accreditation body. The ISO logo may not be used to indicate certification; the mark you may use is the issuing body's.
What about SOC 2?
Not available. It is also a different kind of thing, and the difference is worth stating. SOC 2 is not a certification and there is no SOC 2 certificate. It is an attestation engagement performed by a licensed CPA firm under the AICPA's attestation standards, reporting on controls against the Trust Services Criteria: security, which every report includes, and where elected, availability, processing integrity, confidentiality and privacy. A Type I opines on design at a point in time; a Type II opines on operation across a period. The report is ordinarily provided under restriction rather than published. ISO/IEC 27001 certifies a management system against a published international standard through an accredited body and produces a certificate on a 3-year cycle. The underlying evidence overlaps, which is why a second engagement is usually lighter than the first. SOC 2 is not part of the product today, and nothing is committed about it.
Can I get a copy of what I have entered?
Yes. Intake answers are kept as you enter them, and a PDF copy of the intake record can be sent on request to the address the intake link was issued to. Evidence entries are hashed and timestamped and cannot be altered afterwards; a correction is recorded as a new entry beside the original, so the log shows the sequence of what was entered and when.
Who can use it today?
Access is by invitation and waiting list. If you hold an intake link from us, it opens the file directly and no request is needed. Otherwise, request access and we write when a place opens.
Request access
Executionist is early, and access is opening gradually. Tell us which standard you have been asked for, and the month you have been given. We write when a place opens.
Access is by invitation and waiting list. No pricing has been set.
Already have an account? Sign in. Holding an intake link from us? It opens the same file — continue there.