Home / ISO27001 Certification
Prove your commitment to information security with an internationally recognized certification. As a DANAK-accredited certification body, we guide you safely through the entire processk, from preparation to certification, with a strong focus on quality and transparency.
Being ISO27001 certified means that your organization has established and documented an Information Security Management System (ISMS) that complies with the internationally recognized standard for information security, ISO27001. The certification demonstrates that you work systematically to identify, assess, and manage risks, and that you have the necessary policies, procedures, and controls in place to protect your organization’s information.
An ISO27001 certification signals to customers, partners, and authorities that you take information security seriously, and that you are continuously working on improvements and adjustments to your security measures.
Regardless of size or industry, ISO27001 certification can strengthen your business and provide the opportunity to document compliance with the requirements of the standard.
Organizations of all sizes and levels of complexity can become certified under ISO27001, as the scope of the ISMS is defined by the organization itself.
This flexibility means that certification can benefit both companies with complex systems and those looking for a more simple, effective framework to meet the ISO27001 requirements.
Dansk Audit Institut is subject to strict international rules for auditing, in line with other accredited certification bodies. This means that we follow a standardized audit process that is transparent, fair, and internationally recognized.
Our transparent process ensures that all clients receive fair and consistent treatment—both during the audit and in pricing.
The certification process begins with you completing an information form. Here we collect key details about your organization, such as the number of employees, locations, complexity, existing security measures, and the scope of certification.
This step is important, as the completed form forms the basis for planning your certification process. The more precisely the form is filled in, the better we can:
Match you with an auditor who has relevant industry experience
Tailor the audit process to fit your needs and schedule
Minimize the risk of delays or additional costs later in the process
A correct and detailed application means that we can start the certification process quickly, efficiently, and with a full overview of your situation.
Once we have assessed your needs, you will receive a detailed proposal describing the scope, timeline, audit phases, and price. The agreement is not only a formal step, it also gives you assurance that we share a clear understanding of objectives, deadlines, and expectations.
This step ensures that there is no doubt about what the certification involves, and that you can plan resources and internal activities in good time.
A transparent proposal and a clear agreement mean that you can start the audit with a clear overview.
We appoint a qualified and independent auditor with specific experience in your industry. This is important, as an auditor with knowledge of your field will better understand the context and fairly assess your systems.
As a DANAK-accredited certification body, we ensure that our auditors work according to internationally recognized procedures, so that the results are objective and valid both nationally and internationally.
This gives you assurance that the audit is conducted professionally, with respect for both your time and your business operations.
The audit process typically consists of two phases:
Phase 1 Audit (pre-audit) – Review of documentation and preparation for the full audit
Phase 2 Audit – Practical assessment of how processes and controls function in practice
Before the actual certification audit is carried out, a pre-audit is conducted. Here, we review selected parts of your ISMS to identify any potential gaps or weaknesses in relation to the ISO27001 requirements.
The purpose is to ensure that you have a fully implemented and functioning ISMS, so that the full audit can be conducted correctly. This can save both time and resources, as you gain an overview of whether the final audit can be completed within the planned timeframe.
In the second phase of the audit, the full audit, a practical assessment is conducted to evaluate how processes and controls work in practice. This typically includes a review of your entire ISMS to confirm that you comply with the standard’s requirements.
If the audit shows that all requirements are met, we issue an official ISO27001 certificate. This certificate is valid for three years, provided that the organization carries out annual surveillance audits to confirm continued compliance.
Certification is not only proof of compliance, it is also a strong signal to customers, partners, and authorities that you take information security seriously and work systematically to protect data.