Programme pathway

A structured route from scope to a checkable credential.

The programme is designed to make assessment inputs, review steps, issuance decisions, and public verification understandable for organisations and the people who rely on their credentials.

Five stages

Clear inputs. Clear decisions. A live public record.

Timescales and requested evidence depend on an organisation’s context, scope, and readiness. A credential is issued only following an affirmative programme decision.

01

Application

Submit legal details, business activity, contact information, and the proposed scope.

02

Scope review

Clarify the organisation, management-system boundaries, and the activities to be considered.

03

Evidence review

Provide relevant ISMS documentation and operational evidence for the programme review.

04

Decision

Review findings are considered against the applicable programme requirements.

05

Registry record

Where issued, the credential is recorded with its scope, dates, and current status.

What you provide

Start with the facts that define your management system.

The application captures the details needed to understand the organisation and the proposed scope. Further evidence may be requested during review where it is relevant to a decision.

  • Legal organisation identity and registered address.
  • Main activities and the information-security scope proposed for assessment.
  • Relevant ISMS context, risk, control, and operational evidence.
  • Accurate contact details for assessment correspondence.
Open the ISO 27001 application