Get certified
The Get certified page (in the sidebar as Get certified, at the top of Overview) is your guided path to ISO/IEC 27001 certification. It tracks six milestones, in order — and each one flips to done automatically when the corresponding work actually exists in your workspace, not when you tick a box. A progress bar shows how many of the six you’ve met, and the next one to work is highlighted as Do this next.
The milestones
Section titled “The milestones”- Define your ISMS scope — Clause 4.3 requires a documented scope: the boundaries and applicability of your ISMS.
- Run your risk assessment — Clause 6.1.2 requires an information security risk assessment to identify and evaluate your risks before treating them.
- Implement your controls — Clause 6.1.3 and Annex A: apply the controls that treat your risks, and get most of your applicable requirements covered.
- Generate your Statement of Applicability — Clause 6.1.3 d) requires an SoA stating which Annex A controls apply, with justification for inclusions and exclusions.
- Complete an internal audit — Clause 9.2 requires internal audits of the ISMS at planned intervals, ahead of your certification audit.
- Hold a management review — Clause 9.3 requires top management to review the ISMS for continuing suitability, adequacy, and effectiveness.
Each milestone links straight to the page where you do the work, and the Implement your controls milestone shows your live clause-coverage percentage for the framework.
When all six are met, Keel marks you certification-ready — you have the scope, risk assessment, controls, SoA, internal audit, and management review a certification audit expects. Keel gets you audit-ready; the certificate itself is issued by an independent certification body, not by Keel.
Next steps
Section titled “Next steps”- Quickstart: stand up the program the milestones track.
- Statement of Applicability: milestone 4 in detail.