Complade ISO 27001 Certification in Canada
Complade provides SCC-accredited ISO/IEC 27001 certification in Canada. To be eligible, your organization must meet the requirements of ISO/IEC 27001 and assess the controls in Annex A. ISO/IEC 27002 provides detailed guidance on information security controls.
ISO/IEC 27001 Certification Process: Overview
Get an instant ISO/IEC 27001 estimate and start your application online
Watch the ISO 27001 process video on its own page
- 01
Step 1: Complete the initial application in the Complade certification portal and receive an estimate. A meeting with the Complade team is optional.
- 02
Step 2: Complete the certification application. The information is used to determine the certification scope, audit plan, and contract details.
- 03
Step 3: The Complade Certification Team shares the initial audit plan draft, mutual NDA, certification terms and conditions, invoice, and certification process.
Once the documents are approved, invoice paid, the certification audit team will be introduced for the Stage 1 audit
- 04
Step 4: The audit team requests copies of the applicable policies and procedures, risk assessment, internal audit, management review results, and Statement of Applicability. See the full list.
- 05
Step 5: The audit team will share Stage 1 report and meet with you to discuss readiness for Stage 2.
- 06
Step 6: Stage 2 audit planning: the audit team works with you to confirm the audit dates and schedule.
- 07
Step 7: Stage 2 audit: conducted virtually or in person to confirm the effectiveness of the Information Security Management System.
- 08
Step 8: The audit team shares the Stage 2 audit report.
- 09
Step 9: If any gaps are identified, you will be asked to provide a corrective action plan.
- 10
Step 10: The Complade Certification Team will review all reports and make the certification decision.
- 11
Step 11: If all requirements are met, Complade issues the certificate with its defined validity period and publishes the applicable record on IAF CertSearch.
Certification Policies
Start your ISO/IEC 27001 certification journey with an instant online estimate.
Start onlineIf you would like help before applying, email info@complade.com, call (289) 804-1616, or book a meeting.
How long does it take to get certified?
Short answer: 6 weeks
Long answer:
To achieve initial certification, the duration depends on the complexity of your organization. For a very small organization with 15 full-time employees and a few outsourced roles (such as bookkeeping and IT services personnel), and assuming your management system is implemented and ready for auditing, it takes about 6 weeks. Here is the rationale:
- 1
You submit the application form (1 business day).
- 2
The Complade back office team reviews the form and confirms the details with you, ensuring your organization is ready for an audit. You then sign the contract (approximately 2 business days).
- 3
The Complade back office team assigns an auditor to you, shares the audit plan, and lists the required documents, etc. (1 business day).
- 4
Assuming you have everything prepared and you submit the required information (1 business day).
- 5
The auditor conducts a document review (1-2 weeks; for simplicity, let's say 1 week, which equals 5 business days).
- 6
Assuming the auditor has no clarification questions and shares the timeline for a remote or in-person audit day (1 business day).
- 7
Conducting the audit (3-15 business days based on complexity).
- 8
Assuming there are no major non-conformities, and only a few minor ones for which you need to submit a corrective action plan (1 business day).
- 9
A second auditor reviews all the documentation (5 business days).
- 10
Assuming everything is satisfactory, congratulations, you receive your certificate.
In summary, the fastest scenario for achieving certification is 6 weeks.
If you have any questions, please contact us. We can provide more precise answers based on the dynamics of your organization.
How much does ISO 27001 certification cost?
Quick answer: published pricing starts at CAD $1,900 for organizations with 1–10 people in scope.
The published starting estimate for initial ISO/IEC 27001 certification is CAD $1,900 for an organization with 1–10 people in scope and the listed infrastructure baseline. The calculator shows additional assumptions for organization size, infrastructure, audit language, and delivery method. Non-profit organizations receive a 15% discount.
Pricing is a planning estimate. Complade provides the firm quotation after reviewing the application, certification scope, and required audit time.
Use the pricing calculatorI am not ready, how do I prepare?
Quick Answer: Seek assistance from an ISO 27001 consultant or implementer; Complade cannot provide consulting services.
Long Answer
Much like in accounting, where your accountant or bookkeeper cannot serve as your financial auditor, Complade does not offer consultation or implementation services, nor do we provide "templates." Our objective is to assure you that your information risks and controls are adequately balanced. Offering implementation advice or templates would compromise the integrity of our audit process. It wouldn't make sense for us to identify non-conformities in procedures we advised you to implement, would it? Just as your accountant cannot audit their own financial records, an implementer responsible for implementing and maintaining your Information security management system cannot audit their own processes.
The good news is that there are many implementers and tools available to help you implement the ISO 27001 standard. We do not endorse or recommend any specific organizations. You might consider asking your IT services provider for assistance. Once you're ready, reach out to us. It makes no difference to us who assists you in implementing and maintaining your systems; our role is to assess your compliance impartially and provide you with a fair report and certification.
What documents are required for Stage 1?
Quick answer: the documented information required for the Information Security Management System.
Detailed answer:
Initial documents required for the Stage 1 review:
- 01
Scope of the ISMS (Clause ISO 27001:2022 4.3)
- 02
Information Security Policy (or policies) (Clause ISO 27001:2022 5.2)
- 03
Information Security Risk Assessment (Clause ISO 27001:2022 6.1.2)
- 04
Information Security Risk Treatment & Statement of Applicability (Clause ISO 27001:2022 6.1.3)
- 05
Information Security Objectives & Planning to Achieve Them (Clause ISO 27001:2022 6.2)
- 06
Competence Records (Training, Skills, and Qualifications) (Clause ISO 27001:2022 7.2)
- 07
Additional ISMS Supporting Documents (if applicable) (Clause ISO 27001:2022 7.5.1)
- 08
Information Security Risk Assessment Results (Clause ISO 27001:2022 8.2)
- 09
Information Security Risk Treatment Results (Clause ISO 27001:2022 8.3)
- 10
Monitoring, Measurement, Analysis & Evaluation Records (Clause ISO 27001:2022 9.1)
- 11
Internal Audit Program & Latest Internal Audit Report (Clause ISO 27001:2022 9.2.2)
- 12
Management Review Results (Including Management Review Meeting Report) (Clause ISO 27001:2022 9.3.3)
ISO 27001 certification in Canada: common questions
Direct answers from Complade's certification team about scope, cost, timing, audits and accreditation.
What is ISO/IEC 27001 certification?
ISO/IEC 27001 certification is an independent assessment of an organization's information security management system against ISO/IEC 27001:2022. It certifies the management system within the stated scope, not an individual or product.
Is Complade an accredited ISO 27001 certification body in Canada?
Yes. Complade Canada Inc. is accredited by the Standards Council of Canada to provide ISO/IEC 27001 management system certification. Complade's current accreditation status can be verified in the SCC directory and IAF CertSearch.
How much does ISO 27001 certification cost in Canada?
Complade's published starting estimate is CAD $1,900 for an organization with 1–10 people in scope under the listed assumptions. A firm quotation is issued after Complade reviews the application, scope and required audit time.
How long does ISO 27001 certification take?
Approximately six weeks is the fastest scenario for a small organization whose ISMS is implemented and ready for audit. Actual timing depends on scope, complexity, readiness, auditor availability and corrective actions.
What is the difference between Stage 1 and Stage 2?
Stage 1 reviews the ISMS scope, required documented information, risk assessment, Statement of Applicability, internal audit and management review. Stage 2 evaluates whether the management system and controls are implemented and effective in practice.
How long is the ISO 27001 certification cycle?
The certification cycle is three years, subject to annual surveillance audits in Years 1 and 2 and a recertification audit before the next cycle.
Can the ISO 27001 audit be performed remotely?
Yes. Complade offers remote and in-person certification audits. The suitable delivery method is confirmed during audit planning and depends on the certification scope.
Can Complade implement ISO 27001 for my organization?
No. Complade is an independent certification body and does not provide consulting, implementation, templates tailored to a client, or internal audit services.
Additional information
Download the controlled Audit Process Policy for the detailed procedures, requirements, and practices used in Complade certification audits.
Audit Process Policy
Download Audit Process PolicyCertification process review
Contact Complade to discuss your certification scope, application, audit process, or evidence requirements. Complade can explain the process but cannot provide implementation consulting.
Contact us