ISO/IEC 27006:2024 · ISMS Certification Bodies · Evidence & Implementation Kit
Get your certification body accredited to ISO 27006, without mapping ISO 17021-1 plus the ISMS requirements yourself.
Every ISO 27006 requirement handed to you as an adopt-ready control, from impartiality and auditor competence through the ISMS audit-time determination and stage 1 and stage 2, with the evidence an accreditation assessor examines.
Accreditation-ready in a weekend, not a quarter.
Here is the honest situation. A certification body that audits ISO 27001 is itself accredited against ISO 27006, which builds ISMS-specific requirements on top of ISO 17021-1: impartiality and independence, auditor competence in information security, the ISMS audit-time determination, and a disciplined stage 1 and stage 2 certification process. Building all of that into a documented, evidenced management system for the certification body, and passing accreditation, is months of work, and a weak auditor-competence scheme or audit-time calculation is the finding an accreditation assessor raises first.
This Kit removes that build. It is every ISO 27006 requirement written as an adopt-ready control you personalize in a weekend, with the evidence an accreditation assessor examines.
What you get, the moment you buy
34
Requirements as adopt-ready controls. Every ISO 27006 requirement, from impartiality and competence through the ISMS audit-time determination, stage 1 and stage 2, surveillance and recertification, written so you personalize and apply it.
34
Evidence-they-examine checklists. For each requirement, exactly what an accreditation assessor examines, plus where certification bodies fall short, so you close it before accreditation.
1
Certification Body Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status and evidence location across the certification body.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.
Grounded in ISO/IEC 27006:2024, which builds ISMS-specific requirements on ISO/IEC 17021-1, with auditor competence, the ISMS audit-time determination and stage 1 and stage 2 called out. Editable Word and Excel files.
Auditor competence and audit time are what assessors probe
The two things an accreditation assessor tests hardest are whether your auditors are genuinely competent in information security and whether your ISMS audit-time determination is defensible. This Kit builds both as explicit controls with the records to prove them, so the areas that fail accreditations are handled first.
What one control looks like
This is the ISMS audit-time determination, a requirement accreditation assessors examine closely. All 34 are built to this depth.
9.1.4 Determining ISMS audit time CERTIFICATION PROCESS
Meet this requirement
The [Certification Body] shall determine the audit time for each ISMS using the methodology and starting-point tables in ISO/IEC 27006-1 Annex C based on the number of persons doing work under the organization control, and shall document adjustments for ISMS complexity, risk, number and type of controls, technologies, outsourcing, and site arrangements, recording the rationale for any reduction or increase from the starting point.
Accreditation note.
The 2024 edition introduced identical-activity headcount grouping and explicit scope-extension audit time; ensure the calculation reflects Annex C and D not the withdrawn 2015 chart.
Evidence an accreditation assessor examines
- Audit time calculation record per client referencing Annex C tables
- Justification for complexity and risk adjustment factors applied
- Effective-headcount determination including identical-activity grouping
- Scope-extension audit time records where applicable
Common finding they raise: Audit days are set to fit the client budget without a documented Annex C calculation or justified adjustment factors, understating required effort.
Why this is not another template pack
- The evidence is the point. A certification body you cannot evidence fails accreditation. This tells you exactly what an assessor examines and where bodies fall short, for every requirement.
- ISMS-specific, not just 17021. Auditor competence in information security, the ISMS audit-time determination and ISMS stage 1 and stage 2 are written in, the requirements ISO 27006 adds on top of ISO 17021-1.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. ISO 27006 builds on ISO 17021-1, so this work maps onto your accreditation across other management-system schemes.
Who buys this
Certification bodies that audit and certify ISO 27001, the accreditation and quality leads who own compliance with ISO 27006, and consultants preparing a body for accreditation. Whether it is a first accreditation or a reassessment, you save months and walk in with the controls and evidence ready.
By the end of the weekend you will have
✓ An adopt-ready control for all 34 requirements
✓ A completed certification body control matrix
✓ The evidence an accreditation assessor examines
✓ Your auditor competence and audit-time scheme defined
✓ A readiness percentage and a fix list
✓ The common findings closed before accreditation
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Who is this for? Certification bodies that audit and certify ISO 27001, not organizations seeking ISO 27001 themselves. It is for the body that issues the certificate.
How does it relate to ISO 17021-1? ISO 27006 adds ISMS-specific requirements on top of ISO 17021-1. This Kit focuses on those ISMS additions plus the general requirements.
Does it cover audit-time determination? Yes. The ISMS audit-time determination and multi-site sampling are their own controls, because accreditation assessors probe them hard.
What if it is not for me? A 30-day money-back guarantee.
Do not map two standards into an accreditation by hand.
Every ISO 27006 requirement is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and get your body accreditation-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com