ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange episode artwork

EPISODE · Jun 2, 2026 · 37 MIN

ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange

from Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance · host Dejan Kosutic

In this Secure & Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Aron Lange, founder of GRC Lab and an ISO 27001 certification auditor, about what auditors look for in certification audits. Aron highlights common nonconformities and explains how auditors gather objective evidence through interviews, document review, and observation, emphasizing execution over paperwork. The conversation also covers auditor interpretation, challenging unsupported findings, risk-based control auditing, management-system vs security-posture certification, continual improvement, and the difference between nonconformities and opportunities for improvement.Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software- White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses- Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t- How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining  (00:00) - Interview with Aron Lange (01:09) - Top Nonconformities in Audits (04:20) - How Auditors Gather Evidence (11:55) - The Limits of Tools Based on SOC 2 (14:05) - Challenging Auditor Interpretations (16:48) - Disputing Nonconformities (19:38) - Problem with Generic Controls (23:07) - Certifying Management System (27:02) - Nonconformity vs Improvement (29:58) - Auditing vs Consulting (32:24) - Auditor Mindset and Trust (35:03) - Prep Tips and Wrap Up (36:30) - Resources for Consultants and CISOs

Episode metadata supplied by the publisher feed · Published Jun 2, 2026

Embed this episode

Ready to play

ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange

0:00 37:51

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance?

This episode is 37 minutes long.

When was this Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance episode published?

This episode was published on June 2, 2026.

Can I download this Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!