The TRECCERT ISO/IEC 27001 Lead Auditor certification validates your ability to plan, conduct and manage audits of an information security management system against ISO/IEC 27001. The Lead Auditor level is accredited by the American National Accreditation Board (ANAB) under ISO/IEC 17024, which places it alongside credentials such as ISACA's CISM and ISC2's CISSP. For audit, assurance and senior compliance roles, it is one of the most valuable certifications in the field.
Who is it for?
The certification is designed for professionals who evaluate rather than build: internal auditors, compliance officers, security consultants and assurance professionals. It proves you can examine whether an organization's information security actually meets the standard, and report on it in a way that withstands challenge.
The three auditor levels
The auditor track has three levels. All share the profession; they differ in the experience you can evidence. The requirements at a glance:
Requirement | Associate Auditor | Auditor | Lead Auditor |
|---|---|---|---|
General work experience | Less than 3 years | 3 years | 5 years |
Information security experience | Less than 1 year | 1 year | 2 years |
ISMS audit experience | Less than 200 hours | More than 200 hours | More than 400 hours |
Degree waiver available | No | Yes | Yes |
ANAB accredited | No | No | Yes |
A bachelor's or master's degree can waive one or two years of the general work experience respectively. A high school degree is the minimum education requirement. The practical consequence: nobody is locked out for being early in their career. You enter at the level your experience supports and progress as your audit hours grow.
The six exam domains
Domain | Weight | Focus |
|---|---|---|
ISMS Fundamentals | 13.33% | ISMS principles and terminology |
ISMS Requirements and Controls | 36.66% | Interpreting ISO/IEC 27001 in an audit context |
Auditing Fundamentals | 6.66% | Auditing principles and roles |
Audit Initiation and Preparation | 10.00% | Planning and preparing risk-based audits |
Audit Execution | 23.33% | Conducting audits according to plan and standards |
Audit Reporting and Follow-Up | 10.00% | Reporting findings and verifying corrective actions |
Note where the weight sits: more than a third of the exam is the standard itself. An auditor who cannot interpret the requirements has nothing to audit against, which is why this guide's implementation section is relevant preparation even for the audit track.
Exam format
Element | Detail |
|---|---|
Questions | 150, multiple choice |
Duration | 3 hours |
Pass mark | 60 percent, 90 of 150 correct |
Delivery | Online, computerized, with an immediate result |
The certification process
Prepare for the exam across the six domains, with emphasis on the standard's requirements and audit execution.
Purchase an exam voucher, submit the exam application form, and schedule your slot on TRECCERT's online platform once approved.
Sit the 150-question exam; the result appears immediately.
Submit the certification application and the experience verification form. TRECCERT reviews your education and audit hours and awards the level they support.
Maintain the credential: it is valid for three years, sustained through 90 CPE credits per cycle, the maintenance fee, and the TRECCERT Code of Ethics. Records of CPE activity should be kept for twelve months beyond the cycle for potential audits. Current details are in the candidate handbook at treccert.com.

What does the certification cost?
The exam voucher is the main position: the GRC Lab store lists the Lead Auditor voucher at €629, with a free retake included, which removes the financial risk of a demanding first attempt. Add preparation, through self-study with the official TRECCERT material available at checkout or through instructor-led training, and the maintenance fee once certified. Current voucher prices are always shown in the store.
From the auditor's chair
This is the credential behind the work I do, so an honest word about the work itself. Auditing is not finding faults; it is establishing, on evidence, whether a management system does what the organization claims, and writing findings precisely enough that people accept them and act. The skills that matter daily are interviewing, sampling, and separating what you observed from what you concluded. Implementation experience helps more than any other preparation, because you recognize what a working ISMS looks like from the inside. If your audit hours are still growing, the Associate Auditor level is the honest entry: same profession, same exam, a level that matches your evidence today.
Lead Implementer or Lead Auditor?
Choose by accountability. The Lead Implementer is accountable for building an ISMS that passes; the Lead Auditor is accountable for judging whether it deserves to. The experience requirements mirror each other, five years general and two in information security, with 400 hours of implementation tasks on one side and 400 audit hours on the other. Many professionals hold both over a career, and most auditors are better for having implemented first.
Frequently asked questions
Can I take the exam without audit experience?
Yes. The exam is open to you, and TRECCERT awards the level your verified experience supports. The Lead Auditor level itself requires five years of general experience, two in information security, and more than 400 ISMS audit hours.
Is the certification accredited?
The Lead Auditor level is accredited by ANAB under ISO/IEC 17024. The Associate Auditor and Auditor levels are not individually accredited.
Should I do Lead Implementer or Lead Auditor first?
Follow your role. If you are building an ISMS, start with the Lead Implementer. If you are moving into audit and assurance, the auditor track is yours, and implementation experience will make you a stronger auditor.


