The TRECCERT ISO/IEC 27001 Lead Implementer certification validates your ability to design, implement and manage an information security management system based on ISO/IEC 27001. It is accredited by the American National Accreditation Board (ANAB) under ISO/IEC 17024, placing it alongside credentials such as ISACA's CISM and ISC2's CISSP. It is the credential for the people who actually build and run the ISMS.

Who is it for?
This certification suits professionals in information security, IT governance and risk management who lead or support an ISO 27001 implementation: ISMS managers, security consultants, compliance officers, IT managers, and anyone made responsible for getting their organization to a passed audit. If your work is the 12-step project this guide describes, this is the credential that matches it.
The six exam domains
The exam evaluates knowledge across six domains, weighted as follows.
Domain | Weight | Focus |
|---|---|---|
01 ISMS Fundamentals | 6.66% | Terminology, concepts and principles of an ISMS |
02 ISMS Requirements and Controls | 26.66% | The requirements and controls of ISO/IEC 27001 |
03 ISMS Initiation and Planning | 13.66% | Initiating and planning an ISMS against security objectives |
04 ISMS Implementation | 26.66% | Implementing and operating an ISMS in line with the standard |
05 ISMS Evaluation | 13.66% | Evaluating ISMS performance and effectiveness |
06 ISMS Improvement | 13.66% | Maintaining and improving suitability, adequacy and effectiveness |
The weighting mirrors the reality of the role: more than half of the exam sits in requirements, controls and implementation, the ground covered by the risk assessment, risk treatment and Annex A articles of this guide.
Exam format
Element | Detail |
|---|---|
Questions | 150, multiple choice |
Duration | 3 hours |
Pass mark | 60 percent, 90 of 150 correct |
Delivery | Online, computerized, with an immediate result |
Certification requirements
Passing the exam is the milestone, not the finish line. The credential is awarded after TRECCERT verifies your experience through the certification application.
Requirement | ISO/IEC 27001 Lead Implementer |
|---|---|
General work experience | 5 years |
Information security experience | 2 years, including 400 hours of implementation tasks |
Education waiver | A bachelor's or master's degree can waive up to 2 years of general experience |
The sequence published by TRECCERT runs exam first, verification second: you sit the exam once prepared, then submit the certification application and experience verification forms by email, and the credential is issued once the application is approved.
Maintaining the certification
The certification is valid for three years. Keeping it active requires 90 continuing professional education credits across the cycle, with 30 per year recommended, earned through training, conferences, publishing or comparable professional activity. A maintenance fee applies, payable annually or once per cycle, and holders commit to the TRECCERT Code of Ethics. The current details and the candidate handbook are published at treccert.com.
What does the certification cost?
Three components make up the real cost. The exam voucher: the GRC Lab store lists the Lead Implementer voucher at €629, with a free retake included, so a failed first attempt does not double the exam cost. Preparation: self-study with the official TRECCERT material, which can be added at checkout, or structured training if you want the implementation practice behind the theory. And after certification, the TRECCERT maintenance fee. Current voucher prices are always shown in the store.
From the auditor's chair
I meet certified Lead Implementers from the other side of the table, and the credential changes how the conversation starts: it tells me the person speaks the standard's language and has evidenced real implementation hours, so we can discuss substance instead of definitions. What it signals to employers is the same thing regulators increasingly demand: a named, competent human who can be held accountable for the ISMS. Tools can draft a policy in seconds; they cannot own one in an audit interview. The exam is passable through disciplined study, but the professionals who get the most from this credential are those who treat the 400 implementation hours as the actual qualification and the exam as its proof.
Frequently asked questions
Do I need the Practitioner certification first?
No. There is no required sequence. The Practitioner is a useful entry point for early-career professionals, but experienced implementers go directly to the Lead Implementer exam.
Can I sit the exam before I have the full experience?
Yes. The published process runs exam first, then the certification application in which TRECCERT verifies your experience. The credential is issued once both are complete.
How long is the certification valid?
Three years. It is maintained through 90 CPE credits per cycle, the maintenance fee and adherence to the Code of Ethics.


