TRECCERT is a certification body for professional credentials in information security and related disciplines. Several of its programmes, including the ISO/IEC 27001 Lead Implementer and Lead Auditor certifications, are accredited by the American National Accreditation Board (ANAB) under ISO/IEC 17024, the standard governing bodies that certify persons. That places them in the same accredited category as credentials such as ISACA's CISM and ISC2's CISSP. This article maps the TRECCERT ISO 27001 path and helps you choose where to enter it.
For transparency: Aron Lange, the author of this guide, is a TRECCERT Approved Trainer, and GRC Lab distributes official TRECCERT exam vouchers.
Certifying organizations vs certifying people
Two different things are called "ISO 27001 certification", and they run under different rules. Organizations certify their management system against ISO 27001, through a certification body accredited under ISO/IEC 17021-1; that is the certification process covered earlier in this guide. Individuals cannot certify against ISO 27001 itself. They earn personal credentials, issued under ISO/IEC 17024, which attest that a person has demonstrated defined knowledge and, at the higher levels, verified experience. The TRECCERT programme belongs to this second category.
Why accreditation matters for a personal credential
Anyone can sell a certificate. Accreditation under ISO/IEC 17024 means an independent accreditation body has examined how the certification is run: how competence is defined, how exams are constructed and protected, how impartiality is maintained, and how certificate holders are required to keep their knowledge current. When an employer or client sees an accredited credential, they are not trusting the issuer's marketing; they are trusting an audited process. That is why accreditation is the first thing to check before investing in any certification, TRECCERT or otherwise.
The ISO 27001 certification path
Credential | Validates | Experience required |
|---|---|---|
ISO/IEC 27001 Practitioner | Foundational understanding of the requirements and controls | None |
ISO/IEC 27001 Lead Implementer | Designing, implementing and managing an ISMS | Yes, verified at application |
ISO/IEC 27001 Lead Auditor | Planning, conducting and managing ISMS audits | Yes, verified at application |
ISO/IEC 27005 Professional | Information security risk management based on ISO/IEC 27005 | See TRECCERT requirements |

The Practitioner is the entry point: no experience requirement, a shorter exam, and a solid base for either specialization. The Lead Implementer is the credential for the people who build and run the ISMS. The Lead Auditor serves audit, assurance and senior compliance roles. The 27005 Professional complements both tracks with depth in risk management, the discipline at the centre of every ISMS.
Choosing your track
Choose by the work you want to be accountable for, not by perceived prestige. If your role is to get an organization to a passed audit, the implementer track matches your daily reality: you will be building the 12 steps this guide describes. If you want to be the person who evaluates other organizations' ISMS and writes findings they must act on, the auditor track is yours. Many professionals eventually hold both, and implementation experience makes a noticeably better auditor.
From the auditor's chair
The market context has shifted. AI tools have made surface knowledge cheap: anyone can ask a model what a control means. What has become more valuable, not less, is verifiable competence, the demonstrated ability to apply the standard, defend decisions in front of an auditor, and judge whether a generated answer is right. An accredited certification does not replace that judgement, but it is the clearest portable evidence that you have built it. That is also why the Lead-level credentials verify experience, not just exam performance.
Frequently asked questions
Are TRECCERT certifications accredited?
The ISO/IEC 27001 Lead Implementer and Lead Auditor certifications are accredited by ANAB under ISO/IEC 17024. Entry-level credentials in the programme are not individually accredited, which is normal across certification bodies.
Where should I start without any experience?
With the ISO/IEC 27001 Practitioner. It has no experience requirement and covers the foundations both Lead-level tracks build on.
Do TRECCERT certifications expire?
Accredited certifications are valid for three years. Holders maintain them through continuing professional education, a maintenance fee and adherence to the TRECCERT Code of Ethics.


