Governance. Risk. Compliance. Cybersecurity.
Audit & Certification

Audit & Certification — NCEMA 7000

What to expect from the external assessment — and how MAST positions you to pass first time.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Selecting an audit body or assessor

  • Accreditation status and recognition in your target markets
  • Experience in your sector and geography
  • Lead auditor availability for the desired audit window
  • Commercial terms, surveillance frequency and re-certification cycle
Audit-body selection criteria

Checklist titled "Audit-body selection criteria" with 4 items, every item marked complete: Accreditation status and recognition in your target markets; Experience in your sector and geography; Lead auditor availability for the desired audit window; Commercial terms, surveillance frequency and re-certification cycle.

  • Accreditation status and recognition in your target markets
  • Experience in your sector and geography
  • Lead auditor availability for the desired audit window
  • Commercial terms, surveillance frequency and re-certification cycle

Stage 1 readiness review

Documentation and design review — typically two to three days. Outcome is either readiness to proceed or a corrective action list before Stage 2.

Stage 2 / main assessment

On-site or hybrid fieldwork against the implemented control set. MAST attends in an observation role to clarify evidence and protect engagement momentum.

Surveillance and re-certification

Annual surveillance plus three-yearly re-certification for ISO standards; comparable cycles for SOC 2 (annual) and regulator submissions. MAST's Managed Compliance Service maintains evidence continuously between audits.

End-to-end certification journey

From engaging an assessor to maintaining certification — the full NCEMA 7000 lifecycle on one timeline.

NCEMA 7000 certification lifecycle

Process flow diagram titled "NCEMA 7000 certification lifecycle" with 8 sequential steps: Select accredited body; Stage 1 documentation review; Remediate Stage 1 findings; Stage 2 main assessment; Address non-conformities; Certificate issued; Annual surveillance; Three-yearly recertification.

  1. Select accredited body
  2. Stage 1 documentation review
  3. Remediate Stage 1 findings
  4. Stage 2 main assessment
  5. Address non-conformities
  6. Certificate issued
  7. Annual surveillance
  8. Three-yearly recertification