Training, exams and certification
Forty scenario questions in two hours, restricted open book, twenty to pass. The word that does the work here is restricted: you may take four named documents in, and nothing else.
The APMG ISO/IEC 27001 Auditor certificate tests whether you can judge audit situations against the standard, rather than recall the standard itself.
| Questions | 40, multiple choice, built on mini scenarios |
|---|---|
| Duration | 120 minutes |
| Pass mark | 50% — 20 correct answers out of 40 |
| Materials | Restricted open book |
| Prerequisites | None stated |
| Accredited training | Not mandatory. Self-study and direct exam booking are supported |
| Typical course | Two days, where a course is taken |
Restricted open book means a named list, and the list is short:
| ISO/IEC 27001:2022 | The requirements standard itself |
|---|---|
| ISO/IEC 27002:2022 | The guidance on the Annex A controls |
| ISO 19011:2018 | Guidelines for auditing management systems |
| APMG supplementary paper | The scheme’s own ISO/IEC 27001 supplementary material |
Your course notes are not on that list. Neither is a summary you wrote yourself, a cheat sheet, or an annotated printout of somebody’s blog. If your revision strategy is a one-page crib, it does not survive contact with this exam.
The inclusion of ISO 19011 is the tell. This is an auditing exam before it is an information-security exam: the questions are as likely to turn on how an audit is planned, conducted and reported as on what a control requires.
Two hours across forty questions is three minutes each, and the questions are built on mini scenarios — a short situation, then a judgement.
Three minutes is enough to read a scenario, form a view and check one clause. It is not enough to read a scenario, form no view, and go looking for the answer in three documents. The difference between those two ways of using the time is the difference between finishing and not.
Twenty wrong answers is the margin, which is unusually wide — half the paper. Failure here is rarely about the threshold; it is about the last ten questions being rushed.
This certificate does not make you a certified lead auditor. It certifies expertise in performing audits against ISO/IEC 27001. Schemes that award a Lead Auditor credential — PECB’s, for one — additionally require years of professional experience and a logged number of audit hours before the title is granted.
That is not a criticism of either scheme; they answer different questions. APMG’s asks whether you understand auditing against this standard. PECB’s asks that, and then asks how long you have been doing it.
Tab all four permitted documents. Clause numbers on the outside edge, control themes on the bottom. You are being timed on retrieval, not on reading.
Read ISO 19011 properly. It is the document candidates skip, and it carries the audit process the scenarios are built on.
Decide, then verify. Form a view from the scenario before you open anything.
ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 19011:2018 and the APMG ISO/IEC 27001 supplementary paper. Nothing else.
Twenty out of forty — 50%.
Two hours for forty scenario-based multiple-choice questions.
APMG does not state it as a prerequisite, though most providers sequence the levels that way.
No, though it is advised. A two-day Auditor course is the usual route.
No. That is a different credential under a different scheme, with experience and audit-hour requirements attached.
Sources. Every figure on this page comes from APMG International’s own published certification pages, checked in September 2026.
GoToCertify will offer preparation for the ISO/IEC 27001 certifications, with the exam voucher alongside it.
Not on sale on GoToCertify yet — we are setting it up. In the meantime the exam facts above are free to use.