Hi, we are an Information Security Consulting and Auditing Company. We are well established in the information security space and have been doing PCI DSS audits for about 9 years. We have a client who would like us to certify them for ISO 27001. We have an auditor in the team, who is certified as a ISO 27001 Lead Implementer. What will it require for us to become a company who can perform a ISO 27001 Auditor?
To certify an organization your company has to be accredited by an accreditation body (e.g., UKAS for UK, or ANAB for USA), and for this purpose your organization has to be certified by an accreditation body against ISO/IEC 17065. You can have an overview of this standard here: https://www.iso.org/obp/ui/#iso:std:iso-iec:17065:ed-1:v1:en