ISO 27001 Compliance Checklist
ISO 27001 certifies your Information Security Management System (ISMS). Here's the practical order of operations to get there.
Book a 20-min deal readiness callGet management commitment
ISO 27001 fails without leadership buy-in. Secure budget, a project owner, and executive sign-off before anything else.
Define your ISMS scope
Decide which parts of the business, which locations, and which systems fall inside the certification boundary.
Run a risk assessment
Identify information security risks across your scope, then score them by likelihood and impact using a documented methodology.
Build your Statement of Applicability
Map each of Annex A's controls to your environment: which apply, which don't, and why. This document is central to the audit.
Write your core policies
Information security policy, risk treatment plan, access control policy, and the rest of the mandatory documentation set.
Implement controls
Put the technical and organizational controls from your SoA into practice: access management, encryption, vendor security, incident response.
Run internal audits
Test your own ISMS against the standard before the external auditor does. Fix what's broken while it's still cheap to fix.
Hold a management review
Leadership formally reviews ISMS performance, audit findings, and improvement actions. This is a certification requirement, not optional.
Stage 1 audit
The certification body reviews your documentation and readiness. This surfaces gaps before the real test.
Stage 2 audit
The certification body tests whether your controls are actually operating as documented. Passing this earns your certificate.
Maintain and improve
ISO 27001 requires ongoing surveillance audits and a 3-year recertification cycle, so the ISMS has to keep running, not just exist for the audit.
What auditors actually ask for
- Can you show top management formally reviewed the ISMS?
- Does your Statement of Applicability justify every excluded Annex A control?
- Can you evidence a completed internal audit cycle before Stage 2?
- Can you show risk treatment decisions were approved by a risk owner?
- Is your asset inventory current and owned?
Where teams most often trip up
- Scoping the ISMS so broadly that evidence becomes unmanageable
- A Statement of Applicability that lists controls but never justifies exclusions
- Skipping the internal audit and management review, both are mandatory clauses
- Policies written but never communicated or acknowledged by staff
- Forgetting that surveillance audits continue annually after certification
Realistic timeline
Typically 3-6 months to Stage 1 for a first ISMS, then 4-8 weeks to Stage 2. Certification runs on a 3-year cycle with annual surveillance.