ISO 27001 Compliance Checklist | Certifyi
Compliance checklist

ISO 27001 Compliance Checklist

ISO 27001 certifies your Information Security Management System (ISMS). Here's the practical order of operations to get there.

Book a 20-min deal readiness call
  1. Get management commitment

    ISO 27001 fails without leadership buy-in. Secure budget, a project owner, and executive sign-off before anything else.

  2. Define your ISMS scope

    Decide which parts of the business, which locations, and which systems fall inside the certification boundary.

  3. Run a risk assessment

    Identify information security risks across your scope, then score them by likelihood and impact using a documented methodology.

  4. Build your Statement of Applicability

    Map each of Annex A's controls to your environment: which apply, which don't, and why. This document is central to the audit.

  5. Write your core policies

    Information security policy, risk treatment plan, access control policy, and the rest of the mandatory documentation set.

  6. Implement controls

    Put the technical and organizational controls from your SoA into practice: access management, encryption, vendor security, incident response.

  7. Run internal audits

    Test your own ISMS against the standard before the external auditor does. Fix what's broken while it's still cheap to fix.

  8. Hold a management review

    Leadership formally reviews ISMS performance, audit findings, and improvement actions. This is a certification requirement, not optional.

  9. Stage 1 audit

    The certification body reviews your documentation and readiness. This surfaces gaps before the real test.

  10. Stage 2 audit

    The certification body tests whether your controls are actually operating as documented. Passing this earns your certificate.

  11. Maintain and improve

    ISO 27001 requires ongoing surveillance audits and a 3-year recertification cycle, so the ISMS has to keep running, not just exist for the audit.

← Back to all checklists

What auditors actually ask for

  • Can you show top management formally reviewed the ISMS?
  • Does your Statement of Applicability justify every excluded Annex A control?
  • Can you evidence a completed internal audit cycle before Stage 2?
  • Can you show risk treatment decisions were approved by a risk owner?
  • Is your asset inventory current and owned?

Where teams most often trip up

  • Scoping the ISMS so broadly that evidence becomes unmanageable
  • A Statement of Applicability that lists controls but never justifies exclusions
  • Skipping the internal audit and management review, both are mandatory clauses
  • Policies written but never communicated or acknowledged by staff
  • Forgetting that surveillance audits continue annually after certification

Realistic timeline

Typically 3-6 months to Stage 1 for a first ISMS, then 4-8 weeks to Stage 2. Certification runs on a 3-year cycle with annual surveillance.

Scroll to Top