Back to blog
Checklists

ISO 27001 checklist: every step from scoping to certification

A complete, practical ISO 27001 implementation checklist - the mandatory documents, the risk work, the Annex A controls and the audit stages - so you can see exactly what certification requires before you commit.
GRC Copilot Team
Read in:
ISO 27001 checklist: every step from scoping to certification

An ISO 27001 checklist breaks the standard into the concrete tasks and documents an auditor will actually ask for. ISO/IEC 27001:2022 has two halves: the management-system requirements in clauses 4 to 10 (all mandatory) and the 93 controls in Annex A (applied based on your risk assessment). The checklist below follows the order most successful implementations use.

Phase 1 - Scope and governance

  • Define the ISMS scope: which entities, locations, systems and services are covered.
  • Document the internal and external issues and interested parties that affect the ISMS (clause 4).
  • Obtain documented leadership commitment and assign an ISMS owner (clause 5).
  • Publish an information security policy approved by top management.
  • Set measurable information security objectives (clause 6.2).

Phase 2 - Risk assessment and treatment

  • Define and document your risk assessment methodology - how you score likelihood and impact, and your risk acceptance criteria.
  • Build an asset or information inventory as the basis for assessment.
  • Identify risks, assign owners, and evaluate each against your criteria.
  • Choose a treatment for every risk: mitigate, transfer, avoid or accept.
  • Produce the risk treatment plan and get risk owners to approve residual risk.

Phase 3 - Statement of Applicability and controls

  • Write the Statement of Applicability (SoA): for each of the 93 Annex A controls record whether it applies, its implementation status, and the justification for inclusion or exclusion. This is the single most scrutinised document in the audit.
  • Implement the selected controls across the four Annex A themes: organisational, people, physical and technological.
  • Close the gap between written policy and actual configuration - auditors test both.

Phase 4 - Mandatory documents and records

These are the artefacts ISO 27001 explicitly requires. Missing any of them is a guaranteed finding:

  • ISMS scope statement and information security policy
  • Risk assessment methodology, risk assessment results and risk treatment plan
  • Statement of Applicability
  • Information security objectives and evidence of competence and awareness
  • Monitoring and measurement results
  • Internal audit programme and results
  • Management review minutes
  • Records of nonconformities and corrective actions

Phase 5 - Operate, audit and certify

  • Run the ISMS long enough to generate evidence - most auditors want to see two to three months of operating records.
  • Deliver security awareness training and keep attendance records.
  • Complete a full internal audit covering every clause and applicable control.
  • Hold a documented management review.
  • Raise and close corrective actions for anything the internal audit found.
  • Stage 1 audit: the registrar reviews your documentation and readiness.
  • Stage 2 audit: the registrar tests whether the ISMS actually operates as documented.
  • Maintain the certificate through annual surveillance audits and a three-yearly recertification.

Work the checklist without the spreadsheets

GRC Copilot turns this checklist into a live workspace: it maps your evidence to each Annex A control, keeps your Statement of Applicability current, and shows your readiness score in real time.

How long does ISO 27001 certification take?

For a small to mid-sized organisation starting from scratch, three to six months of implementation plus the audit cycle is realistic. Organisations with mature security practices often move faster; the constraint is usually the evidence history, not the control work.

Frequently asked questions

Do I have to implement all 93 Annex A controls?

No. Annex A is a catalogue, not a mandate. You implement the controls that address your assessed risks and justify any exclusions in the Statement of Applicability. Clauses 4 to 10, however, are all mandatory.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 is a documentation and readiness review - the auditor checks that your ISMS exists on paper. Stage 2 tests implementation: the auditor samples evidence to confirm the controls genuinely operate.

Can I get certified without an internal audit?

No. A completed internal audit and a management review are mandatory inputs to certification, and their absence is one of the most common reasons a Stage 2 audit fails.

Is ISO 27001 the same as SOC 2?

No. ISO 27001 certifies a management system against an international standard; SOC 2 is an attestation report produced by a CPA firm against the Trust Services Criteria. They overlap heavily in evidence, so many organisations pursue both.

Key takeaways

  • Clauses 4 to 10 are mandatory; Annex A controls are selected by risk.
  • The Statement of Applicability is the document auditors examine most closely.
  • Certification requires an internal audit and a management review before Stage 2.
  • Evidence history matters - start generating records early.
#iso27001 #checklist #isms #certification #implementation