An ISO 27001 checklist breaks the standard into the concrete tasks and documents an auditor will actually ask for. ISO/IEC 27001:2022 has two halves: the management-system requirements in clauses 4 to 10 (all mandatory) and the 93 controls in Annex A (applied based on your risk assessment). The checklist below follows the order most successful implementations use.
Phase 1 - Scope and governance
- Define the ISMS scope: which entities, locations, systems and services are covered.
- Document the internal and external issues and interested parties that affect the ISMS (clause 4).
- Obtain documented leadership commitment and assign an ISMS owner (clause 5).
- Publish an information security policy approved by top management.
- Set measurable information security objectives (clause 6.2).
Phase 2 - Risk assessment and treatment
- Define and document your risk assessment methodology - how you score likelihood and impact, and your risk acceptance criteria.
- Build an asset or information inventory as the basis for assessment.
- Identify risks, assign owners, and evaluate each against your criteria.
- Choose a treatment for every risk: mitigate, transfer, avoid or accept.
- Produce the risk treatment plan and get risk owners to approve residual risk.
Phase 3 - Statement of Applicability and controls
- Write the Statement of Applicability (SoA): for each of the 93 Annex A controls record whether it applies, its implementation status, and the justification for inclusion or exclusion. This is the single most scrutinised document in the audit.
- Implement the selected controls across the four Annex A themes: organisational, people, physical and technological.
- Close the gap between written policy and actual configuration - auditors test both.
Phase 4 - Mandatory documents and records
These are the artefacts ISO 27001 explicitly requires. Missing any of them is a guaranteed finding:
- ISMS scope statement and information security policy
- Risk assessment methodology, risk assessment results and risk treatment plan
- Statement of Applicability
- Information security objectives and evidence of competence and awareness
- Monitoring and measurement results
- Internal audit programme and results
- Management review minutes
- Records of nonconformities and corrective actions
Phase 5 - Operate, audit and certify
- Run the ISMS long enough to generate evidence - most auditors want to see two to three months of operating records.
- Deliver security awareness training and keep attendance records.
- Complete a full internal audit covering every clause and applicable control.
- Hold a documented management review.
- Raise and close corrective actions for anything the internal audit found.
- Stage 1 audit: the registrar reviews your documentation and readiness.
- Stage 2 audit: the registrar tests whether the ISMS actually operates as documented.
- Maintain the certificate through annual surveillance audits and a three-yearly recertification.
Work the checklist without the spreadsheets
GRC Copilot turns this checklist into a live workspace: it maps your evidence to each Annex A control, keeps your Statement of Applicability current, and shows your readiness score in real time.
Try GRC Copilot free Generate an AI-powered assessment Download the checklist Book a demo
How long does ISO 27001 certification take?
For a small to mid-sized organisation starting from scratch, three to six months of implementation plus the audit cycle is realistic. Organisations with mature security practices often move faster; the constraint is usually the evidence history, not the control work.
Frequently asked questions
Do I have to implement all 93 Annex A controls?
No. Annex A is a catalogue, not a mandate. You implement the controls that address your assessed risks and justify any exclusions in the Statement of Applicability. Clauses 4 to 10, however, are all mandatory.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 is a documentation and readiness review - the auditor checks that your ISMS exists on paper. Stage 2 tests implementation: the auditor samples evidence to confirm the controls genuinely operate.
Can I get certified without an internal audit?
No. A completed internal audit and a management review are mandatory inputs to certification, and their absence is one of the most common reasons a Stage 2 audit fails.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 certifies a management system against an international standard; SOC 2 is an attestation report produced by a CPA firm against the Trust Services Criteria. They overlap heavily in evidence, so many organisations pursue both.
Key takeaways
- Clauses 4 to 10 are mandatory; Annex A controls are selected by risk.
- The Statement of Applicability is the document auditors examine most closely.
- Certification requires an internal audit and a management review before Stage 2.
- Evidence history matters - start generating records early.