ISO 27001 Checklist
The ISMS, step by step.ISO 27001 certifies a management system, not just controls — which is why teams that treat it like SOC 2 with different letters get findings. This checklist follows the order a certification body will examine.
01 Build the ISMS foundation
- Define ISMS scope: products, locations, teams, and what's explicitly excluded
- Write the information security policy and get top-management approval
- Assign security roles and responsibilities in writing
- Establish the risk assessment methodology: how you score likelihood, impact, and acceptance
- Create the risk register and populate it from a structured assessment
02 Select and justify controls
- Work through all 93 Annex A controls and mark each applicable or excluded
- Write the Statement of Applicability with a justification for every exclusion
- Map each applicable control to an owner and an implementation status
- Build the risk treatment plan linking risks to controls with deadlines
03 Implement and operate
- Implement access control, cryptography, operations security, and supplier controls per your SoA
- Run security awareness training tied to onboarding and annual cycles
- Establish incident management with documented response records
- Operate vendor risk management with contracts covering security requirements
- Collect operating evidence continuously — certification auditors sample records, not intentions
04 Audit yourself first
- Run a full internal audit covering every ISMS clause and applicable control
- Record nonconformities and corrective actions with owners and dates
- Hold a management review with documented inputs and decisions
- Close corrective actions before Stage 1 — open findings become audit findings
05 Pass certification
- Choose an accredited certification body (check accreditation, not just price)
- Pass Stage 1: documentation review of ISMS, SoA, and risk assessment
- Pass Stage 2: implementation audit with evidence sampling
- Plan for surveillance audits in years two and three — the ISMS has to keep running
The trap in ISO 27001 is doing it as paperwork. The standard’s clause structure — risk assessment, treatment, internal audit, management review — is a loop, and certification bodies check that the loop actually turned: dated records, real decisions, closed actions. A beautiful ISMS binder with no operating history fails Stage 2.
The efficient path runs ISO 27001 and SOC 2 together on one control set — see the SOC 2 vs ISO 27001 guide for when that’s worth it.
ISO 27001 Implementation
End-to-end ISO 27001 implementation: ISMS build, risk assessment, Statement of Applicability, internal audit, and certification support — experts included.
Book a CallHow long does ISO 27001 certification take?
Typical range for a startup with an owner: 4–6 months to Stage 2, driven mostly by how fast the risk assessment and internal audit cycles run. The certification audit itself spans a few weeks across both stages.
What's the difference between this and a SOC 2 checklist?
SOC 2 tests controls; ISO 27001 certifies the management system that chooses and reviews those controls. The overlap in technical controls is large — evidence collected once maps to both — but the ISMS clauses (risk methodology, internal audit, management review) have no SOC 2 equivalent.
Can we self-declare ISO 27001 compliance?
You can claim alignment, but only an accredited certification body can certify you — and enterprise procurement teams ask for the certificate. Self-declaration rarely survives a security review.