Checklist · 22 items · Updated July 2026

ISO 27001 Checklist

The ISMS, step by step.

ISO 27001 certifies a management system, not just controls — which is why teams that treat it like SOC 2 with different letters get findings. This checklist follows the order a certification body will examine.

01 Build the ISMS foundation

  • Define ISMS scope: products, locations, teams, and what's explicitly excluded
  • Write the information security policy and get top-management approval
  • Assign security roles and responsibilities in writing
  • Establish the risk assessment methodology: how you score likelihood, impact, and acceptance
  • Create the risk register and populate it from a structured assessment

02 Select and justify controls

  • Work through all 93 Annex A controls and mark each applicable or excluded
  • Write the Statement of Applicability with a justification for every exclusion
  • Map each applicable control to an owner and an implementation status
  • Build the risk treatment plan linking risks to controls with deadlines

03 Implement and operate

  • Implement access control, cryptography, operations security, and supplier controls per your SoA
  • Run security awareness training tied to onboarding and annual cycles
  • Establish incident management with documented response records
  • Operate vendor risk management with contracts covering security requirements
  • Collect operating evidence continuously — certification auditors sample records, not intentions

04 Audit yourself first

  • Run a full internal audit covering every ISMS clause and applicable control
  • Record nonconformities and corrective actions with owners and dates
  • Hold a management review with documented inputs and decisions
  • Close corrective actions before Stage 1 — open findings become audit findings

05 Pass certification

  • Choose an accredited certification body (check accreditation, not just price)
  • Pass Stage 1: documentation review of ISMS, SoA, and risk assessment
  • Pass Stage 2: implementation audit with evidence sampling
  • Plan for surveillance audits in years two and three — the ISMS has to keep running

The trap in ISO 27001 is doing it as paperwork. The standard’s clause structure — risk assessment, treatment, internal audit, management review — is a loop, and certification bodies check that the loop actually turned: dated records, real decisions, closed actions. A beautiful ISMS binder with no operating history fails Stage 2.

The efficient path runs ISO 27001 and SOC 2 together on one control set — see the SOC 2 vs ISO 27001 guide for when that’s worth it.

Don't Want to Run This Yourself?

ISO 27001 Implementation

End-to-end ISO 27001 implementation: ISMS build, risk assessment, Statement of Applicability, internal audit, and certification support — experts included.

Book a Call
Frequently Asked
How long does ISO 27001 certification take?

Typical range for a startup with an owner: 4–6 months to Stage 2, driven mostly by how fast the risk assessment and internal audit cycles run. The certification audit itself spans a few weeks across both stages.

What's the difference between this and a SOC 2 checklist?

SOC 2 tests controls; ISO 27001 certifies the management system that chooses and reviews those controls. The overlap in technical controls is large — evidence collected once maps to both — but the ISMS clauses (risk methodology, internal audit, management review) have no SOC 2 equivalent.

Can we self-declare ISO 27001 compliance?

You can claim alignment, but only an accredited certification body can certify you — and enterprise procurement teams ask for the certificate. Self-declaration rarely survives a security review.