ISO 27001

ISO 27001 checklist: every step from scope to certificate

A practical checklist for an ISO 27001:2022 project, in the order auditors expect to see the work. Tick it off as you go.

Short answer

An ISO 27001 checklist covers the steps to certification in order: define the ISMS scope, get leadership commitment and a policy, assess and treat risks, write the Statement of Applicability, implement and evidence controls, train people, run an internal audit and management review, fix nonconformities, then pass the Stage 1 and Stage 2 certification audits.

Key takeaways

  • Do the work in the order of clauses 4 to 10; auditors follow the same order.
  • The risk assessment and SoA come before choosing controls.
  • Controls only count if they leave records.
  • Internal audit and management review must run before Stage 2.

How to use this checklist

Each section follows a clause of ISO/IEC 27001:2022. Work through them in order; later steps depend on earlier ones. Progress ticks are saved in your browser.

Checklist

Clause 4: context and scope

0 of 4 done

Checklist

Clause 5: leadership

0 of 3 done

Checklist

Clause 6: planning

0 of 5 done

Checklist

Clause 7: support

0 of 4 done

Checklist

Clause 8 and Annex A: operation

0 of 5 done

Checklist

Clauses 9 and 10: evaluation and improvement

0 of 4 done

Checklist

Certification

0 of 5 done

Mandatory documents

Auditors start with the documented information the standard names: ISMS scope (4.3), information security policy (5.2), risk assessment and treatment process (6.1.2, 6.1.3), Statement of Applicability (6.1.3 d), objectives (6.2), evidence of competence (7.2), operational planning records (8.1), risk assessment and treatment results (8.2, 8.3), monitoring results (9.1), internal audit programme and results (9.2), management review results (9.3), and nonconformities and corrective actions (10.2).

Put this into practice on QULDEX

Frequently asked questions

How long does it take to work through an ISO 27001 checklist?

Most organisations of 50 to 250 people take 6 to 12 months from scoping to certificate, depending on how much of the ISMS already exists.

What is the most common gap before Stage 1?

A risk assessment and Statement of Applicability that don't match each other, or controls marked implemented with no records behind them.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO/IEC 27001:2022/Amd 1:2024 Climate action changes, ISO
  3. ISO/IEC 27003:2017 Information security management systems: Guidance, ISO