Short answer
An ISO 27001 checklist covers the steps to certification in order: define the ISMS scope, get leadership commitment and a policy, assess and treat risks, write the Statement of Applicability, implement and evidence controls, train people, run an internal audit and management review, fix nonconformities, then pass the Stage 1 and Stage 2 certification audits.
Key takeaways
- Do the work in the order of clauses 4 to 10; auditors follow the same order.
- The risk assessment and SoA come before choosing controls.
- Controls only count if they leave records.
- Internal audit and management review must run before Stage 2.
How to use this checklist
Each section follows a clause of ISO/IEC 27001:2022. Work through them in order; later steps depend on earlier ones. Progress ticks are saved in your browser.
Checklist
Clause 4: context and scope
0 of 4 done
Checklist
Clause 5: leadership
0 of 3 done
Checklist
Clause 6: planning
0 of 5 done
Checklist
Clause 7: support
0 of 4 done
Checklist
Clause 8 and Annex A: operation
0 of 5 done
Checklist
Clauses 9 and 10: evaluation and improvement
0 of 4 done
Checklist
Certification
0 of 5 done
Mandatory documents
Auditors start with the documented information the standard names: ISMS scope (4.3), information security policy (5.2), risk assessment and treatment process (6.1.2, 6.1.3), Statement of Applicability (6.1.3 d), objectives (6.2), evidence of competence (7.2), operational planning records (8.1), risk assessment and treatment results (8.2, 8.3), monitoring results (9.1), internal audit programme and results (9.2), management review results (9.3), and nonconformities and corrective actions (10.2).
Put this into practice on QULDEX
Frequently asked questions
How long does it take to work through an ISO 27001 checklist?
Most organisations of 50 to 250 people take 6 to 12 months from scoping to certificate, depending on how much of the ISMS already exists.
What is the most common gap before Stage 1?
A risk assessment and Statement of Applicability that don't match each other, or controls marked implemented with no records behind them.