Complies
ISO 27001 CHECKLISTS

ISO 27001 Checklist: 13 Steps From Scope to Certification

MARCH 2026 · 11 MIN READ · BY THE COMPLIES TEAM

An ISO 27001 checklist runs from defining your ISMS scope, through a risk assessment and the Statement of Applicability against Annex A's 93 controls, to an internal audit and the two-stage certification audit. Here are the 13 steps in order, with what each one produces and where teams commonly stall.

Before you start: what ISO 27001 actually certifies

ISO 27001:2022 certifies your information security management system (ISMS): the documented system of scope, leadership, risk assessment, controls, and continual improvement described in clauses 4-10 of the standard. Annex A supplies the reference control set: 93 controls organized into 4 themes (organizational, people, physical, and technological). Unlike SOC 2, which produces an auditor's attestation report, ISO 27001 produces a certificate issued by an accredited certification body, typically on a 3-year cycle with annual surveillance audits.

The 13-step ISO 27001 checklist

  1. Get leadership commitment and assign ownership. Clause 5 requires demonstrable top-management involvement. Name an ISMS owner with real authority; a security policy signed by the CEO is the first artifact.
  2. Define the ISMS scope. Decide which parts of the business, which systems, and which locations are in scope, and write the scope statement. A focused scope (your SaaS product and the teams that run it) is faster to certify than "the whole company."
  3. Identify interested parties and requirements. List customers, regulators, and contractual obligations that shape the ISMS (clause 4.2). This becomes the backbone of your obligation tracking.
  4. Build an asset and data inventory. You cannot assess risk to assets you have not listed: systems, data stores, laptops, SaaS vendors, and the data classifications that apply.
  5. Run the risk assessment. Define a repeatable methodology (likelihood x impact scales, acceptance criteria), then assess risks to confidentiality, integrity, and availability. Clause 6.1.2 requires the method to produce consistent, comparable results. Our guide to running a compliance risk assessment covers the matrix and cadence.
  6. Write the risk treatment plan. For each unacceptable risk, decide: mitigate with a control, transfer, avoid, or accept. Record who approved each acceptance.
  7. Produce the Statement of Applicability (SoA). Go through all 93 Annex A controls and declare, for each one, whether it applies and why, or why it is excluded. Auditors read the SoA line by line; vague justifications are the most common stage 1 finding.
  8. Implement the controls and write the policies. Access control, cryptography, secure development, supplier security, incident management, business continuity, and the rest of your applicable set. Each control needs an owner and, where recurring, a schedule. Drafting policies is where AI assistance saves real weeks, as long as a human reviews and approves every document.
  9. Run security awareness training. Clause 7.2-7.3 requires competence and awareness records for everyone in scope. Keep completion logs; they are sampled at audit.
  10. Operate and collect evidence. Certification bodies expect the ISMS to have actually run: access reviews performed, incidents logged, vendor reviews done, metrics reported. A quarter of real operation before stage 2 is a common working target.
  11. Run the internal audit. Clause 9.2 makes this mandatory before certification. It must cover the full ISMS and be performed by someone independent of the work audited; a competent contractor is fine for small teams. Write up nonconformities and fix them.
  12. Hold the management review. Clause 9.3 requires leadership to formally review ISMS performance, audit results, risks, and improvement opportunities, with minutes. Do not skip the minutes; auditors ask for them.
  13. Take the certification audit: stage 1, then stage 2. Stage 1 is a documentation review confirming you are ready (scope, SoA, risk assessment, mandatory records). Stage 2, typically 4-8 weeks later, tests whether the ISMS operates in practice, through interviews, sampling, and evidence walkthroughs. Pass stage 2 and the body issues your certificate; expect annual surveillance audits and full recertification in year 3.

What it costs and how long it takes

Certification body fees for a small company typically run $10,000-$30,000 across the initial 3-year cycle, with the stage 1 plus stage 2 audits making up most of year one. Readiness work, tooling, an external internal-auditor if you use one, and staff time are extra. From a reasonable security baseline, small teams commonly reach stage 2 in 4-8 months; starting from scratch, closer to 9-12.

Where teams stall

  • The SoA becomes a copy-paste exercise. Justifying 93 controls honestly takes focused effort; auditors notice boilerplate.
  • Recurring controls decay. The access review that ran once in month one and never again is the classic stage 2 nonconformity. Every recurring control needs a calendar entry and an owner, which is exactly what an obligation tracker with due dates enforces.
  • Internal audit is left to the last week. You need time to fix what it finds before stage 2.
  • Doing ISO 27001 in isolation when SOC 2 is also coming. The control overlap is large; completed SOC 2 work commonly pre-fills around 60% of ISO 27001. See SOC 2 vs ISO 27001 before you sequence them.

A necessary caveat: no checklist, consultant, or tool certifies you or guarantees the audit result. The certification body decides; your job is to walk in with an ISMS that has visibly been running.

Working the checklist without a spreadsheet graveyard

Every step above decomposes into tracked items: obligations from clause 4.2, risks with owners, 93 SoA decisions, policies awaiting approval, recurring controls on a calendar, and evidence with due dates. Complies packages that as self-serve ISO 27001 compliance software with cross-mapping to SOC 2, GDPR, HIPAA, and PCI DSS, AI-drafted policies that humans approve, and a live readiness score, with prices published from $79 per month and no sales call required. Get started with the scope statement; the rest of the checklist follows in order.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.