Free resources
/
ISO 27001 Checklist

The Ultimate ISO 27001 Checklist

A ten-step checklist for building an ISO 27001:2022 information security management system, from scope and risk assessment to the Statement of Applicability and your external audit.

ISO 27001 is the international standard for managing information security across the whole business, not just the cloud stack. That's all 93 controls in the 2022 revision, the people and physical ones included, not the technical third on its own. This checklist lays out the ten steps of building an ISMS that certifies and holds, in plain English, without assuming you arrived with the standard memorised.

What's inside:

  • Team and plan: get leadership backing, set up your ISMS team, and build a certification plan with owners and timelines
  • Scope: define your ISMS boundaries, and the legal and regulatory obligations that apply
  • Asset register: build a digital asset register with risk assessments linked from the start
  • Risk assessment: choose a methodology, identify and evaluate risks, and create your risk treatment plan
  • Controls and evidence: build your Statement of Applicability and start collecting control evidence
  • Policies: create or migrate the mandatory policies and procedures, with a reading and approval regime
  • Audits: run your internal audit, then the Stage 1 and Stage 2 external audit
  • Maintain and mature: keep the ISMS current through years two and three

By the end, you'll have a clear map of the whole-business work ISO 27001 actually involves, what you can evidence today, and what to put in front of an auditor at each stage.

Questions? We've
Got You Covered

Planning an audit? These will help.
For anything else, just ask.

What is ISO 27001?

ISO/IEC 27001 is the international standard for information security management. It defines how an organisation builds and runs an information security management system, or ISMS, covering 93 controls across organisational, people, physical and technological measures in the 2022 revision. Certification is independently audited.

Who is this ISO 27001 checklist for?

Information security and compliance leads building or recertifying an ISMS, and the founders or IT managers who own it in smaller teams. It maps the work without assuming deep ISO expertise.

How many controls are in ISO 27001:2022?

The 2022 revision has 93 controls in Annex A, grouped into four themes: 37 organisational, 8 people, 14 physical and 34 technological. A common mistake is to treat ISO 27001 as a technical exercise; the technological controls are only about a third of it.

How long does ISO 27001 certification take?

It depends on the size of your scope and how much is already in place. Certification runs through a Stage 1 and Stage 2 external audit once your ISMS is built and evidenced. This checklist helps you plan the steps in order, so nothing surfaces late.

Is the checklist really free?

Yes. Enter a business email and it unlocks straight away. No sales call, just the checklist.