ISO 27001 Checklist
Achieving ISO 27001 certification requires a structured approach to building and maintaining an information security management system (ISMS). Without a clear plan, organisations can overlook critical requirements or waste time on low-priority tasks. This ISO 27001 checklist provides a step-by-step guide to help you meet every requirement, from initial planning through to your external certification audit. If you are new to the standard, our guide on what is ISO 27001 explains the fundamentals, and our ISO 27001 training courses can support your team throughout the process.
This article covers what you need to understand, how to prepare, and 14 steps to stay compliant.
Contents
Understanding ISO 27001 Requirements To Stay Compliant
ISO 27001 sets out the requirements for establishing, implementing, maintaining, and continually improving an ISMS. The standard is structured around core clauses (4 to 10) covering context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A provides a reference set of 93 information security controls grouped into four themes: organisational, people, physical, and technological. Using an ISO 27001 requirements checklist helps ensure you address each clause systematically and do not miss any mandatory elements. For a full breakdown, see our guide to ISO 27001 requirements.
Preparing for ISO 27001 Implementation
Before working through your ISO 27001 checklist, take time to prepare your organisation. Key preparation steps include:
- Secure management commitment – Top management must demonstrate leadership and allocate the resources needed for ISMS implementation
- Define scope – Determine which parts of your organisation, processes, and information assets the ISMS will cover
- Understand your context – Identify internal and external issues, and the needs and expectations of interested parties relevant to information security
- Obtain the standard – Acquire a copy of BS EN ISO/IEC 27001:2023+A1:2024 or the version with tracked changes to reference throughout implementation
14 Steps to Stay Compliant in ISO 27001
The following ISO 27001 compliance checklist outlines the key steps to implement and maintain your ISMS effectively.
- Build your ISO 27001 Project Plan – Create a detailed project plan with timelines, milestones, and responsibilities. Define your target certification date and work backwards to set realistic deadlines for each stage.
- Define your Information Security Management System (ISMS) – Document the scope, boundaries, and applicability of your ISMS. Clearly state which locations, departments, processes, and technologies are included.
- Form an ISMS Team and Assign Responsibilities – Appoint an ISMS lead or information security manager and assign roles for risk assessment, policy development, training, and audit activities.
- Identify and Catalogue Information Assets – Create an asset inventory covering all information assets, including data, hardware, software, people, and facilities. Assign an owner to each asset.
- Carry out a Comprehensive Risk Assessment – Identify threats and vulnerabilities to your information assets. Assess the likelihood and impact of each risk to determine which require treatment.
- Create and Maintain a Risk Register – Record all identified risks, their current status, risk owners, and the controls in place. Keep this register updated as your risk landscape changes.
- Prepare and Document a Risk Treatment Plan – For each unacceptable risk, decide whether to mitigate, transfer, avoid, or accept it. Document the controls you will apply and the expected timeline for implementation.
- Complete the Statement of Applicability (SoA) – The SoA lists all Annex A controls and states whether each is applicable or not, with justification. This is a mandatory document for certification.
- Set Information Security Objectives – Establish measurable information security objectives that are consistent with your information security policy, and plan how you will achieve them, who is responsible, and how you will monitor progress (Clause 6.2).
- Implement ISMS Policies – Develop and implement the required policies, including your information security policy, acceptable use policy, access control policy, and any others relevant to your scope.
- Establish Ongoing Employee Training – Ensure all employees understand their information security responsibilities through regular awareness training and role-specific education.
- Perform Management Reviews of the ISMS – Top management must review the ISMS at planned intervals to assess its continuing suitability, adequacy, and effectiveness. Record decisions and actions from each review.
- Maintain Required Records – Keep documented evidence of your ISMS activities, including risk assessments, training records, audit results, and management review minutes, as required by the standard.
- Conduct an ISMS Internal Audit – Perform internal audits to verify your ISMS meets the standard’s requirements before your certification audit. Use findings to drive corrective actions.
- Complete an External Certification Audit for ISO 27001 Compliance – Engage an accredited certification body to conduct your Stage 1 (documentation review) and Stage 2 (implementation audit) assessments. Address any nonconformities to achieve certification.
Enrol in an ISO 27001 Course
Working through an ISO 27001 checklist is more effective when your team has the right training. SEQM Training offers CQI and IRCA certified courses to support every stage of your ISMS journey, including the ISO 27001 Lead Auditor Course, the ISO 27001 Internal Auditor Course, and the ISO 27001 Foundation Course.
Frequently Asked Questions
Choose a certification body accredited by a recognised national accreditation body such as UKAS in the UK. Check their experience with your industry sector, ask about their audit process and timelines, and confirm they are listed on the accreditation body’s register.
A comprehensive ISO 27001 checklist should cover scope definition, risk assessment, the Statement of Applicability, ISMS policy implementation, employee training, internal audits, management reviews, and preparation for external certification audits.


