BGYS.Online · Guide

ISO 27001:2022 Certification Checklist

A practical, 13-step readiness checklist for ISO 27001 certification under the ISO 27001:2022 standard — from defining scope to passing the Stage 2 audit. Use it as a gap assessment before you engage a certification body.

Quick readiness assessment

If you cannot answer "yes, with evidence" to all of the following, you are not yet ready for a Stage 2 audit:

  • Our ISMS scope statement is approved and current
  • Every in-scope asset has an owner and a CIA classification
  • Every unacceptable risk has an approved treatment and residual risk sign-off
  • Our Statement of Applicability justifies all 93 Annex A controls
  • An independent internal audit covering the whole ISMS is complete
  • All nonconformities have verified corrective actions
  • A management review has been held and minuted in the last 12 months

The 13-step ISO 27001 certification checklist

  1. 1.Define scope and context (Clause 4)

    Document the boundaries of your ISMS: locations, business units, systems and third parties in scope.

    • Write an ISMS scope statement with clear inclusions and exclusions
    • Map internal and external issues affecting information security
    • List interested parties and their requirements (customers, regulators, staff)
  2. 2.Secure leadership commitment (Clause 5)

    ISO 27001:2022 requires demonstrable top-management involvement and assigned responsibilities.

    • Approve an information security policy signed by top management
    • Appoint an ISMS owner and define an RACI for security roles
    • Allocate budget, tooling and people to the programme
  3. 3.Build the asset and process inventory

    You cannot assess risk on assets you have not identified. Classify by confidentiality, integrity and availability.

    • Inventory information assets, systems, suppliers and data flows
    • Assign an owner to every asset and process
    • Apply a CIA classification scheme consistently
  4. 4.Run the risk assessment (Clause 6.1.2)

    Use a repeatable methodology — commonly a 5x5 likelihood × impact matrix — and record results in a risk register.

    • Document and approve the risk assessment methodology
    • Identify threats, vulnerabilities and existing controls per asset
    • Score inherent risk and define your risk acceptance criteria
  5. 5.Produce the risk treatment plan

    Every unacceptable risk needs a decision: mitigate, transfer, avoid or accept — with an owner and due date.

    • Select a treatment option and controls for each risk
    • Record residual risk after treatment
    • Obtain risk owner sign-off on residual risk acceptance
  6. 6.Complete the Statement of Applicability (SoA)

    The SoA covers all 93 Annex A controls of ISO 27001:2022 across the four themes: organisational, people, physical and technological.

    • Mark each Annex A control applicable or not applicable
    • Justify every inclusion and exclusion in writing
    • Record current implementation status and evidence links
  7. 7.Write and approve mandatory documentation

    Auditors expect controlled documents with version history, approvers and review dates.

    • Policies, procedures, instructions, plans and forms under document control
    • Access control, incident response, backup, supplier and BCM procedures
    • Formal approval workflow and staff acknowledgement records
  8. 8.Implement controls and collect evidence

    Certification is evidence-driven: screenshots, tickets, logs, meeting minutes and signed records.

    • Operate controls for long enough to generate records (typically 2–3 months)
    • Store evidence centrally, linked to the control it supports
    • Track control implementation status and gaps
  9. 9.Deliver awareness and training (Clause 7)

    Competence and awareness must be planned, delivered and evidenced for all in-scope personnel.

    • Run security awareness training with attendance records
    • Execute phishing simulations and track results
    • Keep competence records for security-critical roles
  10. 10.Perform an internal audit (Clause 9.2)

    An independent internal audit of the full ISMS is mandatory before the certification audit.

    • Approve an internal audit programme covering all clauses and applicable controls
    • Record findings as nonconformities, observations or opportunities
    • Ensure auditor independence from the audited area
  11. 11.Close findings with corrective actions (Clause 10)

    Each nonconformity needs root cause analysis, a corrective action and effectiveness verification.

    • Log CAPA records with owners and target dates
    • Perform root cause analysis, not just symptom fixes
    • Verify effectiveness before closing the finding
  12. 12.Hold the management review (Clause 9.3)

    Top management reviews ISMS performance against defined inputs and records decisions and actions.

    • Cover audit results, risk status, objectives, incidents and improvement opportunities
    • Record decisions, resource needs and action owners in minutes
    • Schedule reviews at planned intervals, at least annually
  13. 13.Pass Stage 1 and Stage 2 certification audits

    An accredited certification body reviews your documentation (Stage 1) then tests the ISMS in operation (Stage 2).

    • Stage 1: scope, SoA, policies, risk assessment and internal audit readiness
    • Stage 2: evidence that controls operate effectively in practice
    • Plan surveillance audits in year 1 and 2, recertification in year 3

Frequently asked questions

How long does ISO 27001 certification take?

Most organisations need 3 to 9 months, depending on scope, existing maturity and how quickly evidence can be generated. Controls usually must operate for at least two to three months before the Stage 2 audit.

What changed in ISO 27001:2022?

ISO 27001:2022 restructured Annex A from 114 controls in 14 domains into 93 controls across four themes — organisational, people, physical and technological — and introduced 11 new controls such as threat intelligence, cloud services security and data leakage prevention.

Which documents are mandatory for ISO 27001?

Scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, objectives, competence records, operational planning evidence, monitoring results, internal audit programme and results, management review minutes, and nonconformity/corrective action records.

Run this checklist in one workspace

BGYS.Online tracks scope, risks, Annex A controls, the Statement of Applicability, policies, internal audits, findings, CAPA and evidence — so every checklist item above has a live status instead of a spreadsheet.

Sign in to your ISMS workspace