ISO 27001 Compliance Checklist
ISO 27001 is the international standard for an information security management system (ISMS). The compliance checklist runs: get leadership support, define the ISMS scope, run a risk assessment, choose risk treatments and Annex A controls, document policies, train staff, operate the ISMS, run an internal audit and management review, then pass a two-stage certification audit. It proves to customers you manage information security to a recognized standard.

- ISO 27001 certifies that you run an information security management system (ISMS) to an international standard.
- The core of the work is a risk assessment, then treating risks with controls from Annex A.
- You must document policies, train staff, and operate the ISMS, not just write it down.
- An internal audit and management review come before the external certification audit (stages 1 and 2).
- Certification proves security to customers and partners and often wins or unlocks contracts.
What is ISO 27001?
ISO 27001 is the leading international standard for information security. Rather than prescribing a fixed list of technical controls, it defines how to build and run an information security management system (ISMS): a systematic, risk-based framework of policies, processes, and controls for protecting your information. Achieving certification means an accredited auditor has verified that you manage information security to this recognized standard. Businesses pursue it to protect their data, to meet contractual and regulatory requirements, and, increasingly, to win business, because more customers now require proof that their suppliers handle data securely before they will sign.
The investment makes sense against the cost of getting security wrong: the average data breach reached $4.88 million in 2024 and takes about 258 days to identify and contain, and reported cybercrime losses topped $12.5 billion in a single year. ISO 27001 reduces that risk while turning your security into a credential you can show. This guide is a step-by-step checklist of what certification involves. It pairs with our IT compliance services and cybersecurity services overviews.
Step 1: Secure leadership support and scope the ISMS
ISO 27001 is an organizational commitment, not just an IT project, so it starts with leadership. Management must back the effort, assign responsibility, and provide resources, because the standard explicitly requires demonstrated leadership involvement. With that in place, define the scope of your ISMS: which parts of the business, locations, systems, and information it covers. Scope is a critical early decision, because everything that follows, the risk assessment, the controls, the audit, applies to what is in scope. A clear, sensible scope keeps the project achievable rather than boiling the ocean.
Step 2: Run a risk assessment
Risk assessment is the heart of ISO 27001. You assess the information assets in scope, identifying the threats and vulnerabilities to each, and the likelihood and impact of those risks materializing, producing a prioritized picture of where your real exposure lies. This is what makes ISO 27001 risk-based rather than checkbox compliance: the controls you implement are chosen to address your actual risks, not applied blindly. A documented, repeatable risk-assessment methodology is itself a requirement, and the assessment drives everything that follows.

Step 3: Treat risks and select Annex A controls
For each significant risk, decide how to treat it: reduce it with a control, accept it, avoid it, or transfer it. Where you reduce risk, you select controls, drawing on Annex A of the standard, a catalog of information-security controls spanning organizational, people, physical, and technological measures (things like access control, encryption, supplier security, and incident management). You then produce a Statement of Applicability (SoA), a key ISO 27001 document that lists which Annex A controls you apply and why, and justifies any you exclude. The SoA is one of the first things auditors examine, because it shows your security choices trace directly to your risks.
Step 4: Document policies and implement controls
ISO 27001 requires a set of documented policies and procedures, an information security policy, access control, incident response, business continuity, and more, that define how your ISMS operates. But documentation alone is not enough: you must actually implement the controls and run the processes in practice. This is where many organizations underestimate the effort, because closing the gap between written policy and daily reality, configuring systems, enforcing access, training people, takes real work. The standard is checking that your security is lived, not just filed.
Step 5: Train staff and build awareness
People are central to ISO 27001, and to security generally, since the human element features in 68 percent of breaches. The standard requires that staff are aware of the information security policy, understand their responsibilities, and are trained appropriately. Practically, that means a security-awareness program, clear communication of policies, and evidence that training happens. Auditors will ask employees about security, so awareness must be genuine, not a one-time slideshow. Building a security-conscious culture is both an ISO 27001 requirement and one of the most effective risk reducers there is.

Step 6: Operate, internally audit, and review
Before any external auditor arrives, you must run the ISMS for a period and check it yourself. ISO 27001 requires an internal audit, an objective review of whether your ISMS meets the standard and works as intended, and a management review, where leadership formally evaluates the ISMS and its performance. Together these catch gaps and nonconformities while you can still fix them, and they demonstrate the continual improvement the standard demands. Treat the internal audit as a genuine dress rehearsal, not a formality; finding problems here is far better than finding them during certification.
Step 7: Pass the certification audit
Certification is performed by an accredited external body in two stages. Stage 1 is a documentation review, where the auditor checks that your ISMS documentation, policies, risk assessment, and SoA, meets the standard and that you are ready. Stage 2 is the main audit, where the auditor examines whether your ISMS is actually implemented and effective in practice, gathering evidence and interviewing staff. If you pass, you receive certification, typically valid for three years with annual surveillance audits to confirm you maintain it. Certification is not the finish line: the ISMS is meant to keep running and improving.

Getting to ISO 27001 with help
ISO 27001 is achievable but demanding, requiring information-security expertise, project management, and sustained effort, often several months to a year for a first certification. That expertise is scarce amid a global shortfall of about 4.8 million cybersecurity professionals, which is why many businesses bring in a managed IT or security provider or consultant experienced in ISO 27001 to guide the project, run the risk assessment, implement controls, and prepare for the audit. It is part of why the managed services market is projected to grow from about $330 billion in 2024 to about $879 billion over the next decade, and the scope keeps widening as more systems move to the cloud, in a market where public cloud spending is forecast to top $723 billion in 2025. A partner who has done it before dramatically reduces the time, cost, and risk of failing the audit.
If ISO 27001 is on your roadmap, an experienced partner can take you from scoping to certification. To find one, browse vetted, merit-ranked firms by city in the Best IT MSP directory, where ranking is earned on rating and verified data.
Frequently asked questions
What is ISO 27001?
ISO 27001 is the leading international standard for information security. It defines how to build and run an information security management system (ISMS): a systematic, risk-based framework of policies, processes, and controls for protecting information. Certification means an accredited auditor has verified you manage information security to this recognized standard.
What are the steps to ISO 27001 compliance?
Secure leadership support and define the ISMS scope, run a risk assessment, treat risks and select Annex A controls (documented in a Statement of Applicability), document policies and implement the controls, train staff, operate the ISMS and run an internal audit and management review, then pass the two-stage external certification audit.
What is the Statement of Applicability in ISO 27001?
The Statement of Applicability (SoA) is a key ISO 27001 document that lists which Annex A controls you apply and why, and justifies any you exclude. It shows that your security choices trace directly to the risks identified in your risk assessment, and it is one of the first things auditors examine during certification.
How long does ISO 27001 certification take?
For a first certification, it often takes several months to a year, depending on the size of the organization, the scope of the ISMS, and the maturity of your existing security. The bulk of the time goes into the risk assessment, implementing controls, operating the ISMS for a period, and the internal audit before the external certification audit.
What are the two stages of the ISO 27001 audit?
Stage 1 is a documentation review, where the accredited auditor checks that your ISMS documentation, including policies, risk assessment, and Statement of Applicability, meets the standard and that you are ready. Stage 2 is the main audit, where the auditor examines whether the ISMS is actually implemented and effective in practice, gathering evidence and interviewing staff.
Why get ISO 27001 certified?
Certification protects your data by enforcing a systematic security framework, helps meet contractual and regulatory requirements, and increasingly wins business, since many customers require proof that suppliers handle data securely before signing. Against an average breach cost of $4.88 million, it reduces risk while turning your security into a credential you can show prospects.
Related reading
Get expert help on the road to ISO 27001
Best IT MSP is the independent directory of vetted managed IT and security providers across North America. Compare merit-ranked firms in your city experienced in ISO 27001 and information security. No pay-to-play.
Best IT MSP is an independent directory that connects you with vetted managed IT providers. Browse the directory city by city:
- Managed IT Services in Chicago
- Managed IT Services in Houston
- Managed IT Services in Dallas
- Managed IT Services in Phoenix
- Managed IT Services in Reno
- Managed IT Services in Richmond
- Managed IT Services in Rochester, MN
- Managed IT Services in Sacramento
- Managed IT Services in Salt Lake City
- Managed IT Services in San Antonio