Implementation
    Featured

    ISO 27001 Checklist: Complete Requirements for Certification

    A comprehensive ISO 27001 checklist covering every requirement you need to meet for successful ISMS implementation and certification.

    ISO27001KIT|March 1, 2026|14 min read
    ISO 27001 Checklist: Complete Requirements for Certification

    Why You Need an ISO 27001 Checklist

    Achieving ISO 27001 certification involves hundreds of requirements across documentation, controls, processes, and governance. A structured checklist ensures nothing falls through the cracks during implementation and audit preparation.

    Mandatory Documentation Checklist

    The following documents are explicitly required by ISO 27001:

    Clause 4 – Context of the Organization

    • Scope of the ISMS (Clause 4.3)
    • List of interested parties and their requirements (Clause 4.2)
    • Internal and external issues affecting the ISMS (Clause 4.1)

    Clause 5 – Leadership

    • Information Security Policy (Clause 5.2)
    • Roles, responsibilities, and authorities (Clause 5.3)
    • Evidence of management commitment (Clause 5.1)

    Clause 6 – Planning

    • Risk assessment methodology (Clause 6.1.2)
    • Risk assessment results (Clause 6.1.2)
    • Risk treatment plan (Clause 6.1.3)
    • Statement of Applicability (Clause 6.1.3 d)
    • Information security objectives (Clause 6.2)

    Clause 7 – Support

    • Evidence of competence (Clause 7.2)
    • Security awareness program records (Clause 7.3)
    • Document control procedure (Clause 7.5)

    Clause 8 – Operation

    • Operational planning and control records (Clause 8.1)
    • Risk assessment results (Clause 8.2)
    • Risk treatment results (Clause 8.3)

    Clause 9 – Performance Evaluation

    • Monitoring and measurement results (Clause 9.1)
    • Internal audit program and results (Clause 9.2)
    • Management review minutes (Clause 9.3)

    Clause 10 – Improvement

    • Nonconformity and corrective action records (Clause 10.1)
    • Continual improvement evidence (Clause 10.2)

    Annex A Controls Checklist

    ISO 27001:2022 contains 93 controls across four themes. Use our Annex A Selector Tool to determine which apply to your organization.

    Organizational Controls (A.5) – 37 Controls

    • Information security policies (A.5.1)
    • Information security roles (A.5.2)
    • Segregation of duties (A.5.3)
    • Management responsibilities (A.5.4)
    • Threat intelligence (A.5.7)
    • Information security in project management (A.5.8)
    • Inventory of information assets (A.5.9)
    • Acceptable use of assets (A.5.10)

    People Controls (A.6) – 8 Controls

    • Screening (A.6.1)
    • Terms and conditions of employment (A.6.2)
    • Information security awareness and training (A.6.3)
    • Disciplinary process (A.6.4)
    • Responsibilities after termination (A.6.5)
    • Remote working (A.6.7)

    Physical Controls (A.7) – 14 Controls

    • Physical security perimeters (A.7.1)
    • Physical entry controls (A.7.2)
    • Securing offices and facilities (A.7.3)
    • Clear desk and clear screen (A.7.7)
    • Equipment siting and protection (A.7.8)

    Technological Controls (A.8) – 34 Controls

    • User endpoint devices (A.8.1)
    • Privileged access rights (A.8.2)
    • Information access restriction (A.8.3)
    • Secure authentication (A.8.5)
    • Malware protection (A.8.7)
    • Management of technical vulnerabilities (A.8.8)
    • Information backup (A.8.13)
    • Logging (A.8.15)
    • Network security (A.8.20)
    • Secure coding (A.8.28)

    Pre-Audit Readiness Checklist

    Before your certification audit, verify these critical items:

    Stage 1 Audit Preparation

    • All mandatory documents are approved and distributed
    • Statement of Applicability is complete and justified
    • Risk assessment is documented and current
    • Internal audit has been conducted
    • Management review has been performed
    • Corrective actions from internal audit are closed

    Stage 2 Audit Preparation

    • All controls in the SoA are implemented
    • Staff are aware of security policies
    • Evidence of control effectiveness exists
    • Incident management process is tested
    • Business continuity plans are tested
    • Supplier security requirements are documented

    Using Our Free Tools

    Streamline your checklist completion with our tools:

    Common Gaps Found During Audits

    Based on industry data, the most common nonconformities are:

    1. Incomplete risk assessments – Not covering all assets or threats
    2. Missing evidence of awareness training – No records of employee training
    3. Outdated documents – Policies not reviewed or updated annually
    4. Weak access control – No formal access provisioning process
    5. No incident response testing – Plans exist but are never tested

    Conclusion

    Use this checklist as your roadmap to ISO 27001 certification. Start with our Gap Analysis to identify your current position, then work through each section systematically.

    Tags:
    ISO 27001
    Checklist
    Certification
    Requirements
    Compliance
    Annex A

    Found this article helpful?

    Share it with your colleagues.