Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

ISO 27001 Checklist: Every Requirement in One Place

August 11, 2026
hero-iso-27001-checklist-1.png

An ISO 27001 checklist has two parts. Part one covers management-system requirements, the clauses that make your ISMS actually run.

ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish it jointly.

Both parts matter equally to an auditor. Skip the management-system clauses and you have no ISMS to certify. Skip the Annex A controls and you have no proof the ISMS actually protects anything.

What’s In This ISO 27001 Checklist

Before the detail, here’s the shape of the whole thing. Use this table to see where you’re headed before working through either list.

PartWhat It CoversWho Typically Owns It
Part 1: Management-System RequirementsThe clauses proving your ISMS is a real, running system: scope, policy, risk process, audits, management reviewLeadership and whoever is running the ISO 27001 project

Part 1: Management-System Requirements Checklist

These are the clauses an auditor checks first. They prove your ISMS is a functioning system, not a folder of policies nobody follows.

RequirementISO ClauseWhat “Done” Looks Like
ISMS policy5A documented information security policy, backed by visible top-management leadership.
Internal audit conducted9An internal audit checking whether the ISMS meets its own requirements and ISO 27001’s.
Management review conducted9Top management formally reviewing ISMS performance and deciding what changes next.
Corrective-action process10A documented process for handling nonconformities and driving continual improvement.

Two items on that list trip up more businesses than the rest combined. Both deserve a closer look.

The Statement of Applicability Deserves Extra Attention

The SoA is where most ISO 27001 checklists get vague. It has to do real work, not sit as a formality.

A complete SoA does four things:

Auditors review the SoA during the Stage 1 readiness audit. It’s core evidence of how your risk decisions map to real controls. A thin SoA, one that excludes controls without justification or skips evidence references, is one of the fastest ways to stall at Stage 1.

Risk Assessment Isn’t a One-Time Task

Risk assessment is not a one-time exercise. A risk assessment methodology that only ran once, months before your audit, will not satisfy an auditor looking for an operating process.

The same logic applies to the risk treatment plan. It has to trace clearly to the SoA. Every control marked “included” should point back to a specific risk it treats. Auditors follow that thread from risk, to treatment decision, to control, to evidence. A gap anywhere in that chain is a finding.

Get these eight items solid before you touch Part 2. An auditor who can’t verify your management system won’t move on to testing individual controls, no matter how well those controls are implemented.

Part 2: Annex A Controls Checklist, By Theme

Part 1 covers whether your ISMS runs correctly. Part 2 covers whether specific safeguards are in place. For a plain-English overview of the standard itself, start with what ISO 27001 is.

The changes came in three types:

ThemeControlsWhat It Covers
Organizational37Governance, policies, supplier and third-party relationships, access control
People8HR security, screening, training, awareness
Physical14Facility and equipment protection
Technological34Encryption, access management, logging and monitoring, malware defense

Organizational controls (37) set the governance backbone. That includes documented policies, a clear access control policy, and security requirements in supplier contracts.

  • [ ] Information security policies are documented and approved by leadership
  • [ ] Access control policy defines who can reach what, and why
  • [ ] Supplier and third-party contracts include security requirements

People controls (8) cover the human side: who you hire, what they’re trained on, and what happens when they leave.

  • [ ] Screening happens before someone gets access to sensitive systems
  • [ ] Security awareness training runs on an ongoing basis, not just at onboarding
  • [ ] HR processes cover both hiring and termination

Physical controls (14) protect the equipment and space, not just the network.

  • [ ] Facility access is controlled and logged
  • [ ] Servers, laptops, and backup media are physically secured

Technological controls (34) are usually where the most implementation work happens. They’re the technical safeguards an IT team actually builds and maintains.

  • [ ] Encryption applies to sensitive data at rest and in transit
  • [ ] Access management enforces least privilege
  • [ ] Logging and monitoring capture security-relevant events
  • [ ] Malware defense is active across endpoints

What “Audit-Ready” Actually Looks Like Before Stage 1

Finishing this checklist is not the same as being ready for an audit. It tells you what to build. It does not tell you whether it’s working yet.

A few signs you’re actually ready:

Stage 2 typically runs about twice as long as Stage 1. Auditors test whether your documented controls actually work in practice, not whether they exist on paper.

A gap assessment maps where you stand at the start of this process. A readiness assessment confirms you’re actually done, right before Stage 1. If you want the full picture of what certification requires beyond this checklist, see the certification requirements breakdown.

Certification only counts if it comes from an accredited certification body, not a self-declared audit.

Certification is not one-and-done, either. Accredited bodies run annual surveillance audits in Years 1 and 2 of the three-year cycle. At the end of that cycle, a full recertification audit renews the certificate. Let it lapse, and the certificate is gone, not paused.

See Where You Stand

Reading a checklist is one thing. Knowing where you actually stand against it is another. The free 2-minute ISO 27001 Risk-Check walks through 8 plain-English questions covering everything above. It gives you a readiness level and the specific gaps to close first. No sign-up required to see your result.

Take the free 2-minute ISO 27001 Risk-Check

Frequently Asked Questions

Organizational holds 37, Technological holds 34, Physical holds 14, and People holds 8.

Your Statement of Applicability can mark a control as excluded, as long as you document why it does not apply. Auditors review those exclusions directly during the Stage 1 audit. A control marked included still needs real implementation evidence behind it.</p> </details>

A gap assessment benchmarks your current practices against this checklist and produces a prioritized list of what’s missing. It happens early, before remediation work starts. A readiness assessment happens later, right before Stage 1, to confirm those gaps actually got closed.

An outside, accredited certification body runs the actual certification audit, in two stages. Stage 1 reviews your documentation and readiness. Stage 2 tests whether the controls you documented are actually implemented, and usually takes about twice as long as Stage 1.

A certificate is valid for three years. A full recertification audit renews it at the end of the cycle.

No, it’s voluntary. No US or Illinois law requires it, unlike HIPAA or GLBA. In practice, many enterprise customers will not sign a contract with a vendor that cannot produce a valid certificate, which makes it a de facto requirement in some markets.

Get Help Closing the Gaps

LeadingIT does not issue ISO 27001 certification. That has to come from an independent, accredited certification body. What LeadingIT does is get your technical environment and evidence trail ready before that body shows up. That means:

  • Access management and encryption
  • Centralized logging and monitoring
  • Patch management
  • The operational records a Stage 2 auditor will ask for

If you want a partner for that technical groundwork, look at LeadingIT’s ISO 27001 compliance support. Ready to talk specifics? Book a call or contact us.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.