A practical guide for first-time organisations that breaks the path to ISO 27001 certification into simple steps.

GuideAbout 7 min readISO 27001

What is ISO 27001 and what does it give you?

ISO 27001 is the international standard that defines the requirements for an Information Security Management System (ISMS). Its aim is to turn information security from something left to individuals and tools into a risk-based management system that is continually improved. Certification is granted after audits by an independent certification body and is typically valid for three years, with annual surveillance audits in between.

Why it matters: Customers and tenders increasingly ask for ISO 27001. The real value, however, is managing risks knowingly and being able to prove it.

Roadmap: certification in six steps

Duration differs for every organisation, but the order is almost always the same:

Scope and contextWhich units, processes and assets are in scope?
Gap analysisThe difference between today and the standard
Risk and SoAAssess risks and select controls
ImplementationPolicies, processes and technical controls
Internal auditAudit yourself first
CertificationStage 1 and Stage 2 audits

Getting the scope right

Scope is the foundation of every later step. Too broad and the project drags; too narrow and the certificate loses value.

  • Which business units, locations and processes are in scope?
  • Which information assets and systems do these processes rely on?
  • What dependencies exist on suppliers and cloud services?
  • If an area is excluded, is the reason documented?

Tip: You can start with a narrow scope and widen it in later years.

Risk assessment and the Statement of Applicability (SoA)

The standard does not ask you to apply a ready-made checklist but to choose controls based on your risks.

  • Inventory your information assets and assign owners.
  • Identify threats and vulnerabilities and rate likelihood and impact.
  • Decide a treatment for each risk: reduce, transfer, accept or avoid.
  • Show in the SoA which of the 93 Annex A controls (ISO 27001:2022) are applied and which are excluded, with reasons.

Pre-audit checklist

  • Scope statement approved
  • Information security policy published and communicated
  • Risk assessment and treatment plan up to date
  • SoA ready and current
  • Internal audit done and findings closed
  • Management review held and recorded
  • Awareness training and incident records available
  • Corrective actions documented

Common mistakes

  • Piling up documents and skipping real implementation
  • Not securing management support and resources up front
  • Filling in the risk assessment as a formality
  • Running the internal audit late and superficially
  • Choosing an over-broad scope that stretches the project

Let’s start your ISO 27001 journey together

We will assess your current state and build a roadmap that fits.