ISO27K

ISO 27001 checklist, clause by clause

A checklist made of clause headings tells you nothing about whether you are ready. This one follows the order the work actually happens in, and every item says what done looks like and what the audit team will ask you to produce.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

ISO/IEC 27001:2022 has two halves that behave differently. Clauses 4 to 10 carry 25 mandatory requirements, none excludable. Annex A lists 93 reference controls, and which of those apply is an output of your risk treatment rather than an input to it. Ticking all 93 before doing a risk assessment produces a Statement of Applicability nobody can defend.

The order below is the dependency order. Scope constrains the risk assessment, the assessment produces the treatment plan, the plan decides Annex A, and the rest is evidence that the system is running. The requirements are set out clause by clause on the clauses page, and the route to a certificate here is on ISO 27001 certification in Canada.

25 Mandatory requirements in clauses 4 to 10, none excludable

93 Annex A reference controls, applicability decided by risk

2 Audit stages before a certificate is issued

Each item below names an artifact, the condition that makes it done, and the question asked about it in the audit room. An item is not done because a document exists. It is done when the document is approved, dated, owned by somebody who can explain it, and matched by what happens in the business.

Clause 4: context and scope

A scope written too wide drags systems, offices and teams into an audit that did not need to be there. One written too narrow gets challenged at stage 1, or satisfies nobody in your pipeline because the certificate does not cover the product the customer buys.

0 of 5 done ·

Clause 5: leadership

Clause 5 asks for three things and auditors test them by talking to people rather than reading documents. The evidence is whether the answers match.

0 of 4 done ·

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Clause 6: planning, risk and the Statement of Applicability

This is the largest block of work and it determines everything downstream. Do it in the stated order: a risk assessment run before the methodology is agreed produces results nobody can reproduce, and reproducibility is an explicit requirement.

0 of 6 done ·

The ordering trap

If your Statement of Applicability was produced by opening Annex A and marking almost everything applicable, the audit team can see it: the justifications read as generic and no control traces back to a risk. Letting the register drive control selection saves an argument at every audit that follows.

Clause 7: support

Clause 7 separates a system that exists on paper from one people use. Four of its five requirements are about human beings.

0 of 5 done ·

Clause 8: operation

Clause 8 is short in the standard and long in practice. Run the processes you designed and keep the evidence that you ran them.

0 of 4 done ·

Clause 9: performance evaluation

Three requirements, and the last two are the ones a certification body checks have genuinely happened before it will issue anything.

0 of 4 done ·

Clause 10: improvement

Two requirements, and an empty nonconformity log is itself a signal.

0 of 3 done ·

Annex A: 93 controls in four themes

Annex A of the 2022 edition holds 93 controls in four themes. The 2013 edition had 114 in 14 domains and nothing was removed in the rewrite. Controls were merged and regrouped by who owns them.

Annex A themes in ISO/IEC 27001:2022 and what each covers
ThemeControlsWhat it covers
Organizational37Policies, roles, supplier and cloud relationships, threat intelligence, incident management, continuity, legal requirements
People8Screening, terms of employment, awareness, disciplinary process, duties after termination, remote working, reporting events
Physical14Perimeters, entry, secure areas, equipment siting, cabling, maintenance, secure disposal, clear desk and screen
Technological34Endpoints, privileged access, cryptography, secure development, logging, monitoring, backup, data masking, web filtering
Total reference controls93Applicability decided by risk treatment

The checklist item here is not "implement 93 controls". It is that every control has a recorded decision, every applicable control traces to a risk or a requirement and carries a status and an owner, and every exclusion has a justification that would survive being read aloud. Excluding a control because you have no on-premises data centre is defensible. Excluding one because it looked difficult is a finding waiting to happen, and the physical controls are where that shows up in remote-first companies that still keep an office.

The Annex A controls page sets out what each theme expects, and the Annex A control selector gives a first pass at applicability. Implementation guidance lives in ISO 27002, which is not itself certifiable.

Before the certification audit

Certification runs in two stages with the same audit team. Stage 1 reads, stage 2 tests, and knowing which questions belong to which stage is the difference between a clean pass and findings that delay the certificate.

What each audit stage asks for
Stage 1, documentation reviewStage 2, effectiveness audit
Scope statement, and whether it matches what you sellInterviews to see whether the documented process is the one staff follow
Information security policy and supporting policiesSamples of records across the period: access reviews, change approvals, incident tickets
Risk methodology, risk assessment and treatment planEvidence that treatment actions were implemented on the dates claimed
Statement of Applicability, including exclusionsControl testing against the applicable controls in the Statement of Applicability
Internal audit plan and reportsWhether findings raised internally were actually closed
Management review minutesWhether decisions recorded in the review led to anything
Readiness for stage 2, and a dateNonconformities, graded major or minor, with a window to respond

The gap between stages runs from a few weeks to a few months, and a stage 1 finding that the system has not operated long enough is the usual cause of the longer gap. Evidence samples need three months of operation at the short end. The stage 1 and stage 2 page covers what happens between them, the stage 1 readiness check flags what is missing before you book a date, and a gap assessment does the same job against a longer runway.

The items that fail most often

  1. Interfaces and dependencies missing from clause 4, which makes the scope unverifiable.
  2. A Statement of Applicability where applicable controls trace to no risk.
  3. Objectives that are not measurable, so clause 9 has nothing to measure against.
  4. Internal audit performed by the person who built the system, failing the independence requirement.
  5. Management review minutes missing two or three of the required inputs.
  6. Corrective actions closed without an effectiveness review.
  7. Awareness records covering employees but not contractors.

Each is cheaper to fix before stage 1 than after stage 2. The free tools on this site ask for no email address.

Get quotes for ISO 27001 readiness

Tell us your scope, target date and position on this checklist.

Get matched

Common questions

Do we have to implement all 93 Annex A controls?

No. You have to make and record a decision about all 93. Which ones apply is determined by your risk treatment and by legal, regulatory and contractual requirements, and the Statement of Applicability is where those decisions are written down. Most organizations end up with a large majority applicable, but each exclusion has to rest on a reason that relates to your situation.

Can we do the internal audit ourselves?

Yes, as long as the auditor is independent of the work being audited. In a small company that means somebody from a different function, or an outside party. The person who wrote the policies and built the controls cannot audit them, and that is the most common way this requirement fails. Keep a record of the auditor's training or experience.

How long does the checklist take to work through?

For a company under 100 people starting from documented but informal practice, six to nine months to stage 2 is realistic, and the binding constraint is elapsed time rather than effort. Clause 9 needs an internal audit and a management review to have happened, and clause 8 needs operating history. Neither compresses by adding people.

This directory is published by TrazTech Inc.