ISO 27001 Certification: A Step-by-Step Checklist for UK Businesses

Updated 31 July 20269 min read

ISO 27001 certification is won or lost long before the auditor arrives. This checklist sets out the order UK organisations should work in, the evidence certification bodies expect, and where implementation programmes usually stall.

1. Define the scope of your ISMS

Your Information Security Management System (ISMS) scope names the services, locations, people and technology covered by the certificate. Too narrow and clients reject it; too broad and the programme becomes unmanageable.

Write the scope statement early, list the interested parties and their requirements, and map the information flows that cross the boundary — including suppliers and cloud platforms.

2. Run a risk assessment you can repeat

The standard requires a defined, repeatable risk methodology. Identify risks to confidentiality, integrity and availability, assign owners, score them consistently, and record treatment decisions.

  • Documented risk assessment methodology with defined impact and likelihood scales.
  • Risk register with owners, current controls and residual risk.
  • Risk treatment plan linking each accepted risk to a control or justification.
  • Statement of Applicability covering every Annex A control, applied or excluded with reasons.

3. Implement the Annex A controls that apply

The 2022 revision groups controls into organisational, people, physical and technological themes. You do not need every control — you need the ones your risk assessment justifies, implemented properly and evidenced.

  • Access control, joiners-movers-leavers and privileged access review.
  • Supplier and cloud service security, including contractual clauses.
  • Threat intelligence, logging, monitoring and vulnerability management.
  • Secure development, change control and secure configuration baselines.
  • Business continuity, backup testing and incident response with defined roles.
  • Security awareness training with attendance and effectiveness records.

4. Produce the mandatory documentation

Auditors check a defined set of records. Missing documents are the fastest route to a nonconformity, and they are also the easiest thing to fix in advance.

  • Information security policy and topic-specific policies.
  • Scope statement, risk methodology, risk assessment results and treatment plan.
  • Statement of Applicability.
  • Security objectives and evidence of measurement.
  • Competence, awareness and training records.
  • Internal audit programme, results and management review minutes.
  • Records of nonconformities and corrective actions.

5. Operate, audit and review before certification

Certification bodies need to see the ISMS running, not just designed. Most expect around three months of operational evidence — completed access reviews, logged incidents, at least one internal audit cycle and a documented management review.

6. Stage 1 and Stage 2 audits

Stage 1 is a readiness review of your documentation and scope. The auditor confirms the ISMS is designed correctly and flags gaps. Stage 2 tests whether it operates in practice through interviews, sampling and evidence review.

Findings are graded as observations, minor nonconformities or major nonconformities. Majors must be closed before the certificate is issued. After certification, surveillance audits run annually and the full cycle recertifies every three years.

Realistic timeline and cost drivers

A focused SME with a narrow scope and existing IT hygiene can certify in three to six months. Complex, multi-site or heavily regulated organisations typically take nine to twelve. Cost is driven by scope size, headcount, number of sites, the certification body's day rate and how much consultancy support you buy.

Frequently asked questions

Book an ISO 27001 gap analysis

Speak to a SafetyX consultant about scope, timelines and fixed-price options for your organisation.

Continue reading