ISO 27001 Certification: A Step-by-Step Checklist for UK Businesses
ISO 27001 certification is won or lost long before the auditor arrives. This checklist sets out the order UK organisations should work in, the evidence certification bodies expect, and where implementation programmes usually stall.
1. Define the scope of your ISMS
Your Information Security Management System (ISMS) scope names the services, locations, people and technology covered by the certificate. Too narrow and clients reject it; too broad and the programme becomes unmanageable.
Write the scope statement early, list the interested parties and their requirements, and map the information flows that cross the boundary — including suppliers and cloud platforms.
2. Run a risk assessment you can repeat
The standard requires a defined, repeatable risk methodology. Identify risks to confidentiality, integrity and availability, assign owners, score them consistently, and record treatment decisions.
- Documented risk assessment methodology with defined impact and likelihood scales.
- Risk register with owners, current controls and residual risk.
- Risk treatment plan linking each accepted risk to a control or justification.
- Statement of Applicability covering every Annex A control, applied or excluded with reasons.
3. Implement the Annex A controls that apply
The 2022 revision groups controls into organisational, people, physical and technological themes. You do not need every control — you need the ones your risk assessment justifies, implemented properly and evidenced.
- Access control, joiners-movers-leavers and privileged access review.
- Supplier and cloud service security, including contractual clauses.
- Threat intelligence, logging, monitoring and vulnerability management.
- Secure development, change control and secure configuration baselines.
- Business continuity, backup testing and incident response with defined roles.
- Security awareness training with attendance and effectiveness records.
4. Produce the mandatory documentation
Auditors check a defined set of records. Missing documents are the fastest route to a nonconformity, and they are also the easiest thing to fix in advance.
- Information security policy and topic-specific policies.
- Scope statement, risk methodology, risk assessment results and treatment plan.
- Statement of Applicability.
- Security objectives and evidence of measurement.
- Competence, awareness and training records.
- Internal audit programme, results and management review minutes.
- Records of nonconformities and corrective actions.
5. Operate, audit and review before certification
Certification bodies need to see the ISMS running, not just designed. Most expect around three months of operational evidence — completed access reviews, logged incidents, at least one internal audit cycle and a documented management review.
6. Stage 1 and Stage 2 audits
Stage 1 is a readiness review of your documentation and scope. The auditor confirms the ISMS is designed correctly and flags gaps. Stage 2 tests whether it operates in practice through interviews, sampling and evidence review.
Findings are graded as observations, minor nonconformities or major nonconformities. Majors must be closed before the certificate is issued. After certification, surveillance audits run annually and the full cycle recertifies every three years.
Realistic timeline and cost drivers
A focused SME with a narrow scope and existing IT hygiene can certify in three to six months. Complex, multi-site or heavily regulated organisations typically take nine to twelve. Cost is driven by scope size, headcount, number of sites, the certification body's day rate and how much consultancy support you buy.
Frequently asked questions
Book an ISO 27001 gap analysis
Speak to a SafetyX consultant about scope, timelines and fixed-price options for your organisation.
Continue reading
Cyber Essentials Certification in the UK: Cost, Requirements and Timeline
The five controls, 2026 pricing bands, Plus audit expectations and the mistakes that cause most first-time failures.
How Much Does Penetration Testing Cost in the UK?
Day rates, realistic scope sizing for web apps, networks and cloud, and the questions to ask before you sign a pen test quote.
