Skip to content
Clear Infosec

ISO 27001 Readiness and Evidence Checklist

ISO 27001 readiness requires a defined ISMS scope, a documented risk assessment and treatment plan, a Statement of Applicability justifying each Annex A control, and evidence that the selected controls operate effectively before a certification audit.

By Clear Infosec Last reviewed: 2026-08-19 Aligned to ISO 27001, ISO 27002

How ISO 27001 certification is evaluated

ISO/IEC 27001 certifies an Information Security Management System (ISMS), not a product. An external auditor assesses conformance in two stages: a Stage 1 documentation review and a Stage 2 audit that tests whether the ISMS operates in practice. Readiness means having both the required documents and the evidence that controls run.

The 2022 revision reorganized Annex A into 93 controls across four themes: organizational, people, physical, and technological. ISO/IEC 27002 provides implementation guidance for those controls.

Define the ISMS scope and context

Scope sets the boundary of the ISMS: which parts of the organization, which locations, systems, and services are covered. A scope statement that is clear and defensible is the foundation for everything that follows.

  • Document the ISMS scope statement, including inclusions, exclusions, and interfaces.
  • Identify interested parties and their information security requirements.
  • Record information security objectives approved by leadership.
  • Evidence leadership commitment, roles, and responsibilities for the ISMS.

Risk assessment and treatment

Risk management is the engine of ISO 27001. The organization must have a defined, repeatable risk assessment methodology, a documented set of identified risks with owners, and a risk treatment plan showing how each risk is addressed.

  • Document the risk assessment methodology and risk acceptance criteria.
  • Maintain a risk register with identified risks, owners, and assessed levels.
  • Produce a risk treatment plan linking each treated risk to selected controls.
  • Retain records of management review and approval of residual risk.

Statement of Applicability and Annex A evidence

The Statement of Applicability (SoA) is a mandatory document that lists every Annex A control, states whether it is applicable, justifies inclusion or exclusion, and references its implementation status. Auditors use the SoA as the map for their control testing.

For each applicable control, readiness means holding the evidence that it operates. Evidence is concrete: policies, records, logs, tickets, configurations, and training records, not just a claim that the control exists.

  • Complete the SoA covering all Annex A controls with applicability and justification.
  • Access control: identity lifecycle records, access reviews, and privileged-access controls.
  • Operations: change records, backup evidence, logging, and vulnerability management output.
  • People: security awareness training records and acceptable-use acknowledgements.

Mandatory clauses and internal assurance

Beyond Annex A, clauses 4 to 10 impose mandatory management-system requirements. Readiness includes evidence of an internal audit programme, a management review, and a corrective-action process for nonconformities.

Running an internal audit and a management review before the certification audit surfaces gaps while they are still cheap to fix, and it is itself required evidence.

  • Documented information security policy approved by leadership.
  • Internal audit programme, reports, and evidence findings were actioned.
  • Management review minutes covering performance, risks, and improvement.
  • Corrective action and continual improvement records.

Related

FAQ

What is the Statement of Applicability?

The Statement of Applicability (SoA) is a mandatory ISO 27001 document listing every Annex A control, stating whether it applies, justifying inclusion or exclusion, and noting implementation status. Auditors use it as the reference map for testing controls.

How many controls are in Annex A of ISO 27001:2022?

The 2022 revision has 93 Annex A controls grouped into four themes: organizational, people, physical, and technological. ISO/IEC 27002:2022 provides implementation guidance for these controls.

What is the difference between a Stage 1 and Stage 2 audit?

Stage 1 is a documentation and readiness review that checks the ISMS is designed and documented. Stage 2 is the deeper audit that tests whether the ISMS and its controls actually operate in practice, leading to a certification decision.

Want this applied to your environment? Request a scoping call.