
An ISO 27001 checklist has two halves. The first is the management system in clauses 4 to 10, which you must meet in full: the standard says excluding any of those requirements is not acceptable when an organization claims conformity. The second is Annex A, a reference list of 93 controls in four themes, which you select through your risk assessment instead of adopting them all by default.
We help companies build and run these controls through our vCISO services; we are not a certification body. This checklist follows ISO/IEC 27001:2022, the current edition, together with ISO's free Amendment 1:2024, climate action changes. For budgeting, read our ISO 27001 cost guide, and for how Annex A relates to the separate guidance standard, see ISO 27001 vs 27002.
What are the ISO 27001 requirements, clause by clause?
The requirements are the clauses. Clauses 1 to 3 cover scope, references and terms; clauses 4 to 10 hold what the certification auditor tests. Use this table as the first half of your checklist. The middle column is our plain-language reading of what to have in place, not the standard's text, so check each line against your copy of the standard.
| Clause | What to have in place | Evidence to keep |
|---|---|---|
| 4.1 The organization and its context | The internal and external issues that affect what your ISMS must achieve | A dated context analysis |
| 4.2 Interested parties | Who has a stake, such as customers, regulators, staff and suppliers, what they require, and which of those requirements the ISMS will address | An interested parties register |
| 4.3 Scope of the ISMS | The boundary: sites, teams, systems, services and the interfaces with outside parties | An approved scope statement |
| 4.4 The ISMS | The processes that make up the ISMS and how they connect | A process map or short ISMS manual |
| 5.1 Leadership and commitment | Top management sets direction, provides resources and follows results | Minutes and resource decisions |
| 5.2 Policy | An information security policy, approved and communicated | The signed policy and staff acknowledgments |
| 5.3 Roles, responsibilities and authorities | Named owners for the ISMS and for security tasks | Role descriptions or a responsibility matrix |
| 6.1 Risks and opportunities, risk assessment and risk treatment | A repeatable risk method, a risk register with owners, treatment decisions and the controls chosen | Method, register, treatment plan and Statement of Applicability |
| 6.2 Objectives | Measurable security objectives with plans, owners and dates | An objectives tracker |
| 7.1 to 7.4 Resources, competence, awareness, communication | Budget and people, the skills each role needs, security awareness, and who communicates what | Training and competence records, a communication plan |
| 7.5 Documented information | Control of documents and records: versions, approvals, storage and access | A document register |
| 8.1 Operational planning and control | The ISMS processes run as planned | Operating records |
| 8.2 and 8.3 Risk assessment and treatment | Risk assessments repeated on a schedule and after major change, and treatment plans carried out | Dated register updates and completed actions |
| 9.1 Monitoring, measurement, analysis and evaluation | What you measure, how and when, and who reviews the results | Metrics reports |
| 9.2 Internal audit | An internal audit programme that covers the ISMS over time | Audit plan, reports and findings |
| 9.3 Management review | Top management reviews the ISMS and records its decisions | Review minutes with actions |
| 10.1 and 10.2 Improvement, nonconformity and corrective action | Problems fixed, causes found and corrective actions tracked | A corrective action log |
How many controls are in ISO 27001 Annex A?
Annex A lists 93 controls in four themes. They match the controls that ISO/IEC 27002:2022 explains one by one, and ISO aligned the 2022 edition of 27001 with it. This is the full controls list, by theme:
| Theme | Controls |
|---|---|
| Organizational controls (37) | 5.1 Policies for information security; 5.2 Information security roles and responsibilities; 5.3 Segregation of duties; 5.4 Management responsibilities; 5.5 Contact with authorities; 5.6 Contact with special interest groups; 5.7 Threat intelligence; 5.8 Information security in project management; 5.9 Inventory of information and other associated assets; 5.10 Acceptable use of information and other associated assets; 5.11 Return of assets; 5.12 Classification of information; 5.13 Labelling of information; 5.14 Information transfer; 5.15 Access control; 5.16 Identity management; 5.17 Authentication information; 5.18 Access rights; 5.19 Information security in supplier relationships; 5.20 Addressing information security within supplier agreements; 5.21 Managing information security in the ICT supply chain; 5.22 Monitoring, review and change management of supplier services; 5.23 Information security for use of cloud services; 5.24 Information security incident management planning and preparation; 5.25 Assessment and decision on information security events; 5.26 Response to information security incidents; 5.27 Learning from information security incidents; 5.28 Collection of evidence; 5.29 Information security during disruption; 5.30 ICT readiness for business continuity; 5.31 Legal, statutory, regulatory and contractual requirements; 5.32 Intellectual property rights; 5.33 Protection of records; 5.34 Privacy and protection of PII; 5.35 Independent review of information security; 5.36 Compliance with policies, rules and standards for information security; 5.37 Documented operating procedures |
| People controls (8) | 6.1 Screening; 6.2 Terms and conditions of employment; 6.3 Information security awareness, education and training; 6.4 Disciplinary process; 6.5 Responsibilities after termination or change of employment; 6.6 Confidentiality or non-disclosure agreements; 6.7 Remote working; 6.8 Information security event reporting |
| Physical controls (14) | 7.1 Physical security perimeters; 7.2 Physical entry; 7.3 Securing offices, rooms and facilities; 7.4 Physical security monitoring; 7.5 Protecting against physical and environmental threats; 7.6 Working in secure areas; 7.7 Clear desk and clear screen; 7.8 Equipment siting and protection; 7.9 Security of assets off-premises; 7.10 Storage media; 7.11 Supporting utilities; 7.12 Cabling security; 7.13 Equipment maintenance; 7.14 Secure disposal or re-use of equipment |
| Technological controls (34) | 8.1 User endpoint devices; 8.2 Privileged access rights; 8.3 Information access restriction; 8.4 Access to source code; 8.5 Secure authentication; 8.6 Capacity management; 8.7 Protection against malware; 8.8 Management of technical vulnerabilities; 8.9 Configuration management; 8.10 Information deletion; 8.11 Data masking; 8.12 Data leakage prevention; 8.13 Information backup; 8.14 Redundancy of information processing facilities; 8.15 Logging; 8.16 Monitoring activities; 8.17 Clock synchronization; 8.18 Use of privileged utility programs; 8.19 Installation of software on operational systems; 8.20 Networks security; 8.21 Security of network services; 8.22 Segregation of networks; 8.23 Web filtering; 8.24 Use of cryptography; 8.25 Secure development life cycle; 8.26 Application security requirements; 8.27 Secure system architecture and engineering principles; 8.28 Secure coding; 8.29 Security testing in development and acceptance; 8.30 Outsourced development; 8.31 Separation of development, test and production environments; 8.32 Change management; 8.33 Test information; 8.34 Protection of information systems during audit testing |
How do you implement ISO 27001 controls, step by step?
Start from risk, not from the list. ISO/IEC 27002 says determining controls depends on the decisions an organization makes after a risk assessment, and that controls can come from any source. A workable order for a small company:
- Set the scope and list the information and assets inside it, which is also control 5.9.
- Assess risk with a method you can repeat: what could go wrong, how likely it is, how bad it would be, and who owns each risk.
- Decide treatment for each risk and choose the controls that carry it out.
- Compare your choices with Annex A so nothing necessary is missed, and record which controls apply in your Statement of Applicability.
- Implement with owners. Every control gets an owner, a procedure and a record that proves it ran.
- Measure, audit and review under clauses 9.1 to 9.3, then correct what fails under clause 10.2.
For many small companies, much of Annex A maps onto systems they already run. Controls 5.15 to 5.18 and 8.5 become named accounts, multifactor authentication and joiner, mover and leaver steps with periodic access reviews. Controls 8.1 and 8.7 become managed devices with endpoint protection; 8.8 becomes patching and vulnerability scans; 8.13 becomes backups with restore tests; 8.15 and 8.16 become central logs that someone reviews. Controls 5.24 to 5.28 become a written incident response process, and 5.19 to 5.23 a supplier and cloud service review each year.
What evidence will the certification auditor ask for?
- The scope statement, the information security policy and the roles.
- The risk method, the risk register, the treatment plan and the Statement of Applicability.
- Security objectives and how you measure them.
- Training and awareness records.
- Records that controls operated: access reviews, change tickets, backup and restore tests, patch reports, incident logs and supplier reviews.
- Internal audit reports, management review minutes and the corrective action log.
Date every record and keep final versions. An undated screenshot or a draft policy proves little to an auditor sampling across months.
What should an ISO 27001 internal audit checklist include?
Clause 9.2 requires internal audits, and clause 9.2.2 an internal audit programme. ISO 19011, updated in 2026, gives guidance on managing audit programmes and conducting management system audits. A checklist for each internal audit:
- Define the audit's scope and criteria: which clauses, which Annex A controls, which sites.
- Choose an auditor who did not build or run the controls being audited.
- Over the audit cycle, cover every clause from 4 to 10 and every control in the Statement of Applicability.
- Sample records from across the period, not just the latest month.
- Interview the people who run each process and watch at least one control operate.
- Record each finding against the requirement it breaches, with the evidence.
- Report results to the managers responsible and feed nonconformities into corrective action.
Are you ready for the certification audit?
- The scope is approved and stable.
- The risk assessment and treatment are complete, and the Statement of Applicability is approved.
- Policies are approved and acknowledged by staff.
- Controls have run long enough to produce records.
- At least one full internal audit is complete.
- A management review has been held and minuted.
- Every open nonconformity has an owner and a date.
- You have compared several certification bodies and checked their accreditation.
Who maintains the ISO 27001 checklist?
The ISMS owner keeps it current and reports to top management through the management review. Update it whenever the scope, a system or a supplier changes, after every internal audit and after any security incident. Treat it as a working document, not a one-time project.
How does NetSys help with ISO 27001?
We align client environments to frameworks including ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Through our vCISO service, a senior security lead sets risk priorities, writes the policies, handles vendor and insurer questions and reports to leadership, while your IT team, another provider or NetSys engineers carry out the fixes. For managed clients, much of the control evidence comes from identity, devices, email and backups we already run. Certification comes from an independent certification body; mapping your program to ISO 27001 is not a certification, and NetSys claims none.
Want a second opinion on your gap list? Book a call and we will go through your scope and risk register with you.
Frequently asked questions
What are the ISO 27001 requirements?
They are clauses 4 to 10 of ISO/IEC 27001:2022: context and scope, leadership, planning including risk assessment and treatment, support, operation, performance evaluation including internal audit and management review, and improvement. An organization claiming conformity cannot exclude any of them. The Annex A controls are selected through risk treatment.
How do you implement ISO 27001 controls?
Assess risk first, decide how to treat each risk, then choose controls from Annex A or elsewhere to carry out that treatment. Give each control an owner, a written procedure and a record it produces, and use ISO/IEC 27002 for detailed guidance on each control. Check them through internal audits and the management review.
Do we have to implement all 93 Annex A controls?
Not automatically. Annex A is a reference list that you compare against your risk treatment, and your Statement of Applicability records which controls apply. A company that writes no software, for example, has little use for the secure coding controls. Exclusions need a defensible reason, because the auditor will ask.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 states the requirements you are certified against, including the Annex A reference list of controls. ISO/IEC 27002 is guidance: 152 pages explaining each of the same 93 controls, with attributes to help you sort them. You are certified to 27001, not 27002.
Is there an ISO 27001 checklist in Excel?
Copy the two tables above into a spreadsheet: one row per clause and one row per Annex A control, with columns for owner, status, evidence location and next review date. That sheet becomes the working draft of your Statement of Applicability and your internal audit plan.
Can NetSys certify us to ISO 27001?
No. ISO does not certify anyone either; certification comes from an external certification body, ideally an accredited one. We help build and run the controls and the evidence, and an independent certification body performs the audit.
Sources and further reading
- ISO: ISO/IEC 27001:2022: edition, amendment and certification FAQ, checked October 2026.
- IEC webstore: ISO/IEC 27001:2022: the scope text and the clause structure from the official preview, checked October 2026.
- ISO: ISO/IEC 27002:2022: the control guidance standard, with its control list from the official preview, checked October 2026.
- ISO 19011:2026, Guidelines for auditing management systems, checked October 2026.
- ISO: Certification: ISO does not certify, and how to choose a certification body, checked October 2026.
Discuss vciso services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

