Guide
ISO 27001 checklist for small and medium businesses
Eight steps from the scope to the certification audit, written for teams without a compliance department of their own.
What you'll learn
- Understand the structure of ISO 27001 and Annex A controls
- Perform a gap analysis to identify your starting point
- Build a realistic certification timeline for your organization
Introduction
ISO 27001 is the international standard for information security management systems (ISMS). For small and medium businesses, achieving certification can feel overwhelming, but it does not have to be. This checklist breaks the process into manageable steps so your team can work toward certification methodically, even without prior experience.
The standard is divided into two main parts: the management system requirements (Clauses 4-10) and Annex A, which contains 93 reference controls organized into four themes. You do not need to implement every single Annex A control, only those relevant to your organization's risk profile.
Step 1: Define the Scope
Before anything else, determine what your ISMS will cover. For most SMBs, this means the entire organization, but you can also scope it to a specific product, department, or location.
Key questions to answer:
- Which business processes handle sensitive data?
- Which IT systems support those processes?
- Are there regulatory requirements (GDPR, NIS2) that influence the scope?
Document your scope clearly. Auditors will evaluate your ISMS strictly within these boundaries.
Step 2: Conduct a Gap Analysis
A gap analysis compares your current security posture against ISO 27001 requirements. Walk through each clause and Annex A control and rate your current maturity:
- Not implemented. No control exists
- Partially implemented. Some measures are in place but not formalized
- Fully implemented. Control is documented, operational, and reviewed
This exercise produces a clear picture of how much work lies ahead. Expect a share of the controls to be lived informally already, for example access provisioning, backups and onboarding. Those cost you no implementation work, only documentation and a named owner.
Step 3: Perform a Risk Assessment
ISO 27001 is a risk-based standard. You must identify information security risks, evaluate their likelihood and impact, and decide how to treat them.
A practical approach for SMBs:
- List your information assets (databases, cloud services, employee devices)
- Identify threats to each asset (ransomware, insider threats, misconfiguration)
- Assess the likelihood and business impact of each threat
- Decide on treatment: mitigate, accept, transfer, or avoid
Document your risk assessment methodology and results. This becomes a living document you will revisit regularly.
Step 4: Write Your Policies
ISO 27001 requires a set of documented policies. At minimum, you need:
- Information Security Policy. Your top-level commitment to security
- Risk Assessment Methodology. How you identify and evaluate risks
- Statement of Applicability (SoA). Which Annex A controls apply and why
- Access Control Policy. Who can access what, and how access is granted
- Incident Response Policy. How you detect, report, and respond to incidents
- Business Continuity Plan. How you maintain operations during disruptions
Keep policies short. What counts in the audit is whether staff know the content and work by it, not how many pages the document has.
Step 5: Understand Annex A at a Glance
The 2022 revision of ISO 27001 organizes Annex A into four themes:
- Organizational controls (37 controls). Policies, roles, responsibilities, threat intelligence, asset management, access control, supplier relationships
- People controls (8 controls). Screening, terms of employment, awareness training, disciplinary process, responsibilities after termination
- Physical controls (14 controls). Physical security perimeters, entry controls, protecting against environmental threats, equipment maintenance
- Technological controls (34 controls). Endpoint security, access rights, cryptography, secure development, vulnerability management, logging, network security
For each control, document whether it applies (in your SoA), how you implement it, and what evidence demonstrates compliance.
Step 6: Implement and Train
With policies drafted and controls defined, put them into practice:
- Deploy technical controls (MFA, encryption, endpoint protection)
- Reach all employees with awareness training and record attendance
- Assign control owners who are responsible for maintaining each control
- Set up processes for incident reporting, access reviews, and change management
How long this part takes depends mainly on how many technical controls genuinely need building; documentation is rarely the bottleneck.
Step 7: Internal Audit and Management Review
Before your certification audit, you must conduct an internal audit and a management review:
- Internal audit. An independent review of your ISMS against ISO 27001 requirements. This can be done by a trained internal team member or an external auditor.
- Management review. A formal meeting where leadership reviews the ISMS performance, risk status, audit findings, and improvement opportunities.
Document both thoroughly. Auditors will ask for evidence of each.
Step 8: Certification Audit
The certification audit happens in two stages:
- Stage 1 (Document review). The auditor reviews your documentation to confirm your ISMS is designed correctly
- Stage 2 (Implementation review). The auditor verifies that your ISMS is operational and effective through interviews, evidence review, and observation
Address any non-conformities promptly. Minor non-conformities do not block certification, but major ones require resolution before a certificate is issued.
Timeline for SMBs
An example plan for a company with 50-200 employees, assuming no legacy backlog and no parallel projects:
- Weeks 1-2: Scope definition and gap analysis
- Weeks 3-4: Risk assessment
- Weeks 5-8: Policy writing and control implementation
- Weeks 9-10: Employee training and awareness
- Week 11: Internal audit
- Week 12: Management review
- Weeks 13-16: Certification audit (Stage 1 + Stage 2)
The plan assumes one person owns the work and management keeps to the review dates. If either falls away, everything behind it moves too. In KaitoSec the gap analysis, risk assessment and policy drafts sit in one workspace, so the evidence does not have to be collected from scattered files at the end.