Standards playbooks

ISO 27001 playbook: from zero to certification-ready

The 12-week path an experienced ISO 27001 lead implementer would follow inside ISO-STANDARD.app — plus the artifacts your certification auditor will ask for.

12 min read · updated July 2026

Step-by-step

  1. 1

    Define scope and context

    Account → ISMS scope. Write a plain-language description of what's in and out. This is clause 4.3.

  2. 2

    Seed policies

    Adopt the 12 pre-drafted policies. Amend the ones that don't fit; approve the rest.

    Seed policies
  3. 3

    Build the risk register

    Seed sample risks, then adjust to your business. Every risk needs owner + treatment.

  4. 4

    Complete the SoA

    Walk Annex A control-by-control. Mark applicability and justify exclusions.

    Complete the SoA
  5. 5

    Run one internal audit

    Use the ISO 27001 template. Even a partial audit against A.5 and A.8 shows the ISMS is operating.

  6. 6

    Hold a management review

    Schedule and hold. This is clause 9.3 — auditors always check for it.

  7. 7

    Choose a certification body

    UKAS/ANAB-accredited only. Book Stage 1 once policies are approved and Stage 2 12 weeks later.

What corporate buyers look for
  • "Are you ISO 27001 certified or working toward it? If in-progress, what stage?"
  • "Can we see the SoA, ISMS scope and last internal audit result?"
  • "Who is your certification body and when is your next audit?"

What this workflow produces: 'Working toward ISO 27001 with a signed SoA, 12-month internal audit programme and evidence pack' unlocks most enterprise deals well before the certificate.

FAQ

How long does certification take?

For a first-time SME, 12–20 weeks from start to Stage 2, plus the certifier's own scheduling.

What if I fail Stage 1?

Stage 1 finds gaps — that's its job. Findings become CAPAs; you close them before Stage 2.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation