ISO 27001 playbook: from zero to certification-ready
The 12-week path an experienced ISO 27001 lead implementer would follow inside ISO-STANDARD.app — plus the artifacts your certification auditor will ask for.
Step-by-step
- 1
Define scope and context
Account → ISMS scope. Write a plain-language description of what's in and out. This is clause 4.3.
- 2
Seed policies
Adopt the 12 pre-drafted policies. Amend the ones that don't fit; approve the rest.

- 3
Build the risk register
Seed sample risks, then adjust to your business. Every risk needs owner + treatment.
- 4
Complete the SoA
Walk Annex A control-by-control. Mark applicability and justify exclusions.

- 5
Run one internal audit
Use the ISO 27001 template. Even a partial audit against A.5 and A.8 shows the ISMS is operating.
- 6
Hold a management review
Schedule and hold. This is clause 9.3 — auditors always check for it.
- 7
Choose a certification body
UKAS/ANAB-accredited only. Book Stage 1 once policies are approved and Stage 2 12 weeks later.
- "Are you ISO 27001 certified or working toward it? If in-progress, what stage?"
- "Can we see the SoA, ISMS scope and last internal audit result?"
- "Who is your certification body and when is your next audit?"
What this workflow produces: 'Working toward ISO 27001 with a signed SoA, 12-month internal audit programme and evidence pack' unlocks most enterprise deals well before the certificate.
FAQ
For a first-time SME, 12–20 weeks from start to Stage 2, plus the certifier's own scheduling.
Stage 1 finds gaps — that's its job. Findings become CAPAs; you close them before Stage 2.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
