How many documents are mandatory for ISO 27001?

Last verified 2026-08-19 · UK focus

Short answer

ISO/IEC 27001:2022 explicitly requires about 18 pieces of documented information: roughly 11 standing documents (scope, information security policy, risk assessment and treatment processes, Statement of Applicability, objectives) and 7 record types (competence evidence, monitoring results, internal audit programme and results, management review outputs, nonconformity and corrective action records). Annex A controls add further documents only where you apply them.

Key facts

  • The Statement of Applicability is the only Annex A artefact named as mandatory in the main clauses.
  • There is no required page count or template — 'documented information' can be a wiki page or a system record.
  • Auditors sample records far more than they read policies.
  • Applied Annex A controls typically add 5-15 further documents in practice.

Documented information required by ISO/IEC 27001:2022

Documented information required by ISO/IEC 27001:2022
#Documented itemClauseType
1Scope of the ISMS4.3Document
2Information security policy5.2Document
3Information security risk assessment process6.1.2Document
4Information security risk treatment process6.1.3Document
5Statement of Applicability6.1.3 d)Document
6Information security objectives and plans6.2Document
7Evidence of competence7.2Record
8Documented information determined as necessary7.5.1 b)Document
9Evidence of operational planning and control8.1Record
10Results of information security risk assessments8.2Record
11Results of information security risk treatment8.3Record
12Evidence of monitoring and measurement results9.1Record
13Internal audit programme9.2.2Document
14Internal audit results9.2.2Record
15Results of management reviews9.3.3Record
16Nonconformities and actions taken10.2Record
17Results of corrective actions10.2Record
18Continual improvement evidence10.1Record

Caveats

  • Counts published elsewhere vary between 16 and 22 because sources group clause 7.5 and 10.2 items differently.
  • The 2022 revision removed several prescriptive documents present in the 2013 edition's Annex A.

Sources

  1. ISO/IEC 27001:2022, clauses 4-10 (documented information requirements). International Organization for Standardization, 2022-10-25.

Check your own position

Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.

Related