Home / Resources / ISO 27001 Readiness Checklist
This guide walks you through every stage of ISO 27001 certification readiness — from ISMS implementation and risk treatment to Statement of Applicability sign-off, internal audit, and Stage 1 and Stage 2 audit preparation. Use the checklist sections to identify gaps and drive your programme to closure before the external auditor arrives.
ISO 27001 readiness means your information security management system (ISMS) is fully implemented, documented, and evidenced — not just designed on paper. Certification readiness requires that your policies, risk treatment, ISO 27001 controls, and internal audit cycle are all operating before you invite an external auditor to assess them.
Many organisations confuse ISMS implementation with certification readiness. Implementation is building the system; readiness is demonstrating it works. Auditors at both the Stage 1 and Stage 2 audit look for evidence of operation, not intention. A policy that exists but is not followed will generate a nonconformity regardless of how well it is written.
This checklist covers the eight areas that external auditors consistently examine. Work through each section, rate your current status, assign owners to open items, and consolidate your evidence before your first audit date.
Rate each item: complete, partial, or not started. Partial and missing items become your remediation backlog.
These are the gaps most frequently raised as nonconformities during ISO 27001 audit preparation.
Treating the Statement of Applicability as a paperwork exercise
The SoA must reflect the live state of your ISO 27001 controls. Auditors cross-reference it against actual implementations and will raise a nonconformity if controls marked as implemented cannot be evidenced.
No completed internal audit or management review before Stage 1
Both are mandatory requirements. Arriving at the Stage 1 audit without completed records means the auditor cannot confirm your ISMS is operational, and certification will be delayed.
Controls documented in policy but not operating in practice
The most common Stage 2 audit finding. A policy that says "access is reviewed quarterly" must be evidenced by dated access review records. Intention without evidence is a nonconformity.
Risk treatment plan not formally accepted by management
Completing a risk assessment is not enough. ISO 27001 requires that management formally accepts the residual risk and approves the treatment plan. Without a signed or minuted acceptance, clause 6.1 is incomplete.
Internal audit nonconformities left open at Stage 2
Open corrective actions signal that your ISMS improvement cycle is not functioning. Auditors check whether findings have been closed and verified, not just logged.
ISMS scope too broad for available evidence
Organisations sometimes define a wide scope to appear comprehensive, then struggle to produce consistent evidence across all areas. A tightly defined, well-evidenced scope certifies more reliably than a broad scope with evidence gaps.
ISO 27001 certification uses a two-stage audit process. Understanding what each stage tests lets you focus your preparation in the right order.
Typically conducted remotely, the Stage 1 audit confirms your ISMS documentation is complete and your organisation is ready to proceed to the effectiveness audit. Stage 1 findings must be resolved before Stage 2 is scheduled.
Auditors focus on
The Stage 2 audit tests whether ISO 27001 controls are working as intended through staff interviews, process walkthroughs, and evidence sampling. This is where certification is granted or major nonconformities are raised.
Auditors focus on
RiskNow combines platform automation, built-in ISO 27001 content, and optional expert support to reduce implementation time and move teams from planning to audit readiness faster.
Built-in ISO 27001 requirement library
Start from a structured library of ISO 27001 requirements and expected evidence points so your team does not need to build a control framework from scratch.
Predefined risks and controls
Use a predefined risk and control set mapped to common implementation scenarios, then tailor it to your scope instead of starting with a blank register.
Automation for evidence and remediation
Automate evidence collection workflows, track control status, and route remediation actions to owners with deadlines so implementation momentum is maintained.
Optional consultancy when needed
If your team needs support, RiskNow consultancy can help with scope definition, risk treatment decisions, and practical preparation for Stage 1 and Stage 2 audits.
The result is a faster path to ISO 27001 readiness: less manual setup, clearer ownership, and a practical implementation programme your team can execute with confidence.
An information security management system is the set of policies, procedures, and controls that systematically manages information security risks across an organisation. ISO 27001 is the international standard that defines requirements for establishing, implementing, maintaining, and continually improving an ISMS. Certification demonstrates to customers and regulators that your information security management system meets that standard.
Most ISMS implementation programmes take 8 to 20 weeks from kick-off to Stage 1 audit readiness, depending on scope complexity, existing documentation maturity, and dedicated resource availability. Allow a further four to eight weeks between Stage 1 and Stage 2 for evidence consolidation and remediation of Stage 1 findings.
The Statement of Applicability is the document that maps all 93 Annex A controls to your organisation, recording which are applicable and implemented, and why any are excluded. It is one of the first documents requested at the Stage 1 audit because it shows the auditor the shape of your ISO 27001 controls landscape. It must be version-controlled, current, and signed by management.
No, but you must evaluate all 93 ISO 27001 controls and document a justification for any you exclude. Controls are selected based on the risks in your assessment, your legal and contractual obligations, and your operational context. Unjustified exclusions are a common Stage 1 audit finding.
A failed Stage 1 audit means the auditor raised findings that must be resolved before Stage 2 can proceed. Findings can be minor observations, opportunities for improvement, or major nonconformities. Minor issues are closed during the Stage 1 to Stage 2 gap; major nonconformities may require a full re-audit of the affected area and will delay your certification timeline.
Talk to an experienced consultant about your objectives. We'll help you understand what it takes and how RiskNow can accelerate your path to compliance.