Why this checklist
ISO 27001:2022 reorganised Annex A into 93 controls across four themes — Organisational, People, Physical and Technological. Most teams who certified under the 2013 edition underestimate how much evidence they need to refresh.
This checklist is the same shortlist our Lead Auditors run on day one of every readiness engagement.
How to use it
- Print the checklist and walk it room-by-room with the control owner.
- Score each item: Implemented, Partial, or Gap.
- For every Gap, log the owner, target date and evidence reference.
- Repeat the walkthrough 30 days before the Stage 1 audit.
Section A — Context and leadership
- Documented scope statement (4.3) signed by the CEO
- Interested-parties register reviewed in the last 12 months
- ISMS policy approved and communicated to all staff
- Information security objectives with measurable KPIs
- Top-management review minutes for the last two cycles
Section B — Risk and Statement of Applicability
- Risk assessment methodology documented and approved
- Asset-based or scenario-based risk register, with owners
- Risk treatment plan referencing every accepted residual risk
- Statement of Applicability covering all 93 Annex A controls
- Justifications recorded for every excluded control
Section C — People controls (A.6)
- Background-verification policy and evidence per joiner
- Acceptable-use rules signed during onboarding
- Security-awareness training completion >= 95%
- Disciplinary process linked to the security policy
- Remote-working policy reviewed in the last 12 months
Section D — Physical controls (A.7)
- Secure-areas zoning map and access matrix
- Visitor log reviewed monthly
- Equipment maintenance and disposal records
- Clear-desk and clear-screen spot checks
Section E — Technological controls (A.8)
- Endpoint hardening baseline aligned to CIS
- Privileged-access management with break-glass procedure
- Secure development lifecycle artefacts (threat models, code-review evidence)
- Logging and monitoring coverage map
- Backup restore test in the last 90 days
- Vulnerability management SLA tracked monthly
- Incident management runbook with last tabletop exercise
Section F — Performance and improvement
- Internal audit programme covering all clauses in the cycle
- Corrective-action register with owners and due dates
- Management review inputs and outputs documented
- Continual improvement log linked to risk-treatment outcomes
Next step
For a walkthrough against your live evidence, book a 30-minute working session with the practice lead.