ISO 27001 checklist or cheat sheet — certification at a glance
The certification audit examines whether your ISMS meets clauses 4 to 10 of ISO/IEC 27001 and whether the Annex A controls have been selected with a justification. This cheat sheet sums up what matters — clause by clause, with the audit questions, the documents that must be in place and the way the audit proceeds.
ISO/IEC 27001 is the internationally recognised standard for information security management systems (ISMS). A certificate to this standard shows that an independent body has examined how an organisation plans, implements, monitors and improves its information security — and it is the evidence that customers, tenders and partners ask for most often.
Before the auditor arrives, the organisation should know for itself where it stands. That is what this ISO 27001 cheat sheet is for: it puts the essentials of the standard on one page. The article gives the audit questions for every clause, names the documents that must be in place, and describes how to evaluate the result and how the certification audit proceeds.
ISO 27001 checklist or cheat sheet?
A checklist is ticked off item by item. A cheat sheet puts together what one has to have at hand on a subject. This one does so for certification to ISO 27001: it turns the requirements of the standard into audit questions that can be answered with “fulfilled”, “partially fulfilled” or “not fulfilled” — and backed by evidence. Going through them yields a gap analysis: the list of what is still missing between where you stand today and readiness for certification.
There are two things it does not replace. One is the standard itself: the audit is conducted against the wording of ISO/IEC 27001:2022, not against a summary. The other is the internal audit that the standard requires in clause 9.2: the audit questions can be its basis, but an internal audit needs a programme, impartial auditors and a report.
What the certification audit examines
The standard has two parts. Clauses 4 to 10 describe the management system. They apply in full: an organisation that claims conformity with the standard cannot exclude any of these requirements. Annex A names 93 controls in four themes. Which of them are applied follows from the risk treatment and is recorded in the Statement of Applicability (SoA).
| Clause | What it is about | Key evidence |
|---|---|---|
| 4 Context of the organization | Environment, interested parties, scope | Documented scope of the ISMS |
| 5 Leadership | Commitment of top management, policy, roles | Information security policy |
| 6 Planning | Risk assessment, risk treatment, objectives, changes | Risk processes, SoA, risk treatment plan, information security objectives |
| 7 Support | Resources, competence, awareness, communication, documents | Evidence of competence, controlled documents |
| 8 Operation | Control of processes, carrying out risk assessment and risk treatment | Results of the risk assessments and of the risk treatment |
| 9 Performance evaluation | Monitoring and measurement, internal audit, management review | Measurement results, audit programme and audit reports, results of the management review |
| 10 Improvement | Continual improvement, nonconformities, corrective actions | Records of nonconformities and corrective actions |
ISO 27001 cheat sheet: the seven clauses
The questions follow ISO/IEC 27001:2022, including the amendment Amd 1:2024. Every question comes with a piece of evidence — a document, an entry, a record. An answer without evidence does not count in the audit.
Clause 4: Context of the organization
The ISMS begins with the question of what it applies to. The organisation determines the external and internal issues that affect its information security — laws, contracts, market and technology on the one hand, structure, resources and culture on the other — and derives the scope from them.
- Have the external and internal issues been determined that are relevant to the organisation’s purpose and to its ISMS?
- Has it been determined whether climate change is a relevant issue? Since the amendment Amd 1:2024, the standard has expressly required this.
- Are the interested parties known — customers, authorities, owners, employees, suppliers — together with their requirements, including the legal, regulatory and contractual ones?
- Has it been determined which of these requirements will be addressed through the ISMS?
- Is the scope documented — with sites, organisational units and processes, and with the interfaces and dependencies to what other organisations perform?
- Have the processes of the ISMS and their interactions been established?
Clause 5: Leadership
An ISMS that top management does not stand behind will not pass an audit: auditors talk to senior management and ask about objectives, resources and results. The tasks in the ISMS can be delegated; the responsibility for it cannot.
- Have the information security policy and the information security objectives been established, and are they compatible with the strategic direction of the organisation?
- Are the requirements of the ISMS integrated into the business processes, and are the necessary resources available?
- Does the policy include the commitment to satisfy the applicable requirements and to continually improve the ISMS?
- Is the policy documented, communicated within the organisation and — as appropriate — available to interested parties?
- Have responsibilities and authorities for the information security roles been assigned and communicated?
- Has it been settled who reports to top management on the performance of the ISMS?
Clause 6: Planning
The heart of the standard. The risk assessment determines which controls are necessary — not the other way round. Its procedure must be described in such a way that repeated assessments produce consistent, valid and comparable results.
- Risk assessment. Is there a documented procedure with risk acceptance criteria? Have the risks to confidentiality, integrity and availability been identified, analysed and prioritised — and does every risk have a risk owner?
- Risk treatment. Has a treatment option been chosen for every risk? Have the necessary controls been determined and compared with Annex A, so that none is overlooked? Have the risk owners approved the risk treatment plan and accepted the residual risks?
- Statement of Applicability (SoA). Does it name the necessary controls, the justification for their inclusion, their implementation status and the justification for every exclusion of an Annex A control?
- Information security objectives. Are the objectives measurable, where practicable, and are they monitored? Has it been planned what will be done, by whom, with what resources and by when — and how the result will be evaluated?
- Planning of changes. Are changes to the ISMS carried out in a planned manner? This requirement was added with the 2022 edition.
Clause 7: Support
What the ISMS needs in order to work: people, knowledge, communication and controlled documents.
- Resources. Have the resources needed to establish, operate and improve the ISMS been determined and provided?
- Competence. Has it been determined what competence is needed by the people whose work affects information security — and is there evidence of it, for example through education, training or experience?
- Awareness. Do employees know the policy, their own contribution to the ISMS and the consequences of not conforming with requirements?
- Communication. Has it been determined what is communicated internally and externally, when, with whom and how?
- Documented information. Are documents identified, reviewed and approved? Are they available where they are needed, and protected against loss of confidentiality, improper use and loss of integrity?
Clause 8: Operation
Clause 6 plans, clause 8 carries out. Here the auditor wants to see that the procedures are not only described but applied.
- Are the processes by which the requirements are met planned, implemented and controlled — with criteria, and with evidence that they run as planned?
- Are planned changes controlled, and are the consequences of unintended changes reviewed?
- Are externally provided processes, products and services that are relevant to the ISMS controlled?
- Are risk assessments repeated at planned intervals — and whenever significant changes occur? Are the results documented?
- Has the risk treatment plan been implemented and the result documented?
Clause 9: Performance evaluation
Three instruments show whether the ISMS is working: monitoring and measurement, the internal audit and the management review. The certification body’s external audit is not one of them — it presupposes that the organisation has examined itself first.
- Has it been determined what is monitored and measured, by which methods, when and by whom — and who evaluates the results?
- Is there an audit programme that sets out frequency, methods, responsibilities and reporting?
- Have the internal auditors been selected so that objectivity and impartiality are ensured — in other words, does nobody audit their own work?
- Are the audit results reported to the relevant management?
- Does top management review the ISMS at planned intervals — and does the review cover what the standard specifies: the status of actions from previous reviews, changes in the environment and in the requirements of interested parties, nonconformities, measurement and audit results, the results of the risk assessment and the status of the risk treatment plan?
- Are the results of the management review documented — with the decisions on improvements and on changes to the ISMS?
Clause 10: Improvement
Deviations occur in every ISMS. What is examined is not whether there were any, but how the organisation deals with them: whether it looks for the cause instead of merely fixing the individual case.
- Is a nonconformity reacted to — is it corrected, and are its consequences dealt with?
- Is the cause determined, and is it checked whether similar nonconformities exist or could occur?
- Are corrective actions implemented and reviewed for their effectiveness?
- Are nonconformities, actions and results documented?
- Are the suitability, adequacy and effectiveness of the ISMS continually improved?
Annex A: 93 controls and the Statement of Applicability
Annex A is not a list to be worked through item by item. It is a catalogue of possible controls against which the organisation checks its risk treatment. The 2022 edition arranges 93 controls in four themes; ISO/IEC 27002:2022 gives implementation guidance for each control.
| Theme | Number | Examples |
|---|---|---|
| A.5 Organizational controls | 37 | Policies, supplier relationships, handling of security incidents, use of cloud services |
| A.6 People controls | 8 | Screening, training and awareness, remote working |
| A.7 Physical controls | 14 | Physical entry control, protection of equipment, secure disposal |
| A.8 Technological controls | 34 | Privileged access rights, vulnerability management, backup, logging, secure development |
The audit questions on Annex A:
- Has each of the 93 controls been assessed — as applicable or as excluded, with a justification in both cases?
- Can every applicable control be traced back to a risk, a legal requirement or a contractual requirement?
- Does every applicable control have an implementation status, an owner and evidence?
- Have controls also been considered that are not in Annex A but are necessary for your risks? The catalogue is not exhaustive.
- Does the SoA match the risk treatment plan — and what has actually been implemented?
Mandatory documents: what must be in place
At these points the standard expressly requires documented information. If one of these documents is missing, that is a nonconformity in the audit:
- Scope of the ISMS (4.3)
- Information security policy (5.2)
- Risk assessment process (6.1.2)
- Risk treatment process with risk treatment plan (6.1.3)
- Statement of Applicability (6.1.3)
- Information security objectives (6.2)
- Evidence of competence (7.2)
- Evidence that the processes have been carried out as planned (8.1)
- Results of the risk assessments (8.2)
- Results of the risk treatment (8.3)
- Results of monitoring and measurement (9.1)
- Audit programme and audit results (9.2)
- Results of the management review (9.3)
- Nonconformities, corrective actions and their results (10.2)
Added to this is whatever the organisation itself determines as necessary for the effectiveness of its ISMS (7.5.1), and whatever the applied Annex A controls require — for example an inventory of information and assets, rules for acceptable use or procedures for handling security incidents.
How to evaluate the answers
Ticks alone say little. The answers only become meaningful once every one of them has been rated, backed by evidence and turned into a measure:
- Rate. Every question receives a status: fulfilled, partially fulfilled or not fulfilled. “Not applicable” exists only for the Annex A controls — and only with a justification.
- Back it up. Every answer of “fulfilled” comes with its evidence. If you cannot find the evidence, downgrade the answer.
- Prioritise. Gaps in clauses 4 to 10 and missing mandatory documents come first: they put the certificate at risk directly. For the controls, what decides is the level of the risk they treat.
- Plan. Every gap becomes a measure with an owner and a deadline.
- Repeat. After implementation, the assessment is carried out again. The internal audit and the management review come at the end.
The first time round, the result is hard to interpret: whether a requirement is partially fulfilled or not fulfilled depends on what an auditor accepts as evidence. This is where an outside view helps — from someone who knows audits.
From cheat sheet to certificate: how the audit proceeds
The certificate is issued by a certification body. As a rule, it is recognised only if that body is accredited — in Germany, by the Deutsche Akkreditierungsstelle (DAkkS). The initial audit has two stages; after that, a three-year cycle begins:
- Stage 1. The auditor reviews the documentation and the readiness for the audit: scope, risk assessment, SoA — and whether internal audits and the management review are being planned and performed. The result names the points to be resolved before the second stage.
- Stage 2. The auditor examines implementation and effectiveness: talking to management and employees, inspecting evidence and checking whether what is documented is actually practised.
- Nonconformities. Major nonconformities must be resolved before the certificate is issued. For minor ones, a plan with corrective actions is sufficient as a rule.
- Certificate. It is valid for three years.
- Surveillance audits. At least once a year the certification body checks, on a sample basis, whether the ISMS continues to be operated and improved.
- Recertification. Before the three years expire, the entire ISMS is audited again.
From the start of the project to the certificate typically takes three to twelve months — depending on scope, existing documentation and available resources.
Certification is now carried out only against ISO/IEC 27001:2022. The transition period for certificates under the 2013 edition ended on 31 October 2025; older checklists with 114 controls in 14 domains are out of date.
Common weaknesses before the audit
- A scope that does not fit the business. If it is drawn too wide, the project becomes unmanageable. If it is too narrow, the customer asks why the service they use is not on the certificate.
- A risk assessment nobody can repeat. Without defined criteria, two people assessing the same risk arrive at two results.
- An SoA without justifications. “Not applicable” is a statement the auditor examines — for example when secure development is excluded but the company develops software.
- Internal audit and management review are missing. As a rule, certification bodies expect both to have taken place before the second stage. A date in the calendar is not enough.
- Documents nobody knows. A policy that nobody works to comes to light in the conversations with employees.
- Evidence created only for the audit. An ISMS is operated over months. Records that all bear the same date show the opposite.
What ISO 27001 certification delivers
Certification is not required by law. In practice, contracts and tenders demand it. And anyone who falls under NIS2 can use what is documented for ISO 27001 for the corresponding requirements — where it fits in substance.
- Know your risks instead of guessing. The risk assessment shows where an attack or an outage would do the most damage — and where the budget belongs first.
- Protect information in every form. The ISMS applies to paper, your own systems and the cloud: to financial data, intellectual property, personnel data and what customers have entrusted to you.
- Settle responsibilities. Roles, procedures and reporting channels are fixed before an incident occurs.
- Give evidence of trust. A certificate answers many of the questions in customers’ and partners’ security questionnaires with a single document.
- Spend money where it counts. Measures follow the risk. Spending on protection that lowers no risk stands out.
A certificate does not prevent an attack. It shows that the organisation knows its risks, treats them and checks the effectiveness of its measures — and that lowers the likelihood of an incident and limits its consequences.
Preparing for ISO 27001 with Complaica
Audit questions in a spreadsheet are answered once. By the time of the audit, assets, risks and measures have changed — the spreadsheet has not. Complaica is ISMS software for ISO 27001 in which the answers become the current state of the ISMS:
- Requirements and controls as a catalogue. The requirements of ISO/IEC 27001:2022 and the 93 Annex A controls are included, with implementation guidance from ISO/IEC 27002:2022. Every control receives an implementation status, a justification and evidence.
- Risk management. Risks per asset in a configurable risk matrix, with treatment option, measures and residual risk — aligned with ISO/IEC 27005.
- SoA and risk treatment plan as reports. Both are generated from the current data set — at the initial audit and before every surveillance audit.
- Measures with owners and deadlines. Every status change is recorded with author and date.
- Evidence on the object. Documents, links and assessments sit where they prove something.
- AI integration (MCP). For questions on requirements and controls. Assessment and decision stay with you.
- Further frameworks on the same data set. NIS2, TISAX, BSI IT-Grundschutz or the GDPR use the same assets, risks and evidence.
Get to know the Complaica ISMS software for ISO 27001
Added to this is consulting, as far as you need it: gap analysis, setting up the ISMS, risk management, policies, internal audits and preparation for the certification audit. The certification itself is performed by an independent certification body.
Would you like to know where your ISMS stands? Request a free 20-minute checkup.
Conclusion
An ISO 27001 cheat sheet turns the standard into one page that can be taken in at a glance, and the answers to the audit questions into a plan. It has its value when every answer is backed by evidence, every gap has an owner and a deadline, and the assessment is repeated. Start with the scope and the risk assessment — everything else follows from them — and plan the internal audit and the management review so that both are completed before the certification audit.
What do you think?
Write to us — which of these is you?
Thank you.
We will get back to you within one business day.
Not sent.
That did not work. Please check the fields or email us directly.