ISO · Compliance March 2026

How to Prepare for
ISO 27001

A practical, no-nonsense guide based on real certification experience, from the first gap analysis to the final audit.

Why ISO 27001?

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It's not just a checkbox, done right, it becomes the backbone of how your organization handles risk, access, incidents, and data. Clients ask for it. Regulators respect it. And internally, it forces you to document what you actually do, which is often more valuable than the certificate itself.

Step 1: Gap Analysis

Before anything else, map where you stand. Take Annex A (the 93 controls in ISO 27001:2022) and go through each one. For every control, answer: Do we have this? Is it documented? Is it working?

Use a simple spreadsheet: control ID, description, current status (Not implemented / Partial / Implemented), responsible person, and deadline. This becomes your roadmap.

TipDon't try to be perfect on day one. A realistic gap analysis is more useful than an optimistic one. Auditors have seen everything, they respect honesty and evidence, not polished presentations.

Step 2: Define Your ISMS Scope

The scope defines what's in and what's out. It can be the entire company, a single department, or a specific product. The narrower the scope, the faster the certification, but the less valuable it is to clients who deal with your whole organization.

Document the scope clearly. Include: what information assets are covered, which locations, which processes, and any explicit exclusions with justification.

Step 3: Risk Assessment

This is the heart of ISO 27001. You need a formal process for identifying, analyzing, and treating information security risks. The standard doesn't dictate a method, you choose one and apply it consistently.

A practical approach: list your assets, identify threats and vulnerabilities for each, estimate likelihood and impact, calculate risk level, then decide: accept, mitigate, transfer, or avoid.

TipKeep your risk register alive. A risk assessment done once and forgotten is a red flag for auditors. Schedule quarterly reviews and document every update.

Step 4: Policies and Procedures

ISO 27001 requires a set of mandatory documented policies. At minimum: Information Security Policy, Access Control Policy, Asset Management, Incident Response, Business Continuity, and Supplier Security. Each must be approved by management, communicated to staff, and reviewed regularly.

Write policies that reflect what you actually do, not what you wish you did. Auditors will interview your team. If staff can't describe the process, the document is just paper.

Step 5: Internal Audit

Before the external certification audit, run at least one full internal audit. This is where you catch gaps before the auditor does. Assign an internal auditor (or use a consultant), audit against all applicable controls, and produce a formal report with findings and corrective actions.

Step 6: Management Review

Top management must formally review the ISMS at planned intervals. This isn't optional, it's a mandatory requirement. Hold a documented meeting, review audit results, risk treatment status, incidents, objectives, and any changes affecting the ISMS. Minute the meeting and keep records.

Audit Day

The external audit has two stages: Stage 1 (document review) and Stage 2 (implementation audit). In Stage 1, the auditor checks your documentation. In Stage 2, they verify that what's documented is actually happening. Be prepared to show evidence, logs, access reviews, training records, meeting minutes.

Common findings: risk register not updated, evidence of awareness training missing, access reviews not documented, supplier contracts without security clauses. Fix these before Stage 2.

Final thoughtISO 27001 is a journey, not a destination. The certificate is proof of a working system, not proof that you once had one. Build it to last, and it will pay back in trust, efficiency, and resilience.