isms.coach
← All guides

Checklist

The real ISO 27001 checklist (not just Annex A)

Annex A is the part everyone talks about — it's actually the smaller half of what certification requires.

Search "ISO 27001 checklist" and almost every result is really just an Annex A control list. That's only half the standard. Clauses 4 through 10 — the actual management system requirements — are what most self-led implementations underestimate, and what auditors check before they even look at your controls.

The clauses, in the order they actually get built

  • Clause 4 — Context of the organization. Your scope statement, internal/external issues, and interested parties. Auditors start here because it defines what everything else is measured against.
  • Clause 5 — Leadership. A documented, approved Information Security Policy and clearly assigned roles — proof that this isn't just an IT project nobody senior signed off on.
  • Clause 6 — Planning. Your risk assessment and objectives. This is what should be driving your Annex A control selection, not the other way around.
  • Clause 7 — Support. Competence, awareness training, and documented information — the unglamorous administrative backbone auditors check for consistency.
  • Clause 8 — Operation. Evidence the risk treatment plan is actually being executed, not just written down.
  • Clause 9 — Performance evaluation. Internal audit and management review — proof the ISMS checks itself, not just that it exists.
  • Clause 10 — Improvement. Nonconformities and corrective actions. Auditors read this as a sign your ISMS can catch and fix its own problems.
  • Annex A — 93 controls across four themes, selected based on your risk assessment. Browse the full list with plain-English explanations on our Annex A controls page.

Why this matters for your checklist

A self-led implementation that treats Annex A as the whole standard usually produces a Statement of Applicability that looks complete but isn't grounded in a real risk assessment — which is exactly the mismatch an auditor is trained to catch. Build clauses 4 through 6 first; Annex A gets easier and more defensible once it does.

Ready to actually start? Your Statement of Applicability comes pre-populated with all 93 Annex A controls — no blank page.

Start your ISMS