An ISO 27001 Checklist for Small Businesses
ISO 27001 looks enormous from the outside. Broken into phases and taken in order, it becomes a series of manageable jobs. Here's the sequence.
The short version
- It's a system, not a form: ISO 27001 certifies an information security management system (ISMS), so a checklist is really a running order for building one.
- Do it in phases: foundations, then risk, then policies and controls, then people, then running it, then certification. Each phase leans on the last.
- Expect real effort over months: most small firms spend several months getting ready before an external auditor is involved, and the standard expects the system to have been running for a while first.
- Cyber Essentials groundwork carries forward: the technical basics you set up for Cyber Essentials map onto ISO 27001's technology controls, so that work isn't wasted.
- Certification is external: the final Stage 1 and Stage 2 audits are done by an accredited certification body, not by you.
If ISO 27001 has landed on your desk because a big customer or a tender asked for it, the first feeling is usually the same: this looks enormous. And from the outside, it is a lot. The good news is that most of the size comes from the standard being written for organisations of every shape, so a fair chunk of it simply won’t apply to a business of your size. The rest becomes manageable once you stop treating it as one giant wall and start treating it as a sequence of smaller jobs, done in a sensible order.
That order matters more than people expect. ISO 27001 isn’t a checklist you tick off and file away. It certifies an information security management system, an ISMS, which is really just a tidy, repeatable way of running your security so it keeps working after the initial push. But the path to being ready for certification can be sequenced, and each phase below builds on the one before it. Work through them in order and you avoid the classic trap of writing pages of policy before you’ve worked out what you’re actually protecting. Here’s the running order.
Phase 1: Foundations
Before any of the security work, decide what you’re protecting, get leadership genuinely behind it, and put a name against the effort.
- Define your scope. Write down which parts of the business the ISMS covers: which services, sites, systems and people. A tight, honest scope is your friend. Trying to certify everything at once is how small teams drown.
- Get leadership commitment in writing. The standard expects senior people to own this, not just sponsor it from a distance. That means agreeing time, budget and a short information security policy that sets the direction.
- Name an owner. One person needs to hold the thread, even in a business of ten. They don’t have to do every task, but they keep the plan moving and know where everything stands.
- List your information assets. What information matters, where it lives, and who is responsible for it. This list feeds directly into the next phase, so it’s worth doing properly.
Scope is a lever, not a formality
The single biggest influence on how much work certification takes is how wide you draw the scope. A well-chosen scope keeps the whole exercise proportionate to your business. Widen it later, once the system is running smoothly, rather than starting broad and struggling.
Phase 2: Risk
Work out what could realistically go wrong with your information, decide what you’ll do about each risk, and record those decisions in a Statement of Applicability.
- Run a risk assessment. Go through your asset list and identify what threatens the confidentiality, integrity and availability of each one. Give every risk an owner and a sense of how likely and how damaging it is. The method matters less than being consistent, so the same situation gives the same answer twice.
- Decide on risk treatment. For each risk you care about, choose a response: reduce it with a control, accept it, avoid the activity, or share it (for example through insurance or a supplier). This is where the standard’s Annex A controls come in.
- Produce your Statement of Applicability (SoA). This is one of the documents auditors look for first. ISO/IEC 27001:2022 lists 93 controls in Annex A, grouped into four themes: organisational, people, physical and technological. Your SoA lists all 93, says whether each one applies to you, and gives a short reason either way.
You are not obliged to use all 93 controls. The SoA is precisely where you justify leaving out the ones that don’t fit your business. That flexibility is deliberate, and using it honestly is part of doing this well.
Phase 3: Policies and controls
Turn your risk decisions into the actual policies, procedures and technical measures that put the chosen controls into practice.
- Write the documents the standard requires. These include your information security policy, and procedures for the areas your SoA marked as applicable, such as access control, supplier security, and how you handle an incident. Keep them short and true to how you really work. A policy nobody follows is worse than no policy.
- Put the technical controls in place. This covers the everyday defences: access permissions, encryption where it’s needed, backups, logging, protection against malware, and keeping software patched.
- Reuse your Cyber Essentials groundwork. If you’ve already done Cyber Essentials, the five technical areas behind it map neatly onto several of ISO 27001’s technology controls, so that effort feeds straight in. If you haven’t yet, it’s a sound place to start and a smaller first commitment. Our Cyber Essentials checklist walks through the basics, and Cyber Essentials vs ISO 27001 explains how the two fit together.
- Set retention and disposal rules. Decide how long you keep different kinds of information and how you dispose of it safely. Auditors do ask.
Phase 4: People
Your controls only work if the people around them understand their part, so build awareness and record that you’ve done it.
- Run security awareness training. Everyone in scope should understand the basics: spotting a dodgy email, handling data carefully, and knowing who to tell when something looks wrong. It needn’t be elaborate to count.
- Cover the joiners and leavers process. Set out how access is granted when someone starts and, just as importantly, removed promptly when they leave or change role.
- Keep the records. Attendance, sign-offs, dates. Training that happened but left no trace is hard to demonstrate later, and demonstrating things is much of what an audit involves.
Records are the quiet backbone
Right through ISO 27001, the difference between "we do this" and "we can prove we do this" is written records. Get into the habit early of logging decisions, reviews and completed tasks. It feels like admin now and saves you badly during the audit.
Phase 5: Run it
An ISMS has to be seen working before it can be certified, so operate it for a while and check it yourself first.
- Let the system run. Auditors generally want to see your ISMS operating and producing records over a period, not switched on the week before. Build that running-in time into your plan rather than hoping to shortcut it.
- Carry out an internal audit. ISO 27001 clause 9.2 requires you to audit your own system at planned intervals, checking it does what you said and meets the standard. This is your dry run, and it’s meant to surface gaps while there’s still time to fix them.
- Hold a management review. Clause 9.3 asks senior people to sit down and review how the ISMS is performing, what’s changed, and what needs improving. Minute it.
- Fix what you find. Log any weaknesses as corrective actions, sort them, and note what you did. Finding problems here is a sign the system is working, not a failure.
Phase 6: Certification
When your system has been running and you’ve ironed out your own findings, bring in an accredited certification body for the two-stage external audit.
- Choose an accredited certification body. For a certificate that carries real weight, pick one accredited by UKAS, the UK’s national accreditation body. Get quotes from a few and check they know your sector.
- Stage 1: the documentation review. The auditor checks your ISMS is designed properly and that the core documents are in place and consistent. Think of it as confirming you’re ready for the deeper look.
- Stage 2: the implementation audit. Usually a few weeks after Stage 1, the auditor gathers evidence that your controls and processes are genuinely operating, not just written down. This is where those records earn their keep.
- Close out any findings and receive certification. Address anything raised, and once the auditor is satisfied, the certificate is issued. It typically runs for three years, with annual surveillance visits to confirm you’re keeping it up.
Common trip-ups
A few things catch small businesses out. Drawing the scope too wide is the big one, turning a proportionate project into a slog. Writing polished policies that describe an ideal business rather than your real one is another, because auditors talk to your team and the gap shows. Leaving records as an afterthought bites late, when you can’t evidence work you genuinely did. And treating certification as a finish line rather than a habit means the second year feels as hard as the first. None of these are hard to avoid once you know they’re there. Pace yourself, keep the scope honest, and write things down as you go.
If you’re still weighing up whether ISO 27001 is the right target at all, ISO 27001 for SMEs is a gentler starting point, and what ISO 27001 certification costs sets out the money side plainly.
SecurSentry is launching soon to help UK SMEs work through a path like this without the overwhelm, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.
This article is for general information only and does not constitute legal or compliance advice. Scope and steps vary by organisation; where in doubt, consult a qualified professional or an accredited certification body.