ISO 27001 Requirements: What the Standard Asks of an SME
The mandatory parts of ISO 27001 are smaller and more sensible than they first look, and the standard scales to a business your size.
The short version
- The requirements are the clauses, not the controls: the mandatory 'shall' requirements live in clauses 4 to 10, which describe how to run a management system for information security.
- Annex A is a menu: its 93 reference controls are options you select from based on your risks and record in a Statement of Applicability, not a to-do list you complete in full.
- The core deliverable is an ISMS: a scope, a risk assessment, policies, a handful of records, an internal audit, and a management review.
- It scales to your size: a five-person firm meets the same clauses as a multinational, just with far lighter documentation.
- Certification comes from an accredited body: in the UK, look for a UKAS-accredited certification body when the certificate needs to stand up to scrutiny.
If you have started reading about ISO 27001, you have probably met two scary-sounding numbers: seven clauses of formal requirements and ninety-three controls. It is easy to assume you must do all of it, to the letter, before anyone will take you seriously. The good news is that the ISO 27001 requirements are more sensible than that first impression suggests, and once you see how the pieces fit together, the whole thing becomes a lot less daunting.
This guide walks through what the standard genuinely asks of a UK small or medium business, in plain English. We will separate the parts you must do from the parts you choose, cover the documents you need to hold, bust a few myths, and show why the standard scales down to a business your size.
What “requirements” actually means in ISO 27001
The true requirements are the “shall” statements in clauses 4 to 10, which set out how to run a management system, while the Annex A controls are a menu you select from.
This distinction is the single most useful thing to understand. The current version of the standard, ISO/IEC 27001:2022, is built in two parts. The first part, the numbered clauses from 4 through 10, contains the mandatory requirements. These are the auditable “shall” statements a certification body checks you against. The second part, Annex A, lists 93 reference controls you can draw on to treat your risks. You are not required to apply all of them.
People trip up here constantly. They see 93 controls and start building a project plan to implement every one, when the standard never asks for that. The clauses tell you to run a proper information security management system, or ISMS. The controls are simply the toolbox you reach into once you know what you are protecting against.
The one-line version
Clauses 4 to 10 are what you must do. Annex A is what you may choose to do about it. Your risk assessment decides which controls make the cut, and your Statement of Applicability records those choices.
The seven clauses, in plain English
Clauses 4 to 10 describe a sensible management cycle: understand your situation, take charge of it, plan around risk, support the work, run it, check it, and improve it.
Here is what each mandatory clause is really asking.
Clause 4, Context and scope. Work out what your business does, who cares about your information security (customers, regulators, staff), and where the boundaries of your ISMS sit. Scope is your friend here. You define what is in and what is out, and a tight, honest scope keeps the whole exercise manageable.
Clause 5, Leadership and policy. Someone senior has to own this and mean it. You produce a short information security policy and make sure roles and responsibilities are clear. For a small firm this might be the founder and one other person, and that is perfectly acceptable.
Clause 6, Planning and risk. This is the engine room. You assess the risks to your information, decide how to treat each one, and set some security objectives. The risk assessment is what drives your choice of controls, so it earns its place at the heart of the standard.
Clause 7, Support. Give the ISMS what it needs to function: competent people, some awareness across the team, and the documented information the standard calls for. This is also where the rules about keeping and controlling your documents live.
Clause 8, Operation. Actually do the things you planned. Run your risk assessment at planned intervals, carry out your risk treatment, and keep the day-to-day security running as intended.
Clause 9, Performance evaluation. Check that it works. This clause covers monitoring, an internal audit of your own ISMS, and a management review where leadership sits down and looks at how things are going.
Clause 10, Improvement. When something goes wrong or falls short, deal with it, record it, and stop it recurring. The standard expects continual improvement rather than a one-off effort that gathers dust.
Spot the pattern
Those seven clauses are a Plan, Do, Check, Act loop dressed in formal language. If your business already reviews how it works and fixes what breaks, you are closer to ISO 27001 than you think.
Risk assessment and the Statement of Applicability
Your risk assessment identifies what could go wrong, and the Statement of Applicability records which Annex A controls you are using to address it and why.
The risk assessment does not need to be a fifty-page technical treatise. It needs to be honest and repeatable. Identify your information assets, think about what could threaten them, judge how likely and how damaging each risk is, and decide what to do: reduce it, accept it, avoid it, or share it.
Once you know how you are treating each risk, you pick the controls that help. That is where the Statement of Applicability, or SoA, comes in. The SoA is a required document under the standard. It lists the Annex A controls, states whether each one applies to you, gives your reason for including or excluding it, and notes how the applicable ones are handled. The 93 controls sit across four themes: organisational, people, physical, and technological. Many small businesses find that a fair few controls genuinely do not apply, and writing “not applicable, because…” is a completely valid, documented answer.
If you are weighing this against a lighter-touch scheme first, our guide to Cyber Essentials vs ISO 27001 explains where each one fits.
The documented information you must hold
You need a modest set of records, not a filing cabinet: a scope, a policy, your risk method, the SoA, and evidence that the system is running.
The word “documentation” scares people, so let us be concrete about the sorts of documented information ISO 27001 expects you to keep:
- The scope of your ISMS
- An information security policy and your security objectives
- Your risk assessment and risk treatment process, and the results of running it
- The Statement of Applicability
- Evidence of competence and awareness across the people who need it
- Records that the system works, including internal audit results and management review notes, plus how you handle any problems
For a small business, several of these can be short. A policy can be a couple of pages. A risk treatment plan can be a simple table. What matters is that the documents are real, current, and match what you actually do, not that they are long. Auditors are far happier with a lean set of honest records than a thick binder nobody follows.
Myth-busting: what ISO 27001 does not require
A lot of the fear around ISO 27001 comes from requirements it never actually imposes.
Let us clear a few of these away.
- It does not require all 93 controls. They are a reference set you select from. This is worth repeating because it is the most common misunderstanding.
- It does not require a full-time security team. It requires competent people and clear ownership. In a small firm, that can be existing staff wearing an extra hat.
- It does not require expensive tooling. The standard is technology-neutral. It cares that risks are managed, not that you bought a particular product.
- It does not require perfection. It requires a system that finds problems and improves. A recorded issue with a sensible fix is a sign of a healthy ISMS, not a failure.
- It does not require you to reinvent everything. Much of what you already do (backups, access rules, staff onboarding) can be pointed at as evidence, tidied up rather than rebuilt.
A reassuring frame
ISO 27001 rewards businesses that are honest about their risks and steady about managing them. It does not reward the biggest budget or the longest documents.
How much realistically applies to a small business
The standard is deliberately scalable, so a small firm meets the same clauses as a large one but with proportionate effort and far fewer controls in scope.
This is the part that tends to relieve people most. Nothing in ISO 27001 says a ten-person company must do as much as a ten-thousand-person company. The clauses are written to flex. Your scope is smaller, your risk assessment is simpler, your documents are shorter, and your Statement of Applicability legitimately excludes controls that do not touch your business.
A very small team might run its whole management review as a focused meeting a couple of times a year, keep a single risk register, and hold a compact set of policies. That can be entirely compliant. The effort is real, but it is front-loaded and then maintained, which is why so much of the value comes from doing the groundwork once and keeping it fresh.
When you are ready to certify, the certificate itself is issued by a certification body. In the UK, a certificate from a UKAS-accredited body carries the most weight, particularly if larger customers or public-sector procurement are in your future. For a broader picture of the journey and what it costs, our overviews of ISO 27001 for SMEs and the ISO 27001 certification cost are good next stops. And if you are earlier in your security journey, the Cyber Essentials checklist is a sensible, lower-cost first step that builds many of the same habits.
The requirements of ISO 27001 are not a wall. They are a well-worn path, and it scales to fit a business your size.
SecurSentry is launching soon to help UK SMEs turn the ISO 27001 requirements into a clear, maintainable set of steps, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.
This article is for general information only and does not constitute legal or compliance advice. ISO 27001 requirements vary by organisation and scope; where in doubt, consult a qualified professional or an accredited certification body.