Certification planner / ISO 27001

How do you get ISO 27001 certification?

Information security management system: risk assessment, Annex A controls and the Statement of Applicability (SoA). Answer the questions, and we'll map out the stages, timeline and documents you need to prepare for your business, with the reasoning behind each one.

4–9 monthstypical preparation time 114documents in the library 7stage

Your personal roadmap

Free · no sign-up required · about 2 minutes

Describe your main products and services, your customers and how you work in a few sentences.
E.g. metal processing, software, logistics, food production, consulting
Office, factory, warehouse, construction site — all addresses to be included in the certification scope.
Accreditation bodies and legal requirements vary by country.
Do you develop software? Annex A 8.25–8.31 secure development controls depend on this.

Your answers are processed with AI solely to prepare your roadmap.

ISO 27001 certification steps

  1. Scope and gap analysisDefine the certification scope and locations, and identify the gaps between your current practices and the standard.
  2. Leadership, policy and objectivesTop management commitment, policy, roles and measurable objectives.
  3. Risks and standard-specific analysesRisks and opportunities; depending on the standard, environmental aspects, information security risks or business impact analysis.
  4. DocumentationPrepare, approve and publish procedures, work instructions, forms and lists tailored to your business.
  5. Implementation and recordsOperate the system; build up records such as training, calibration, suppliers and corrective actions.
  6. Internal audit and management reviewAudit the system yourself, close the findings and conduct the management review.
  7. Certification auditStage 1 (documentation) and Stage 2 (implementation) audits by an accredited body, followed by the certificate.

Documents required for ISO 27001

The mandatory set from the KaliteGO library. Each one is generated as docx/xlsx, filled in with your company details.

  • DD.1Context Document
  • DD.2Scope and Boundaries Document
  • DD.3IMS Process Setup Document
  • DD.4Leadership Management Document
  • DD.5Support Resource Management Document
  • FR.1Context (Internal and External Issues) Form
  • FR.10Residual Risk Declaration and Approval Form.
  • FR.11Equipment Assignment Form
  • FR.12VPN Access Request Form
  • FR.13Destruction Report
  • FR.14Asset Off-Site Transfer Tracking Report
  • FR.15Tracking Form for Disposed Assets No Longer in Use
  • FR.16Access and Usage Authorization Table.
  • FR.17Tracking Form for Equipment and Hardware Sent Off-Site
  • FR.18Maintenance Tracking Form
  • FR.19Breach Incident Notification Form.
  • FR.2Process Interaction Form.
  • FR.20Breach Incident Outcome Form
  • FR.21Business Continuity Team and Responsibilities Form
  • FR.23Site Entry and Exit Tracking Form.
  • FR.24Job Application Form
  • FR.25Reference Check Form
  • FR.3Internal Communication Form
  • FR.30Training Attendance and Evaluation Form
  • FR.32Incident, Situation and Breach Determination Report Form
  • FR.35Warning Notice Form
  • FR.36Disciplinary Committee Decision Report Form
  • FR.4Meeting Minutes Form
  • FR.5Internal Audit Report
  • FR.6Goal and Objective Tracking Form
  • FR.7Change Request and Tracking Form
  • FR.8Corrective Action Form
  • FR.9Performance Monitoring and Tracking Form.
  • GT.EK.1Management ISMS Responsibilities
  • GT.EK.2ISMS Team Responsibilities
  • GT.EK.3ISMS Responsibilities of Managers and Supervisors
  • GT.EK.4Personnel ISMS Responsibilities
  • LS.1Current Documents and Revision Tracking List
  • LS.10Internal Audit Checklist - IT
  • LS.11Supplier Tracking and Evaluation List.
  • LS.12Breach Incident Tracking List
  • LS.13Asset Inventory List
  • LS.14Legal and Other Requirements List
  • LS.15Breakdown and Maintenance Tracking List
  • LS.2Interested Parties and Stakeholder Analysis List.
  • LS.3External Document List
  • LS.4Opportunity Planning Tracking List
  • LS.5External Communication List
  • LS.6Internal Communication List
  • LS.7Corrective Action Tracking List
  • LS.8Improvement Tracking List
  • LS.9Special Interest Groups Contact List
  • PL.1Internal Audit Plan
  • PL.3ISMS Risk Analysis Plan
  • PL.4Backup Plan
  • PL.5IT Assets Capacity Monitoring Plan
  • PL.6Business Continuity Impact Analysis Plan
  • PL.7Business Continuity Exercise Plan
  • PL.8Risk Analysis, Assessment and Treatment Plan - IMS
  • PO.1Remote Working Access Policy
  • PO.10Backup Policy
  • PO.11Information Transfer Policy
  • PO.12Cryptography Management Policy
  • PO.13Protection Against Malware Policy
  • PO.14Capacity Management Policy
  • PO.15Technical Vulnerability Management Policy
  • PO.16Logging Policy
  • PO.17Endpoint Devices Configuration and Use Policy
  • PO.18Privacy and Protection of Personally Identifiable Information Policy
  • PO.19Monitoring Policy
  • PO.2Asset Management Policy
  • PO.20Cloud Services Management Policy
  • PO.21Test Information Management Policy
  • PO.22Threat Intelligence Policy
  • PO.23Information Deletion and Data Masking Policy
  • PO.3Information Asset Classification and Labeling Policy
  • PO.34Information Security Policy
  • PO.4Acceptable Use of Information and Assets Policy
  • PO.5Configuration Management Policy
  • PO.6Mobile Device Policy
  • PO.7Clear Desk and Clear Screen Policy
  • PO.8Identity Management and Password Security Policy
  • PO.9Network Security Policy
  • PR.1Control of Documented Information and Records Procedure
  • PR.10Purchasing Procedure
  • PR.11Physical Control and Security Procedure
  • PR.12Maintenance Procedure
  • PR.13Human Resources Procedure
  • PR.14Training and Awareness Management Procedure
  • PR.16Information Security Operations and Secure Development Procedure
  • PR.17Information Security Incident Management Procedure
  • PR.18Information Security Business Continuity Procedure
  • PR.19Storage Media, Portable Information and Media Protection Procedure
  • PR.2Risk and Opportunity Management Procedure
  • PR.20Access Control Management Procedure
  • PR.21Intellectual Property Rights, Legal Compliance and Control Procedure
  • PR.22System Acquisition and Development Procedure
  • PR.23Equipment Security Procedure
  • PR.24Software Development Procedure
  • PR.3Change Management Procedure
  • PR.4Communication Management Procedure
  • PR.6Internal Audit Procedure
  • PR.7Management Review Procedure.
  • PR.8Improvement, Nonconformity and Corrective Action Procedure
  • PR.9Goals, Objectives and Performance Monitoring Procedure
  • SOA- Statement of Applicability - ISO 27001 2022
  • SOZ.1Confidentiality Agreement
  • TL.1Document Writing Format and Coding Work Instruction.
  • TL.2Supplier Evaluation Work Instruction
  • TL.3Asset and Equipment Disposal Work Instruction
  • TL.4Internet Use Rules Work Instruction
  • TL.5Server Room Security Work Instruction
  • TL.6Emergency, Crisis Management and Business Recovery Work Instruction
  • ŞM.01Organization Chart

Frequently asked questions

How long does ISO 27001 certification take?

For most SMEs, 4–9 months. The timeline depends on your headcount, locations and current practices. The system needs to run long enough to generate records (usually 2–3 months), followed by an internal audit, a management review and the certification body's Stage 1 and Stage 2 audits.

Which documents are required for ISO 27001?

The standard explicitly requires certain documented information: scope, policy, objectives, procedures and records. The KaliteGO library has 114 document templates for ISO 27001; the planner explains which of them your business needs, and why.

Does KaliteGO issue the certificate?

No. The certificate is issued by an accredited certification body following the audit. KaliteGO gets you ready for the audit: documents, records, internal audit and management review.

Can I prepare without a consultant?

Yes. Most small and medium-sized businesses can prepare with a guided roadmap and ready-made templates. Consultants also use KaliteGO to manage multiple clients.