Certification planner / ISO 27001
How do you get ISO 27001 certification?
Information security management system: risk assessment, Annex A controls and the Statement of Applicability (SoA). Answer the questions, and we'll map out the stages, timeline and documents you need to prepare for your business, with the reasoning behind each one.
ISO 27001 certification steps
- Scope and gap analysisDefine the certification scope and locations, and identify the gaps between your current practices and the standard.
- Leadership, policy and objectivesTop management commitment, policy, roles and measurable objectives.
- Risks and standard-specific analysesRisks and opportunities; depending on the standard, environmental aspects, information security risks or business impact analysis.
- DocumentationPrepare, approve and publish procedures, work instructions, forms and lists tailored to your business.
- Implementation and recordsOperate the system; build up records such as training, calibration, suppliers and corrective actions.
- Internal audit and management reviewAudit the system yourself, close the findings and conduct the management review.
- Certification auditStage 1 (documentation) and Stage 2 (implementation) audits by an accredited body, followed by the certificate.
Documents required for ISO 27001
The mandatory set from the KaliteGO library. Each one is generated as docx/xlsx, filled in with your company details.
DD.1Context DocumentDD.2Scope and Boundaries DocumentDD.3IMS Process Setup DocumentDD.4Leadership Management DocumentDD.5Support Resource Management DocumentFR.1Context (Internal and External Issues) FormFR.10Residual Risk Declaration and Approval Form.FR.11Equipment Assignment FormFR.12VPN Access Request FormFR.13Destruction ReportFR.14Asset Off-Site Transfer Tracking ReportFR.15Tracking Form for Disposed Assets No Longer in UseFR.16Access and Usage Authorization Table.FR.17Tracking Form for Equipment and Hardware Sent Off-SiteFR.18Maintenance Tracking FormFR.19Breach Incident Notification Form.FR.2Process Interaction Form.FR.20Breach Incident Outcome FormFR.21Business Continuity Team and Responsibilities FormFR.23Site Entry and Exit Tracking Form.FR.24Job Application FormFR.25Reference Check FormFR.3Internal Communication FormFR.30Training Attendance and Evaluation FormFR.32Incident, Situation and Breach Determination Report FormFR.35Warning Notice FormFR.36Disciplinary Committee Decision Report FormFR.4Meeting Minutes FormFR.5Internal Audit ReportFR.6Goal and Objective Tracking FormFR.7Change Request and Tracking FormFR.8Corrective Action FormFR.9Performance Monitoring and Tracking Form.GT.EK.1Management ISMS ResponsibilitiesGT.EK.2ISMS Team ResponsibilitiesGT.EK.3ISMS Responsibilities of Managers and SupervisorsGT.EK.4Personnel ISMS ResponsibilitiesLS.1Current Documents and Revision Tracking ListLS.10Internal Audit Checklist - ITLS.11Supplier Tracking and Evaluation List.LS.12Breach Incident Tracking ListLS.13Asset Inventory ListLS.14Legal and Other Requirements ListLS.15Breakdown and Maintenance Tracking ListLS.2Interested Parties and Stakeholder Analysis List.LS.3External Document ListLS.4Opportunity Planning Tracking ListLS.5External Communication ListLS.6Internal Communication ListLS.7Corrective Action Tracking ListLS.8Improvement Tracking ListLS.9Special Interest Groups Contact ListPL.1Internal Audit PlanPL.3ISMS Risk Analysis PlanPL.4Backup PlanPL.5IT Assets Capacity Monitoring PlanPL.6Business Continuity Impact Analysis PlanPL.7Business Continuity Exercise PlanPL.8Risk Analysis, Assessment and Treatment Plan - IMSPO.1Remote Working Access PolicyPO.10Backup PolicyPO.11Information Transfer PolicyPO.12Cryptography Management PolicyPO.13Protection Against Malware PolicyPO.14Capacity Management PolicyPO.15Technical Vulnerability Management PolicyPO.16Logging PolicyPO.17Endpoint Devices Configuration and Use PolicyPO.18Privacy and Protection of Personally Identifiable Information PolicyPO.19Monitoring PolicyPO.2Asset Management PolicyPO.20Cloud Services Management PolicyPO.21Test Information Management PolicyPO.22Threat Intelligence PolicyPO.23Information Deletion and Data Masking PolicyPO.3Information Asset Classification and Labeling PolicyPO.34Information Security PolicyPO.4Acceptable Use of Information and Assets PolicyPO.5Configuration Management PolicyPO.6Mobile Device PolicyPO.7Clear Desk and Clear Screen PolicyPO.8Identity Management and Password Security PolicyPO.9Network Security PolicyPR.1Control of Documented Information and Records ProcedurePR.10Purchasing ProcedurePR.11Physical Control and Security ProcedurePR.12Maintenance ProcedurePR.13Human Resources ProcedurePR.14Training and Awareness Management ProcedurePR.16Information Security Operations and Secure Development ProcedurePR.17Information Security Incident Management ProcedurePR.18Information Security Business Continuity ProcedurePR.19Storage Media, Portable Information and Media Protection ProcedurePR.2Risk and Opportunity Management ProcedurePR.20Access Control Management ProcedurePR.21Intellectual Property Rights, Legal Compliance and Control ProcedurePR.22System Acquisition and Development ProcedurePR.23Equipment Security ProcedurePR.24Software Development ProcedurePR.3Change Management ProcedurePR.4Communication Management ProcedurePR.6Internal Audit ProcedurePR.7Management Review Procedure.PR.8Improvement, Nonconformity and Corrective Action ProcedurePR.9Goals, Objectives and Performance Monitoring ProcedureSOA- Statement of Applicability - ISO 27001 2022SOZ.1Confidentiality AgreementTL.1Document Writing Format and Coding Work Instruction.TL.2Supplier Evaluation Work InstructionTL.3Asset and Equipment Disposal Work InstructionTL.4Internet Use Rules Work InstructionTL.5Server Room Security Work InstructionTL.6Emergency, Crisis Management and Business Recovery Work InstructionŞM.01Organization Chart
Frequently asked questions
How long does ISO 27001 certification take?
For most SMEs, 4–9 months. The timeline depends on your headcount, locations and current practices. The system needs to run long enough to generate records (usually 2–3 months), followed by an internal audit, a management review and the certification body's Stage 1 and Stage 2 audits.
Which documents are required for ISO 27001?
The standard explicitly requires certain documented information: scope, policy, objectives, procedures and records. The KaliteGO library has 114 document templates for ISO 27001; the planner explains which of them your business needs, and why.
Does KaliteGO issue the certificate?
No. The certificate is issued by an accredited certification body following the audit. KaliteGO gets you ready for the audit: documents, records, internal audit and management review.
Can I prepare without a consultant?
Yes. Most small and medium-sized businesses can prepare with a guided roadmap and ready-made templates. Consultants also use KaliteGO to manage multiple clients.