Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 Implementation — guide from Governance Docs

How to Implement ISO 27001: A Ten-Step Plan

ISO 27001 implementation fails in a recognisable way: the risk assessment is
done once by the security team in a spreadsheet nobody else sees, 93 Annex A controls are declared
applicable because declaring them out feels risky, and the Statement of Applicability becomes a
work of fiction. This is a ten-step plan that avoids that.

Before step one of ISO 27001 implementation: fix the scope

Scope decides the cost of everything downstream. Too wide and you are securing systems nobody
asked about; too narrow and the certificate does not cover what customers are asking for, which is
usually why you started. Write the scope around the services your customers actually buy, then check
it against the last three security questionnaires you were sent.

The ten steps of ISO 27001 implementation

  1. Gap analysis (1–3 weeks). Score current practice against clauses 4–10
    and Annex A. See our ISO 27001 gap analysis guide.
  2. Scope, context and interested parties (2–3 weeks). Including climate
    change, which the 2024 amendment added to clauses 4.1 and 4.2.
  3. Policy, roles and management commitment (1–2 weeks).
  4. Asset and information inventory (3–5 weeks). You cannot risk-assess what
    you have not listed. This is where projects discover the shadow IT.
  5. Risk assessment and treatment (4–8 weeks). A repeatable method, applied
    with the people who own the systems. See
    ISO 27001 risk assessment.
  6. Statement of Applicability (1–2 weeks, but only after step 5). All 93
    Annex A controls, each included or excluded with justification, and the SoA traceable to the risk
    treatment plan. See our guide to the
    Statement of Applicability.
  7. Implement the controls (2–6 months). The long pole, and the only step
    that actually changes your security posture. See
    the ISO 27001:2022 controls.
  8. Documentation, competence and awareness (4–6 weeks, overlapping). See
    ISO 27001 mandatory documents.
  9. Run the ISMS (3–6 months). Incidents, access reviews, supplier reviews,
    monitoring — real records before an audit has anything to sample.
  10. Internal audit, management review, certification. Both are prerequisites. See
    internal audit,
    stage 1 vs stage 2 and
    ISO 27001 certification.

Every document in this plan, already written to the 2022 edition.

The ISO 27001 Toolkit provides 162 editable templates — ISMS policies, the risk assessment method and register, the Statement of Applicability, Annex A control documentation and the full internal audit set.

Explore the ISO 27001 Toolkit →

The three steps ISO 27001 implementation always underestimate

Step 4, the asset inventory. Budgeted as a week, takes a month, and determines
whether the risk assessment is real. An inventory that omits the SaaS tools three departments
expense on cards will produce a risk assessment that misses the actual exposure.

Step 7, implementing controls. This is where ISO 27001 implementation stops
being documentation and starts requiring engineering time, budget and someone telling a team to
change how they work. Plan it as a delivery programme, not a paperwork exercise.

Step 9, running the ISMS. Plans routinely jump from “controls implemented” to
“stage 2” in a fortnight. It cannot work: clause 9.2 needs audit results, 9.3 needs review inputs,
and the auditor will sample access reviews and supplier assessments across a period, not a day.

The Statement of Applicability is where ISO 27001 implementation is judged

Everything converges on the SoA, and auditors read it first. The two failure modes are opposite
and equally common. Declaring all 93 controls applicable when several plainly are not — no
development function, no physical data centre — produces commitments you cannot evidence.
Excluding controls with a one-line justification that does not reference the risk assessment
produces a finding. Every inclusion needs an implementation status; every exclusion needs a reason
that traces back to risk.

A realistic total for ISO 27001 implementation

For a single-entity organisation of fifty to two hundred and fifty people with no existing
certification, six to twelve months from gap analysis to certificate is defensible.
Three to six is achievable for a small SaaS business with mature engineering practice and a narrow
scope. Under three months means step 9 has been skipped, and step 9 is what stage 2 samples.
For cost, see our ISO 27001
cost breakdown
, and for sequencing, the ISO 27001
timeline
.

References

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.