ISO 27001 implementation fails in a recognisable way: the risk assessment is
done once by the security team in a spreadsheet nobody else sees, 93 Annex A controls are declared
applicable because declaring them out feels risky, and the Statement of Applicability becomes a
work of fiction. This is a ten-step plan that avoids that.
Before step one of ISO 27001 implementation: fix the scope
Scope decides the cost of everything downstream. Too wide and you are securing systems nobody
asked about; too narrow and the certificate does not cover what customers are asking for, which is
usually why you started. Write the scope around the services your customers actually buy, then check
it against the last three security questionnaires you were sent.
The ten steps of ISO 27001 implementation
- Gap analysis (1–3 weeks). Score current practice against clauses 4–10
and Annex A. See our ISO 27001 gap analysis guide. - Scope, context and interested parties (2–3 weeks). Including climate
change, which the 2024 amendment added to clauses 4.1 and 4.2. - Policy, roles and management commitment (1–2 weeks).
- Asset and information inventory (3–5 weeks). You cannot risk-assess what
you have not listed. This is where projects discover the shadow IT. - Risk assessment and treatment (4–8 weeks). A repeatable method, applied
with the people who own the systems. See
ISO 27001 risk assessment. - Statement of Applicability (1–2 weeks, but only after step 5). All 93
Annex A controls, each included or excluded with justification, and the SoA traceable to the risk
treatment plan. See our guide to the
Statement of Applicability. - Implement the controls (2–6 months). The long pole, and the only step
that actually changes your security posture. See
the ISO 27001:2022 controls. - Documentation, competence and awareness (4–6 weeks, overlapping). See
ISO 27001 mandatory documents. - Run the ISMS (3–6 months). Incidents, access reviews, supplier reviews,
monitoring — real records before an audit has anything to sample. - Internal audit, management review, certification. Both are prerequisites. See
internal audit,
stage 1 vs stage 2 and
ISO 27001 certification.
Every document in this plan, already written to the 2022 edition.
The ISO 27001 Toolkit provides 162 editable templates — ISMS policies, the risk assessment method and register, the Statement of Applicability, Annex A control documentation and the full internal audit set.
The three steps ISO 27001 implementation always underestimate
Step 4, the asset inventory. Budgeted as a week, takes a month, and determines
whether the risk assessment is real. An inventory that omits the SaaS tools three departments
expense on cards will produce a risk assessment that misses the actual exposure.
Step 7, implementing controls. This is where ISO 27001 implementation stops
being documentation and starts requiring engineering time, budget and someone telling a team to
change how they work. Plan it as a delivery programme, not a paperwork exercise.
Step 9, running the ISMS. Plans routinely jump from “controls implemented” to
“stage 2” in a fortnight. It cannot work: clause 9.2 needs audit results, 9.3 needs review inputs,
and the auditor will sample access reviews and supplier assessments across a period, not a day.
The Statement of Applicability is where ISO 27001 implementation is judged
Everything converges on the SoA, and auditors read it first. The two failure modes are opposite
and equally common. Declaring all 93 controls applicable when several plainly are not — no
development function, no physical data centre — produces commitments you cannot evidence.
Excluding controls with a one-line justification that does not reference the risk assessment
produces a finding. Every inclusion needs an implementation status; every exclusion needs a reason
that traces back to risk.
A realistic total for ISO 27001 implementation
For a single-entity organisation of fifty to two hundred and fifty people with no existing
certification, six to twelve months from gap analysis to certificate is defensible.
Three to six is achievable for a small SaaS business with mature engineering practice and a narrow
scope. Under three months means step 9 has been skipped, and step 9 is what stage 2 samples.
For cost, see our ISO 27001
cost breakdown, and for sequencing, the ISO 27001
timeline.
References
- ISO/IEC 27001:2022 — the current edition on iso.org.
- ISO/IEC 27001:2022/Amd 1:2024 — the climate action amendment.
Implementation guides for the other standards
- ISO 27001 implementation — you are here
- ISO 9001 implementation
- ISO 13485 implementation
- ISO 14001 implementation
- ISO 45001 implementation
- ISO 22301 implementation
- GDPR implementation
- ISO 42001 implementation
- ISO 20000 implementation
- HIPAA implementation