Knowing the ISO 27001 mandatory documents is one of the fastest ways to demystify certification. The standard requires a defined set of documented information, and auditors will expect to see each item. This guide lists the documents ISO 27001 requires, the records that support them, and how to produce them efficiently.

For the wider context, see our complete ISO 27001 guide.
Why documented information matters
ISO 27001 is evidence-based. Your Information Security Management System is judged not by intentions but by the documented information you can produce — policies that set direction, procedures that describe how things are done, and records that prove they were done. Getting this documentation right is the core of a successful certification, which is why a structured template set is so valuable.
The core ISO 27001 mandatory documents
The following documented information is required by ISO 27001:2022 and forms the backbone of your ISMS:
- ISMS scope — the boundaries of your management system.
- Information security policy — top-level direction approved by leadership.
- Information security risk assessment process — how you identify and evaluate risks.
- Information security risk treatment process — how you decide to treat them.
- Statement of Applicability (SoA) — which Annex A controls apply, and why.
- Risk treatment plan — how selected controls will be implemented.
- Information security objectives — measurable goals for the ISMS.
The mandatory records you must keep
Alongside the documents above, ISO 27001 requires records that evidence the ISMS in operation:
- Evidence of competence and training.
- Results of the risk assessment and risk treatment.
- Monitoring and measurement results.
- Internal audit programme and results.
- Management review results.
- Records of nonconformities and corrective actions.
These records demonstrate that the system is not just documented but genuinely working — which is precisely what a Stage 2 audit tests.
Commonly expected supporting documents
While not always strictly mandatory, auditors typically expect supporting policies and procedures such as access control, acceptable use, incident management, business continuity, supplier security, and secure development. These operationalise your Annex A controls. Preparing them upfront avoids gaps during the audit and gives your team clear, usable guidance.
How to produce the documents efficiently
Authoring every policy, procedure, and record from a blank page is the slowest part of ISO 27001. The efficient approach is to start from a mapped template set aligned to the 2022 standard, then tailor each document to your organization. This turns a multi-month documentation project into a structured review-and-adapt exercise, and ensures nothing on the mandatory list is missed.
Every required document, ready to adapt.
Our ISO 27001 Toolkit includes the scope, policy, risk assessment, Statement of Applicability, and every supporting procedure and record — mapped to ISO 27001:2022 and editable in Word and Excel.
Frequently asked questions
What are the ISO 27001 mandatory documents?
They include the ISMS scope, information security policy, risk assessment and risk treatment processes, Statement of Applicability, risk treatment plan, and security objectives — plus mandatory records such as audit and management-review results.
Is the Statement of Applicability mandatory?
Yes. The Statement of Applicability records which Annex A controls you apply and your justification, and it is a central document auditors examine.
How many documents does ISO 27001 require?
There is a defined set of mandatory documents and records, supplemented by the policies and procedures needed to operate your selected Annex A controls — the exact number depends on your scope and risks.