Skip to content

Checklist

ISO 27001 checklist

A working checklist for an ISO/IEC 27001:2022 information security management system: every clause from 4 to 10, then a short set of Annex A controls in each theme. Tick items as they are done.

Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.

How to use this checklist

Each item is phrased as something that is done or in place. Tick it only when you could show the evidence: a document, a record or a configuration. If you would have to explain why it is nearly done, leave it unticked.

  • Agree the scope of the ISMS first. Every item is judged within it.
  • Work through clauses 4 to 10 in order. They are requirements, and none of them can be left out.
  • Use the Annex A groups as a sample of controls most organisations need. The full list of 93 is in the controls guide; which ones you need follows from your risk assessment.
  • Where an item links a free tool, the tool checks part of it from the outside. The rest still needs your own records.

The checklist

0 of 60 done

Your ticks are kept in this browser only.

Clause 4: Context of the organisation

Clause 5: Leadership

Clause 6: Planning

Clause 7: Support

Clause 8: Operation

Clause 9: Performance evaluation

Clause 10: Improvement

Annex A: Organisational controls

A sample from 5.1 to 5.37. Include each one that your risk assessment calls for.

  • Free tool: Subdomain finder
  • Free tool: Email security checker

Annex A: People controls

A sample from 6.1 to 6.8.

Annex A: Physical controls

A sample from 7.1 to 7.14. Remote-first organisations still have equipment at home and on the move.

Annex A: Technological controls

A sample from 8.1 to 8.34. The free tools check the public side of some items; internal systems need your own evidence.

  • Free tool: End-of-life software checker
  • Free tool: Website security checker
  • Free tool: Exposed services checker
  • Free tool: SSL/TLS checker
  • Free tool: HTTP security headers checker

What to do with the gaps

Every unticked item is a gap. Give each one an owner, a target date and a definition of done that names the evidence it will produce. The gap analysis guide has a rating scale and a way to prioritise them.

  1. Close the foundations first: scope, policy, roles and the risk method in clauses 4 to 6. Most other items depend on them.
  2. Finish the risk assessment and the Statement of Applicability before deciding which Annex A gaps matter.
  3. Fix internet-facing technical gaps early. They are quick to check and to confirm fixed, and they are what attackers see first.
  4. Keep records from the start, so that by the internal audit and management review the ISMS has a track record. The gap analysis guide covers which evidence to collect.

Evidence for this checklist

Ironfang can check

  • Dated results for the public side of the items that link a tool: certificate transparency, email authentication, end-of-life software, website configuration, TLS and, for verified domains, exposed services
  • Rechecks that show when a finding was fixed, and notices when monitored configuration changes

The organisation must establish

  • Every item in clauses 4 to 10
  • Policies, owners, decisions and records for every Annex A control, including those with a public side
  • Everything not visible from the internet

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.