Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.
How to use this checklist
Each item is phrased as something that is done or in place. Tick it only when you could show the evidence: a document, a record or a configuration. If you would have to explain why it is nearly done, leave it unticked.
- Agree the scope of the ISMS first. Every item is judged within it.
- Work through clauses 4 to 10 in order. They are requirements, and none of them can be left out.
- Use the Annex A groups as a sample of controls most organisations need. The full list of 93 is in the controls guide; which ones you need follows from your risk assessment.
- Where an item links a free tool, the tool checks part of it from the outside. The rest still needs your own records.
The checklist
0 of 60 done
Your ticks are kept in this browser only.
Clause 4: Context of the organisation
Clause 5: Leadership
Clause 6: Planning
Clause 7: Support
Clause 8: Operation
Clause 9: Performance evaluation
Clause 10: Improvement
Annex A: Organisational controls
A sample from 5.1 to 5.37. Include each one that your risk assessment calls for.
Annex A: People controls
A sample from 6.1 to 6.8.
Annex A: Physical controls
A sample from 7.1 to 7.14. Remote-first organisations still have equipment at home and on the move.
Annex A: Technological controls
A sample from 8.1 to 8.34. The free tools check the public side of some items; internal systems need your own evidence.
What to do with the gaps
Every unticked item is a gap. Give each one an owner, a target date and a definition of done that names the evidence it will produce. The gap analysis guide has a rating scale and a way to prioritise them.
- Close the foundations first: scope, policy, roles and the risk method in clauses 4 to 6. Most other items depend on them.
- Finish the risk assessment and the Statement of Applicability before deciding which Annex A gaps matter.
- Fix internet-facing technical gaps early. They are quick to check and to confirm fixed, and they are what attackers see first.
- Keep records from the start, so that by the internal audit and management review the ISMS has a track record. The gap analysis guide covers which evidence to collect.
Evidence for this checklist
Ironfang can check
- Dated results for the public side of the items that link a tool: certificate transparency, email authentication, end-of-life software, website configuration, TLS and, for verified domains, exposed services
- Rechecks that show when a finding was fixed, and notices when monitored configuration changes
The organisation must establish
- Every item in clauses 4 to 10
- Policies, owners, decisions and records for every Annex A control, including those with a public side
- Everything not visible from the internet
Sources
Checked on the review date above. Standards and schemes change; the source is the authority.
- ISO/IEC 27001:2022, Information security management systems: Requirements (ISO)
- ISO/IEC 27001:2022/Amd 1:2024, Climate action changes (IEC Webstore)
- IAF/ISO Joint Communiqué on the addition of climate change considerations to management systems standards, February 2024 (IAF)
- ISO/IEC 27002:2022, Information security controls (ISO)

