ISO 27001 Implementation Steps: A 10-Step Guide

The short answer
ISO 27001 implementation steps follow the clauses of ISO/IEC 27001:2022: get a sponsor and run a gap analysis, set the context, interested parties and scope, write the policy and assign roles, define risk criteria and assess risks, choose treatments and build the Statement of Applicability, put the controls and records in place, train people, run an internal audit and a management review, fix the root causes of what they find, and then book the stage 1 and stage 2 certification audits. For a mid-sized organisation that already runs basic IT controls, six to twelve months is common; the standard itself sets no minimum.
Facts about the standard were checked on iso.org on 11 October 2026 (October 2026). This guide paraphrases ISO/IEC 27001 and 27002 and never reproduces their text; anyone implementing them for real should hold a licensed copy.
Which edition is current
ISO's ISO/IEC 27001 page lists the 2022 edition (edition 3, published October 2022) with one amendment, Amendment 1:2024, "Climate action changes". The amendment adds a short climate question to clause 4.1 and a note to 4.2. The transition from the 2013 edition ended on 31 October 2025, so every valid certificate today is against the 2022 edition. Annex A holds 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The guidance for each control is in ISO/IEC 27002:2022.
The ten steps and what each produces
Step | Clause | What you produce |
|---|---|---|
1. Sponsor and gap analysis | All | Business case, project initiation document, gap scores |
2. Context and interested parties | 4.1, 4.2 | Issues register (with the climate question), parties and their requirements |
3. Scope | 4.3 | Documented scope with inclusions, exclusions and interfaces |
4. Leadership, policy and roles | 5.1 to 5.3 | Signed policy, RACI with one accountable owner per activity |
5. Risk assessment | 6.1.2, 8.2 | Risk criteria, risk register with owners and scores |
6. Risk treatment and SoA | 6.1.3, 8.3 | Treatment plan, Statement of Applicability, accepted residual risks |
7. Objectives, controls and records | 6.2, 7, 8.1 | Measurable objectives, controlled documents, evidence that controls ran |
8. Competence and awareness | 7.2, 7.3 | Training records and role profiles |
9. Internal audit and management review | 9.1 to 9.3 | Audit programme and report, review minutes with decisions |
10. Corrective action, then certification | 10.1, 10.2 | Closed nonconformities, then stage 1 and stage 2 |

The order matters. You cannot write a sensible Statement of Applicability before the risk assessment, because its controls are chosen to treat the risks found. And you cannot run a meaningful internal audit until the controls have produced records for a few weeks.
Step 1 worked example: scoring the gap
Score each of clauses 4 to 10 from 0 (nothing exists) to 3 (exists, followed and evidenced). A 120-person software company scored 2, 1, 1, 2, 1, 0 and 0.
- Sum: 2 + 1 + 1 + 2 + 1 + 0 + 0 = 7.
- Maximum: 7 clauses x 3 = 21.
- Readiness: 7 / 21 = 33%.
Clauses 9 and 10 at zero are normal at the start: no internal audit or management review has run yet. They are also the ones a certification body expects to see completed at least once before stage 1, so the plan must leave time for a full audit and review cycle after the controls are in place. A realistic plan for this company runs about 20 weeks: support and gap analysis in weeks 1 to 3, context, scope and policy in weeks 3 to 6, risk and the SoA in weeks 6 to 10, controls and records in weeks 10 to 16, and audit, review and fixes in weeks 16 to 20.
Steps 3 to 5: scope and risk, where projects go wrong
The scope must contain the information you claim to protect. "The server room at head office" is not a credible scope for a firm whose customer data lives in a public cloud platform run by remote developers. Scope the platform, the teams and the identity and endpoint systems that handle the data, and declare the cloud provider as an interface managed under supplier and cloud controls.
For risk, fix the criteria before scoring anything. This guide uses level = likelihood x impact on 5-point scales, with risks at 8 or below acceptable.
Risk | Likelihood | Impact | Level | Decision |
|---|---|---|---|---|
R1 phishing account takeover | 4 | 4 | 16 | Treat first |
R5 ransomware on the file server | 3 | 5 | 15 | Treat |
R2 unencrypted laptop theft | 3 | 4 | 12 | Treat |
R4 insider copies data to USB | 2 | 5 | 10 | Treat |
R3 cloud region outage | 2 | 4 | 8 | Accept, review next time |
R6 office flood | 1 | 3 | 3 | Accept |
Step 6 worked example: residual risk and the SoA
Treatment for R1: phishing-resistant MFA (Annex A 8.5) and awareness training (6.3) cut likelihood from 4 to 2, so the residual level is 2 x 4 = 8, at the threshold and acceptable. For R5: endpoint protection (8.7) cuts likelihood to 2, and tested offline backups (8.13) with an ICT continuity plan (5.30) cut impact to 3, so 2 x 3 = 6. The risk owners sign the acceptance. If a restore test later fails, R5's impact returns to 5, the level becomes 2 x 5 = 10, and the risk needs treatment again.

Each of those controls then gets a Statement of Applicability row that points to R1 or R5 as its justification. "Required by ISO" is not a justification. Point to a risk, a law, a contract or a business need, and record whether each control is implemented, partly implemented, planned or not applicable. If 6 of 93 controls are not applicable, 70 are implemented and 12 partly implemented, then 87 - 70 - 12 = 5 are planned, and 70 / 87 = 80% of applicable controls are fully in place; the 17 open ones need owners and dates.
Steps 9 and 10: audit, review and certification
Internal auditors must be objective and impartial, and nobody audits their own work. Write findings with the requirement, the evidence and the gap: "4 of 20 sampled leavers still had active accounts 3 to 9 days after leaving" is a nonconformity anyone can verify. Fix the instance (correction), then the cause (corrective action), then re-sample to prove the fix worked.
Certification is by an independent certification body, ideally one whose own ISO/IEC 27001 audit work has been checked by a national oversight body; ISO itself certifies nobody. Stage 1 checks the design and readiness, stage 2 checks implementation and effectiveness, and major nonconformities must be closed before the decision. A certificate decided on 15 March 2026 needs its first surveillance audit by 15 March 2027 and expires on 14 March 2029, so book recertification for around December 2028.
ISO 27001 in India: DPDP and customers
Many Indian IT, BPO and SaaS firms implement ISO 27001 because enterprise and overseas customers ask for it in tenders. An ISMS is also a strong way to choose and evidence the security safeguards that India's data protection law expects, but it does not cover consent, notices, data principal rights or breach reporting deadlines on its own. Our DPDP Act compliance checklist covers those duties, and the ISC2 CC exam prep study plan is a good first step if security itself is new to you. For mapping the same controls to NIST CSF 2.0, NIST's Cybersecurity Framework page is the place to start.
Learn the implementation free
The free ISO 27001:2022 Implementation: Build an ISMS course works through every step above in fourteen modules, with worked problems, an ISMS starter-pack project and mappings to GDPR, NIS2, SOC 2 and NIST CSF 2.0. You do not need to buy the standard to follow it.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not a lead implementer or lead auditor credential, and it does not certify any organisation. Start the ISO 27001 implementation course.
For a classroom route that puts topics like this next to PLC programming, see industrial automation course in Bangalore.
Frequently asked questions
Q: What are the steps to implement ISO 27001?
A: Get a sponsor and run a gap analysis; set context, interested parties and scope; write the policy and roles; assess risks against fixed criteria; choose treatments and build the Statement of Applicability; implement controls and keep records; train people; run an internal audit and a management review; fix root causes; then book the stage 1 and stage 2 audits.
Q: How long does ISO 27001 implementation take?
A: Six to twelve months is common for a mid-sized organisation that already runs basic IT controls. The standard sets no minimum, but certification bodies expect at least one internal audit and one management review before stage 1.
Q: Which version of ISO 27001 is current?
A: ISO/IEC 27001:2022 with Amendment 1:2024 (climate action changes). The transition from the 2013 edition ended on 31 October 2025.
Q: How many controls are in ISO 27001 Annex A?
A: 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. Annex A is a cross-check for your risk-based choices, not a list to implement blindly.
Q: What is a Statement of Applicability?
A: The document that lists every Annex A control, says whether it applies, justifies including or excluding it, and records whether it is implemented. Each justification should point to a risk, a law, a contract or a business need.
Q: Is there a free ISO 27001 course with a certificate?
A: Yes. EDWartens' ISO 27001:2022 Implementation course is a free course with a verifiable certificate of completion. It is not a lead implementer or lead auditor credential.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.




