ISO 27001 Readiness: A Practical Checklist for Growing Companies

ISO 27001 is the international standard for Information Security Management Systems. It sets out what an organization has to do to manage the security of sensitive information in a systematic way, whether that's employee data, financial records, or customer contracts. For a growing B2B company, the push for ISO 27001 certification usually comes from one of two places. Either an enterprise customer makes it a condition of a contract, or an internal risk review flags it as overdue.

Certification requires an external audit. What that audit turns up, and how painful the whole thing feels, depends almost entirely on how much groundwork you've laid before the auditor shows up. This checklist covers the key areas to sort out in the months before you start a formal certification engagement.

Organizational controls

  • Information security policy written, approved by management, and distributed to all staff
  • Roles and responsibilities for information security clearly defined and documented
  • Asset inventory covering all information assets (systems, data, physical devices) maintained and up to date
  • Risk assessment methodology documented and risk register completed
  • Statement of Applicability (SoA) listing which ISO 27001 Annex A controls are applicable and why
  • Supplier and third-party risk assessment process in place for vendors with access to your systems or data
  • Incident response plan documented, tested, and assigned to named individuals

People controls

  • Security awareness training completed by all staff, with records kept
  • Background screening process in place for new hires in sensitive roles
  • Acceptable use policy for company systems and data signed by all employees
  • Onboarding and offboarding checklists that include system access provisioning and revocation
  • Confidentiality agreements (NDAs) signed by employees and contractors with data access

Technical controls

  • Multi-factor authentication enforced for all remote access and admin accounts
  • Least-privilege access implemented, so users have only the access they actually need
  • Patch management process documented with defined SLAs for critical patches
  • Encryption at rest and in transit for sensitive data
  • Logging and monitoring in place for key systems with log retention of at least 12 months
  • Vulnerability scanning run on a regular cadence with results tracked and remediated
  • Network segmentation separating critical systems from general corporate traffic
  • Backup and recovery process tested, meaning not just running but verified to actually restore

Physical and environmental controls

  • Physical access controls to office spaces and server rooms documented
  • Clear desk and clear screen policy in place for workstations handling sensitive data
  • Equipment disposal process that includes secure data wiping

The most common audit finding for growing companies isn't missing technical controls. It's missing documentation. The controls are usually there, but nobody wrote down how they work, who owns them, or when they were last reviewed. An auditor needs evidence, and evidence means records. Start building your documentation library early.

Before you begin the formal audit

Once you've worked through this checklist, run an internal audit against the ISO 27001 standard before you engage an external certifying body. This is called a gap analysis. It surfaces the areas where you're not yet compliant, which gives your team time to fix them before the formal audit begins. A pre-audit security assessment, the kind we described in our article on what a real security audit looks like, is one of the most efficient ways to work through that gap analysis.

The formal certification process runs in two stages: a documentation review (Stage 1) and an on-site audit of how the controls are actually implemented (Stage 2). Pass Stage 2 and you get your certificate. Keeping it means annual surveillance audits, plus a full recertification every three years.

At MSAI Systems, we're building security audit tooling that plugs into compliance frameworks including ISO 27001, so companies can track their readiness continuously instead of scrambling to prepare for an annual audit. Get in touch with our team.

Back to blog
Keep reading