Download this resource
Please enter your details to access the download.
If you run or manage a small business and someone has asked you to get ISO 27001 certified, this checklist is designed for you. Not for an IT department with a dedicated compliance team. Not for a funded startup with a security consultant on retainer. For a business owner, operations manager, or office manager who needs to understand what ISO 27001 actually requires, in plain English, and get it done without losing three months of productivity.
ISO 27001 is the international standard for information security management. It requires you to build and maintain an Information Security Management System (ISMS): a documented, risk-based approach to protecting the information your business holds. The good news is that the standard is designed to be scalable. A 12-person accountancy practice and a 200-person software company can both achieve ISO 27001 certification; the scope and complexity of their systems will look very different, but the requirements of the standard are the same.
This checklist covers every step of the certification journey, from initial scoping through to your certification audit, along with a reference table of the documents ISO 27001 requires you to produce. Use it as a planning tool, a progress tracker, or a briefing document for anyone helping you with the implementation.
Why Small Businesses Are Being Asked for ISO 27001
The most common reason a small business pursues ISO 27001 is because a customer has asked for it, or because a contract they want to win requires it. This is not limited to technology companies. Solicitors handling corporate work, accountancy firms managing client financial data, recruitment agencies holding candidate records, and facilities management companies with building access systems are all being asked by their enterprise clients to demonstrate certified information security.
The pattern is consistent across the UK, Ireland, and increasingly the US: a large organisation reviews its supply chain, identifies third parties who have access to its data or systems, and requires those third parties to demonstrate ISO 27001 certification as a condition of the relationship. For the small business on the receiving end of that request, certification stops being optional and becomes a commercial necessity.
Beyond the customer requirement, there is a genuine operational case. Small businesses are disproportionately affected by data breaches because they typically have fewer recovery resources than large organisations. The process of implementing an ISMS forces a business to identify where its sensitive information actually lives, who has access to it, and what would happen if it were lost, stolen, or compromised. That analysis has value regardless of whether a customer is asking for the certificate.
If you are weighing up whether Cyber Essentials or ISO 27001 is the right starting point for your business, see our full comparison guide.
What ISO 27001 Certification Actually Involves
ISO 27001 certification is awarded by an independent, accredited certification body (registrar) following a formal two-stage audit of your ISMS. Before that audit, you need to build, implement, and operate your management system. The certification body does not help you build it: their role is purely to assess and certify. If you need help building it, that comes from a consultant or from internal resource.
The standard has two parts. Clauses 4 to 10 set out the management system requirements: how you define scope, assess risk, set objectives, manage resources, conduct internal audits, and drive continual improvement. Annex A provides a reference set of 93 information security controls across four themes: organisational controls, people controls, physical controls, and technological controls. You do not have to implement all 93: you conduct a risk assessment, decide which controls are applicable to your situation, and document your reasoning in a Statement of Applicability.
For a small business, the ISMS does not need to be elaborate. An ISMS for a 15-person professional services firm will be significantly simpler than one for a 150-person software company. What matters to the auditor is that the system is proportionate to your risks, genuinely implemented, and producing evidence that it is working.
The 17-Step ISO 27001 Checklist
The checklist below follows the sequence most businesses use to implement ISO 27001. Work through it in order, as each step builds on the previous one. The "Notes for small businesses" column flags where smaller organisations can adopt a leaner approach without compromising the requirements of the standard.
| Step | What you need to do | Notes for small businesses |
|---|---|---|
| 1 | Define your ISMS scope | Be precise but realistic. Scope can cover your whole organisation or specific services or locations. Starting narrow is acceptable; you can extend scope at recertification. |
| 2 | Conduct a gap analysis against ISO 27001:2022 | Assess what you already have in place versus what the standard requires. Most small businesses find they have reasonable security practices but limited documentation. This step shapes your implementation plan. |
| 3 | Appoint an ISMS owner | Someone internal must own the management system. In a small business, this is often the owner, operations manager, or a senior administrator. Formal security expertise is useful but not required: process discipline matters more. |
| 4 | Secure leadership commitment | The standard requires top management to be visibly engaged. In a small business, this is often straightforward since leadership and ownership overlap. Produce a signed information security policy and keep minutes of any management discussions about the ISMS. |
| 5 | Conduct your information security risk assessment | Identify the information your business holds, the threats and vulnerabilities that could affect it, and the likelihood and potential impact of each risk. A risk register does not need to be complex: a well-structured spreadsheet is sufficient for most small businesses. |
| 6 | Produce your risk treatment plan | For each significant risk, decide how you will address it: implement a control, transfer the risk (e.g. via insurance), accept it with justification, or avoid it by changing the activity. Document your decisions. |
| 7 | Complete your Statement of Applicability (SoA) | The SoA lists all 93 Annex A controls, states whether each is applicable to your organisation, and justifies any exclusions. This is one of the central documents your auditor will review. There is no shortcut: every control must be addressed. |
| 8 | Implement your information security policies | Write and implement the core policies your ISMS requires. These do not need to be long. A concise, accurate five-page policy is more valuable than a generic fifty-page one that does not reflect how your business actually operates. |
| 9 | Implement the controls from your risk treatment plan | Put the technical and organisational controls in place: multi-factor authentication, access reviews, backup testing, supplier assessments, staff briefings, and so on. These controls must be operating and producing evidence before your Stage 2 audit. |
| 10 | Train and brief all staff | Every person with access to information covered by your ISMS scope needs to be aware of the information security policy and their responsibilities. Keep records of briefings and training delivered. |
| 11 | Conduct your internal audit | A full internal audit of your ISMS covering all clauses of the standard is required before certification. The auditor must be independent of the areas being audited. In a small business, this often means using an external auditor or a trusted colleague from a different function. |
| 12 | Hold a management review meeting | A formal management review is required before the certification audit. It must cover ISMS performance, risk status, audit findings, objectives progress, and resource needs. Keep clear minutes recording what was discussed and any actions agreed. |
| 13 | Address internal audit findings | Any nonconformities raised during your internal audit must be addressed before the Stage 2 certification audit. Raise corrective actions, conduct root cause analysis, and retain evidence that the actions have been effective. |
| 14 | Choose an accredited certification body and book Stage 1 | Select a certification body accredited for ISO 27001 by a recognised national accreditation body. In the UK, look for UKAS accreditation. In Ireland, INAB. In the US, ANAB or IAS. Certificates from non-accredited bodies are not accepted by most enterprise procurement teams. |
| 15 | Stage 1 audit (documentation review) | Your certification body reviews your ISMS documentation and confirms you are ready to proceed to Stage 2. Any gaps identified at Stage 1 must be addressed before Stage 2 can be scheduled. |
| 16 | Stage 2 audit (certification assessment) | The full certification audit. Your auditor assesses whether your ISMS is effectively implemented in practice, interviews staff, reviews records, and checks that controls are operating. If successful, your certificate is issued. |
| 17 | Maintain and improve | ISO 27001 certificates are valid for three years, subject to annual surveillance audits. Continue running internal audits, management reviews, and risk assessments. Review and update your SoA whenever there are significant changes to your organisation or its risks. |
Step 2 of the checklist above is one of the highest-leverage activities. Our full gap analysis guide explains how to conduct a gap analysis, what to look for, and how to use the results to build your implementation plan.
ISO 27001 Mandatory Documents: What You Need to Produce
One of the most common sources of confusion for small businesses is understanding which documents ISO 27001 actually requires. The list below covers the mandatory documents and records specified in ISO 27001:2022, along with commonly recommended additions that most auditors will expect to see. All references reflect the 2022 version of the standard.
| Document or record | Mandatory? | Notes |
|---|---|---|
| ISMS scope document | Yes | Defines which parts of your organisation, which systems, and which information are covered. |
| Information security policy | Yes | High-level statement of your organisation''s commitment to information security, signed by top management. |
| Risk assessment methodology document | Yes | Explains how you identify, assess, and prioritise information security risks. |
| Risk register (risk assessment results) | Yes | Records the risks you have identified, their assessment, and treatment decisions. |
| Risk treatment plan | Yes | Details the controls you will implement, timelines, and responsible owners for each risk. |
| Statement of Applicability (SoA) | Yes | Lists all 93 Annex A controls with applicability decisions and justifications for exclusions. |
| Information security objectives | Yes | Measurable targets for the ISMS with named owners and tracking methods. |
| Competence records and training records | Yes | Evidence that staff with security responsibilities are competent and have received appropriate training. |
| Documented information control procedure | Yes | Explains how ISMS documents are created, approved, updated, and controlled. |
| Operational planning and control records | Yes | Evidence that processes are planned and carried out as documented. |
| Internal audit programme and reports | Yes | Schedule, plan, and findings from your internal audit cycle. |
| Management review minutes | Yes | Records of management review meetings including inputs, decisions, and actions. |
| Nonconformity and corrective action records | Yes | Log of any nonconformities identified and evidence of corrective actions taken. |
| Asset inventory (information asset register) | Recommended | Not explicitly mandated but expected by most auditors. Lists information assets, owners, and classifications. |
| Access control policy | Recommended | Annex A control A.5.15. Defines who has access to what and on what basis. |
| Acceptable use policy | Recommended | Annex A control A.5.10. Covers how staff should use information and IT systems. |
| Cryptography policy | Recommended | Annex A control A.8.24. Covers use of encryption for data in transit and at rest. |
| Supplier security policy and supplier records | Recommended | Annex A controls A.5.19 to A.5.22. Covers how third parties with access to your data are managed. |
| Incident management records | Recommended | Annex A control A.5.26. Records of information security incidents and how they were handled. |
| Business continuity and backup records | Recommended | Annex A controls A.8.13 and A.5.29. Evidence of backup procedures and recovery testing. |
A note on document length: the 2022 version of ISO 27001 does not prescribe how long your documents should be. A concise, accurate policy that reflects how your business actually operates is more valuable than a lengthy generic document. For a small business with straightforward operations, most core policy documents can be covered in two to four pages each.
Compliance software can help small businesses manage their ISMS documentation, risk register, and audit evidence in one place. Our buyers guide compares the main options available.
Common Mistakes Small Businesses Make
Using generic template documents without adapting them
Template policies are a useful starting point, but they must reflect your actual organisation. If your business does not use biometric access control, your access control policy should not mention it. An auditor who finds a significant mismatch between your documented policies and your actual operations will raise nonconformities regardless of how well the template was written.
Treating the SoA as a formality
The Statement of Applicability is one of the most scrutinised documents in an ISO 27001 audit. Every exclusion must be justified, and every included control must be demonstrably implemented. Many small businesses fill in the SoA quickly, mark most controls as applicable without implementing them, and then fail the audit as a result. Completing the SoA properly takes time, but it is the correct time to invest.
Underestimating the evidence requirement
ISO 27001 auditors do not take your word for it that controls are in place: they look for evidence. Access reviews must have completion records. Backup tests must have logs. Staff briefings must have sign-off records. Training must be documented. Building the habit of capturing evidence as you go, rather than reconstructing it before an audit, is one of the most important disciplines in maintaining a small business ISMS. Our audit preparation guide covers this in detail.
Leaving insufficient time before the certification audit
Your ISMS needs to be operating for a meaningful period before the Stage 2 audit. Most certification bodies want to see at least three months of operating evidence: completed access reviews, incident logs, management meeting minutes. Businesses that build the system and immediately book their audit often find they cannot demonstrate that the system is genuinely operational.
Choosing a non-accredited certification body
Several organisations offer ISO 27001 certification at low cost with very short timelines. These are typically not accredited by a recognised national body and their certificates are not accepted by enterprise procurement teams. In the UK, always verify UKAS accreditation before engaging a certification body. In Ireland, check for INAB accreditation. In the US, look for ANAB or IAS accreditation. Our UKAS vs ASCB guide explains the difference and why it matters for procurement.
Cost and Timeline for Small Business ISO 27001 Certification
Timeline
For a small business with fewer than 30 staff, a realistic certification timeline from starting implementation to receiving the certificate is four to nine months. The wide range reflects variation in starting position (how much security practice is already in place), available internal resource, and whether external consultancy is used. The risk assessment and Statement of Applicability phases are consistently the most time-consuming, and the need to gather operating evidence before the certification audit adds unavoidable time to the process.
Cost
Certification costs for a small business fall into two categories. Certification body fees for a small organisation are typically in the range of £2,500 to £6,000 for the initial Stage 1 and Stage 2 audits, with annual surveillance audit fees of £1,200 to £2,500 thereafter. Implementation costs depend heavily on whether you use a consultant: a full-service consultant engagement for a small business typically costs £4,000 to £12,000, while a targeted engagement covering only the gap analysis and risk assessment might cost £1,500 to £4,000. Self-implementation without a consultant reduces direct costs significantly but requires a greater investment of internal time.
Use the ISOCentral cost calculator to get a tailored estimate of your ISO 27001 certification costs based on your organisation''s size and scope.
Do You Need a Consultant?
ISO 27001 does not require you to use a consultant, and small businesses with a technically capable team member and a methodical approach can self-implement. However, the risk assessment and Statement of Applicability are genuinely complex for first-time implementers, and getting them wrong creates problems that are expensive to fix once the system is built on top of them.
The targeted support model tends to work well for small businesses: use a consultant for the gap analysis, risk assessment, and SoA, then manage the policy documentation, implementation, and internal audit in-house. This captures the highest-value external expertise while keeping overall consultant spend proportionate to the scale of the business.
If you do use a consultant, look for one with demonstrable ISO 27001 experience, preferably IRCA-registered as a lead auditor, and ask specifically about their experience with organisations of your size and sector. A consultant who primarily works with large enterprises or technology companies may not be the best fit for a small professional services firm or a family-owned business.
Browse the ISOCentral consultant directory to find and compare independent ISO 27001 consultants, including details of their sector experience and the standards they work with.
Is This the Right Checklist for a Technology or SaaS Company?
This checklist is written for traditional small businesses: professional services firms, non-technical SMEs, and organisations without a dedicated IT or security function. If your business is a SaaS company, a software development firm, or a technology-native organisation with cloud infrastructure, development environments, and technical security controls to manage, a different framing applies.
Our dedicated guide for SaaS and technology companies covers cloud infrastructure scoping, access control, secure development, the ISO 27001 vs SOC 2 decision, and a realistic implementation timeline for a cloud-native business.
Finding an Accredited Certification Body
The choice of certification body matters more than many small businesses realise. Beyond accreditation status, it is worth checking whether the body has auditors with experience in your sector. An auditor who has certified other professional services firms or businesses of a similar size will conduct a more useful audit and ask more relevant questions than a generalist auditor working from the standard alone.
Most certification bodies will provide a quote on request based on your employee headcount and ISMS scope. It is worth getting two or three quotes before committing, as fee structures vary meaningfully between bodies. Confirm UKAS accreditation (UK), INAB accreditation (Ireland), or ANAB or IAS accreditation (US) before signing any contract.
Use the ISOCentral registrar directory to find and compare accredited certification bodies for ISO 27001, with details of their sector experience and geographic coverage. New to ISO certification? Our guide on what a registrar does explains how to choose one and the difference between accredited and non-accredited certification bodies.
