Back to Resources
    Downloads
    ISO 27001

    ISO 27001 Certification Checklist for Small Businesses

    ByEditor·
    Share:
    ISO 27001 Certification Checklist for Small Businesses

    Download this resource

    Please enter your details to access the download.

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

    If you run or manage a small business and someone has asked you to get ISO 27001 certified, this checklist is designed for you. Not for an IT department with a dedicated compliance team. Not for a funded startup with a security consultant on retainer. For a business owner, operations manager, or office manager who needs to understand what ISO 27001 actually requires, in plain English, and get it done without losing three months of productivity.

    ISO 27001 is the international standard for information security management. It requires you to build and maintain an Information Security Management System (ISMS): a documented, risk-based approach to protecting the information your business holds. The good news is that the standard is designed to be scalable. A 12-person accountancy practice and a 200-person software company can both achieve ISO 27001 certification; the scope and complexity of their systems will look very different, but the requirements of the standard are the same.

    This checklist covers every step of the certification journey, from initial scoping through to your certification audit, along with a reference table of the documents ISO 27001 requires you to produce. Use it as a planning tool, a progress tracker, or a briefing document for anyone helping you with the implementation.

    Why Small Businesses Are Being Asked for ISO 27001

    The most common reason a small business pursues ISO 27001 is because a customer has asked for it, or because a contract they want to win requires it. This is not limited to technology companies. Solicitors handling corporate work, accountancy firms managing client financial data, recruitment agencies holding candidate records, and facilities management companies with building access systems are all being asked by their enterprise clients to demonstrate certified information security.

    The pattern is consistent across the UK, Ireland, and increasingly the US: a large organisation reviews its supply chain, identifies third parties who have access to its data or systems, and requires those third parties to demonstrate ISO 27001 certification as a condition of the relationship. For the small business on the receiving end of that request, certification stops being optional and becomes a commercial necessity.

    Beyond the customer requirement, there is a genuine operational case. Small businesses are disproportionately affected by data breaches because they typically have fewer recovery resources than large organisations. The process of implementing an ISMS forces a business to identify where its sensitive information actually lives, who has access to it, and what would happen if it were lost, stolen, or compromised. That analysis has value regardless of whether a customer is asking for the certificate.

    If you are weighing up whether Cyber Essentials or ISO 27001 is the right starting point for your business, see our full comparison guide.

    What ISO 27001 Certification Actually Involves

    ISO 27001 certification is awarded by an independent, accredited certification body (registrar) following a formal two-stage audit of your ISMS. Before that audit, you need to build, implement, and operate your management system. The certification body does not help you build it: their role is purely to assess and certify. If you need help building it, that comes from a consultant or from internal resource.

    The standard has two parts. Clauses 4 to 10 set out the management system requirements: how you define scope, assess risk, set objectives, manage resources, conduct internal audits, and drive continual improvement. Annex A provides a reference set of 93 information security controls across four themes: organisational controls, people controls, physical controls, and technological controls. You do not have to implement all 93: you conduct a risk assessment, decide which controls are applicable to your situation, and document your reasoning in a Statement of Applicability.

    For a small business, the ISMS does not need to be elaborate. An ISMS for a 15-person professional services firm will be significantly simpler than one for a 150-person software company. What matters to the auditor is that the system is proportionate to your risks, genuinely implemented, and producing evidence that it is working.

    The 17-Step ISO 27001 Checklist

    The checklist below follows the sequence most businesses use to implement ISO 27001. Work through it in order, as each step builds on the previous one. The "Notes for small businesses" column flags where smaller organisations can adopt a leaner approach without compromising the requirements of the standard.

    StepWhat you need to doNotes for small businesses
    1Define your ISMS scopeBe precise but realistic. Scope can cover your whole organisation or specific services or locations. Starting narrow is acceptable; you can extend scope at recertification.
    2Conduct a gap analysis against ISO 27001:2022Assess what you already have in place versus what the standard requires. Most small businesses find they have reasonable security practices but limited documentation. This step shapes your implementation plan.
    3Appoint an ISMS ownerSomeone internal must own the management system. In a small business, this is often the owner, operations manager, or a senior administrator. Formal security expertise is useful but not required: process discipline matters more.
    4Secure leadership commitmentThe standard requires top management to be visibly engaged. In a small business, this is often straightforward since leadership and ownership overlap. Produce a signed information security policy and keep minutes of any management discussions about the ISMS.
    5Conduct your information security risk assessmentIdentify the information your business holds, the threats and vulnerabilities that could affect it, and the likelihood and potential impact of each risk. A risk register does not need to be complex: a well-structured spreadsheet is sufficient for most small businesses.
    6Produce your risk treatment planFor each significant risk, decide how you will address it: implement a control, transfer the risk (e.g. via insurance), accept it with justification, or avoid it by changing the activity. Document your decisions.
    7Complete your Statement of Applicability (SoA)The SoA lists all 93 Annex A controls, states whether each is applicable to your organisation, and justifies any exclusions. This is one of the central documents your auditor will review. There is no shortcut: every control must be addressed.
    8Implement your information security policiesWrite and implement the core policies your ISMS requires. These do not need to be long. A concise, accurate five-page policy is more valuable than a generic fifty-page one that does not reflect how your business actually operates.
    9Implement the controls from your risk treatment planPut the technical and organisational controls in place: multi-factor authentication, access reviews, backup testing, supplier assessments, staff briefings, and so on. These controls must be operating and producing evidence before your Stage 2 audit.
    10Train and brief all staffEvery person with access to information covered by your ISMS scope needs to be aware of the information security policy and their responsibilities. Keep records of briefings and training delivered.
    11Conduct your internal auditA full internal audit of your ISMS covering all clauses of the standard is required before certification. The auditor must be independent of the areas being audited. In a small business, this often means using an external auditor or a trusted colleague from a different function.
    12Hold a management review meetingA formal management review is required before the certification audit. It must cover ISMS performance, risk status, audit findings, objectives progress, and resource needs. Keep clear minutes recording what was discussed and any actions agreed.
    13Address internal audit findingsAny nonconformities raised during your internal audit must be addressed before the Stage 2 certification audit. Raise corrective actions, conduct root cause analysis, and retain evidence that the actions have been effective.
    14Choose an accredited certification body and book Stage 1Select a certification body accredited for ISO 27001 by a recognised national accreditation body. In the UK, look for UKAS accreditation. In Ireland, INAB. In the US, ANAB or IAS. Certificates from non-accredited bodies are not accepted by most enterprise procurement teams.
    15Stage 1 audit (documentation review)Your certification body reviews your ISMS documentation and confirms you are ready to proceed to Stage 2. Any gaps identified at Stage 1 must be addressed before Stage 2 can be scheduled.
    16Stage 2 audit (certification assessment)The full certification audit. Your auditor assesses whether your ISMS is effectively implemented in practice, interviews staff, reviews records, and checks that controls are operating. If successful, your certificate is issued.
    17Maintain and improveISO 27001 certificates are valid for three years, subject to annual surveillance audits. Continue running internal audits, management reviews, and risk assessments. Review and update your SoA whenever there are significant changes to your organisation or its risks.

    Step 2 of the checklist above is one of the highest-leverage activities. Our full gap analysis guide explains how to conduct a gap analysis, what to look for, and how to use the results to build your implementation plan.

    ISO 27001 Mandatory Documents: What You Need to Produce

    One of the most common sources of confusion for small businesses is understanding which documents ISO 27001 actually requires. The list below covers the mandatory documents and records specified in ISO 27001:2022, along with commonly recommended additions that most auditors will expect to see. All references reflect the 2022 version of the standard.

    Document or recordMandatory?Notes
    ISMS scope documentYesDefines which parts of your organisation, which systems, and which information are covered.
    Information security policyYesHigh-level statement of your organisation''s commitment to information security, signed by top management.
    Risk assessment methodology documentYesExplains how you identify, assess, and prioritise information security risks.
    Risk register (risk assessment results)YesRecords the risks you have identified, their assessment, and treatment decisions.
    Risk treatment planYesDetails the controls you will implement, timelines, and responsible owners for each risk.
    Statement of Applicability (SoA)YesLists all 93 Annex A controls with applicability decisions and justifications for exclusions.
    Information security objectivesYesMeasurable targets for the ISMS with named owners and tracking methods.
    Competence records and training recordsYesEvidence that staff with security responsibilities are competent and have received appropriate training.
    Documented information control procedureYesExplains how ISMS documents are created, approved, updated, and controlled.
    Operational planning and control recordsYesEvidence that processes are planned and carried out as documented.
    Internal audit programme and reportsYesSchedule, plan, and findings from your internal audit cycle.
    Management review minutesYesRecords of management review meetings including inputs, decisions, and actions.
    Nonconformity and corrective action recordsYesLog of any nonconformities identified and evidence of corrective actions taken.
    Asset inventory (information asset register)RecommendedNot explicitly mandated but expected by most auditors. Lists information assets, owners, and classifications.
    Access control policyRecommendedAnnex A control A.5.15. Defines who has access to what and on what basis.
    Acceptable use policyRecommendedAnnex A control A.5.10. Covers how staff should use information and IT systems.
    Cryptography policyRecommendedAnnex A control A.8.24. Covers use of encryption for data in transit and at rest.
    Supplier security policy and supplier recordsRecommendedAnnex A controls A.5.19 to A.5.22. Covers how third parties with access to your data are managed.
    Incident management recordsRecommendedAnnex A control A.5.26. Records of information security incidents and how they were handled.
    Business continuity and backup recordsRecommendedAnnex A controls A.8.13 and A.5.29. Evidence of backup procedures and recovery testing.

    A note on document length: the 2022 version of ISO 27001 does not prescribe how long your documents should be. A concise, accurate policy that reflects how your business actually operates is more valuable than a lengthy generic document. For a small business with straightforward operations, most core policy documents can be covered in two to four pages each.

    Compliance software can help small businesses manage their ISMS documentation, risk register, and audit evidence in one place. Our buyers guide compares the main options available.

    Common Mistakes Small Businesses Make

    Using generic template documents without adapting them

    Template policies are a useful starting point, but they must reflect your actual organisation. If your business does not use biometric access control, your access control policy should not mention it. An auditor who finds a significant mismatch between your documented policies and your actual operations will raise nonconformities regardless of how well the template was written.

    Treating the SoA as a formality

    The Statement of Applicability is one of the most scrutinised documents in an ISO 27001 audit. Every exclusion must be justified, and every included control must be demonstrably implemented. Many small businesses fill in the SoA quickly, mark most controls as applicable without implementing them, and then fail the audit as a result. Completing the SoA properly takes time, but it is the correct time to invest.

    Underestimating the evidence requirement

    ISO 27001 auditors do not take your word for it that controls are in place: they look for evidence. Access reviews must have completion records. Backup tests must have logs. Staff briefings must have sign-off records. Training must be documented. Building the habit of capturing evidence as you go, rather than reconstructing it before an audit, is one of the most important disciplines in maintaining a small business ISMS. Our audit preparation guide covers this in detail.

    Leaving insufficient time before the certification audit

    Your ISMS needs to be operating for a meaningful period before the Stage 2 audit. Most certification bodies want to see at least three months of operating evidence: completed access reviews, incident logs, management meeting minutes. Businesses that build the system and immediately book their audit often find they cannot demonstrate that the system is genuinely operational.

    Choosing a non-accredited certification body

    Several organisations offer ISO 27001 certification at low cost with very short timelines. These are typically not accredited by a recognised national body and their certificates are not accepted by enterprise procurement teams. In the UK, always verify UKAS accreditation before engaging a certification body. In Ireland, check for INAB accreditation. In the US, look for ANAB or IAS accreditation. Our UKAS vs ASCB guide explains the difference and why it matters for procurement.

    Cost and Timeline for Small Business ISO 27001 Certification

    Timeline

    For a small business with fewer than 30 staff, a realistic certification timeline from starting implementation to receiving the certificate is four to nine months. The wide range reflects variation in starting position (how much security practice is already in place), available internal resource, and whether external consultancy is used. The risk assessment and Statement of Applicability phases are consistently the most time-consuming, and the need to gather operating evidence before the certification audit adds unavoidable time to the process.

    Cost

    Certification costs for a small business fall into two categories. Certification body fees for a small organisation are typically in the range of £2,500 to £6,000 for the initial Stage 1 and Stage 2 audits, with annual surveillance audit fees of £1,200 to £2,500 thereafter. Implementation costs depend heavily on whether you use a consultant: a full-service consultant engagement for a small business typically costs £4,000 to £12,000, while a targeted engagement covering only the gap analysis and risk assessment might cost £1,500 to £4,000. Self-implementation without a consultant reduces direct costs significantly but requires a greater investment of internal time.

    Use the ISOCentral cost calculator to get a tailored estimate of your ISO 27001 certification costs based on your organisation''s size and scope.

    Do You Need a Consultant?

    ISO 27001 does not require you to use a consultant, and small businesses with a technically capable team member and a methodical approach can self-implement. However, the risk assessment and Statement of Applicability are genuinely complex for first-time implementers, and getting them wrong creates problems that are expensive to fix once the system is built on top of them.

    The targeted support model tends to work well for small businesses: use a consultant for the gap analysis, risk assessment, and SoA, then manage the policy documentation, implementation, and internal audit in-house. This captures the highest-value external expertise while keeping overall consultant spend proportionate to the scale of the business.

    If you do use a consultant, look for one with demonstrable ISO 27001 experience, preferably IRCA-registered as a lead auditor, and ask specifically about their experience with organisations of your size and sector. A consultant who primarily works with large enterprises or technology companies may not be the best fit for a small professional services firm or a family-owned business.

    Browse the ISOCentral consultant directory to find and compare independent ISO 27001 consultants, including details of their sector experience and the standards they work with.

    Is This the Right Checklist for a Technology or SaaS Company?

    This checklist is written for traditional small businesses: professional services firms, non-technical SMEs, and organisations without a dedicated IT or security function. If your business is a SaaS company, a software development firm, or a technology-native organisation with cloud infrastructure, development environments, and technical security controls to manage, a different framing applies.

    Our dedicated guide for SaaS and technology companies covers cloud infrastructure scoping, access control, secure development, the ISO 27001 vs SOC 2 decision, and a realistic implementation timeline for a cloud-native business.

    Finding an Accredited Certification Body

    The choice of certification body matters more than many small businesses realise. Beyond accreditation status, it is worth checking whether the body has auditors with experience in your sector. An auditor who has certified other professional services firms or businesses of a similar size will conduct a more useful audit and ask more relevant questions than a generalist auditor working from the standard alone.

    Most certification bodies will provide a quote on request based on your employee headcount and ISMS scope. It is worth getting two or three quotes before committing, as fee structures vary meaningfully between bodies. Confirm UKAS accreditation (UK), INAB accreditation (Ireland), or ANAB or IAS accreditation (US) before signing any contract.

    Use the ISOCentral registrar directory to find and compare accredited certification bodies for ISO 27001, with details of their sector experience and geographic coverage. New to ISO certification? Our guide on what a registrar does explains how to choose one and the difference between accredited and non-accredited certification bodies.

    Frequently Asked Questions

    Can a small business get ISO 27001 certified?
    Yes. ISO 27001 is designed to be applicable to organisations of any size, and the standard explicitly states that the ISMS should be proportionate to the organisation's context and risk profile. Many small businesses with fewer than 20 employees hold ISO 27001 certification. The management system for a small business will be significantly simpler than that of a large organisation, but the requirements of the standard and the certification process are the same.
    What documents does ISO 27001 require?
    ISO 27001:2022 mandates a defined set of documents and records, including: an ISMS scope document, information security policy, risk assessment methodology, risk register, risk treatment plan, Statement of Applicability, information security objectives, competence and training records, internal audit programme and reports, management review minutes, and nonconformity and corrective action records. Additionally, most auditors will expect to see key security policies covering access control, acceptable use, cryptography, supplier management, and incident handling, even though these are not explicitly listed as mandatory in the standard itself.
    How long does ISO 27001 take for a small business?
    For a small business with fewer than 30 staff, ISO 27001 certification realistically takes between four and nine months from starting implementation to receiving the certificate. The risk assessment and Statement of Applicability are the most time-consuming activities, and the timeline depends heavily on your starting position and whether you use a consultant. Small businesses also need to allow time for their ISMS to be operating before the Stage 2 certification audit, as auditors expect to see at least two to three months of operating evidence including completed access reviews, training records, and incident logs.
    What is the Statement of Applicability in ISO 27001?
    The Statement of Applicability (SoA) is a mandatory document that lists all 93 controls from Annex A of ISO 27001:2022, states whether each control is applicable to your organisation, and provides justification for any that you have excluded. It is the bridge between your risk assessment and your implemented controls, and it is one of the documents most closely scrutinised by certification body auditors. For a small business, the SoA also serves as a useful ongoing reference for understanding which controls your ISMS relies on and why.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.