Implementation Project
/
Project Plan

Implementation Project

var(--variable-QsTa4u5mL)

How to implement ISO 27001 in 12 Steps

var(--variable-Cl6cRG5u3)

Written by

Aron Lange

Published

Sep 3, 2025

Implementation Project

var(--variable-QsTa4u5mL)

How to implement ISO 27001 in 12 Steps

var(--variable-Cl6cRG5u3)

Written by

Aron Lange

Published

Sep 3, 2025

Implementing ISO 27001 means building an information security management system that satisfies clauses 4 to 10 of the standard, then passing a certification audit. This guide breaks the work into 12 steps, in the order a real project follows. Each step links to a detailed article with its requirements, deliverables and common mistakes.

The 12 steps mapped to the standard

Step

Focus

Main reference

1

Scope of the ISMS

Clauses 4.1 to 4.3

2

Gap analysis

Project preparation

3

Management support

Clauses 5.1, 5.3

4

Information security policy

Clause 5.2

5

Asset inventory

Control A.5.9

6

Risk management methodology

Clause 6.1

7

Risk assessment

Clauses 6.1.2, 8.2

8

Risk treatment

Clauses 6.1.3, 8.3

9

Competence and awareness

Clauses 7.2, 7.3

10

Performance evaluation

Clauses 9.1 to 9.3

11

Improvement

Clauses 10.1, 10.2

12

Certification audit

External audit, stages 1 and 2

Step 1: Scope of the ISMS

Define what the Information Security Management System (ISMS) covers — which parts of the organization, which processes, assets, and locations are in and out. A clear scope aligns the ISMS with business objectives and sets a realistic boundary for everything that follows. The boundaries you set here are exactly what the gap analysis in Step 2 will assess. Read how to define the ISO 27001 scope.

Step 2: Gap Analysis

Measure your current security practices against the standard’s requirements, within the scope you just defined. The gap analysis shows where you already comply and where you fall short — and, just as importantly, it produces the evidence base for the business case you will put to management in Step 3. This turns the request for commitment into an evidence-driven proposal rather than a generic appeal. Read how to run a gap analysis.

Step 3: Management Support

Secure genuine commitment from top management. Positioned deliberately after the gap analysis, this step lets you make an evidence-based case using concrete findings instead of vague warnings. Leadership commitment is what gives the project the budget, authority, and priority it needs — and it is mandated by the standard, not optional. The business case secured here feeds directly into the project charter and the information security policy that follow. Read how to win management support.

Step 4: Information Security Policy

Develop the Information Security Policy together with your security objectives. Issued by top management, this policy is a formal statement of intent: it sets the tone, aligns the ISMS with business goals, and mandates participation across every level of the organization. It becomes the reference point for all the security activities that come after it. Read how to write the information security policy.

Step 5: Asset Inventory

Identify and classify the information assets you need to protect — data, hardware, software, processes. You cannot assess risk to something you have not identified, so the inventory is the necessary input to the risk work ahead. Assigning owners and classifications here makes every later decision about protection clearer. Read how to build the asset inventory.

Step 6: Risk Management Methodology

Before assessing any risks, define how you will assess them. This step establishes a repeatable method: your risk criteria, how you will score likelihood and impact, and your risk acceptance thresholds. A consistent methodology is what makes your results defensible and comparable rather than ad hoc. Read how to define the risk methodology.

Step 7: Risk Assessment

Put the methodology to work. Identify, analyze, and evaluate the risks to your information assets, then prioritize them against your acceptance criteria. The result is a clear, documented picture of your organization’s risk exposure — the foundation for deciding what to actually do about it in Step 8. Read how to conduct the risk assessment.

Step 8: Risk Treatment

Decide how to handle each significant risk — mitigate, avoid, share, or accept it — and select the controls to do so, drawing on Annex A’s 93 controls or other frameworks. This step also produces the mandatory Statement of Applicability (SoA), which records which controls you have selected and why. This is often the most effort-intensive phase, as implementing controls can spawn several sub-projects. Read how to create the risk treatment plan.

Step 9: Competence & Awareness

Make sure people have the skills and awareness to play their part in the ISMS. Placed here on purpose — after risk treatment — so that training targets the actual risks and controls you have chosen, rather than generic security advice. Information security is a collective responsibility, and this step equips everyone from executives to frontline staff to uphold it. Read competence and awareness requirements.

Step 10: Performance Evaluation

Check whether the ISMS is actually working. Through monitoring, internal audits, and management review, you confirm the system is operating as intended and surface areas that need attention. This step validates the work done so far and prepares you for the certification audit. Read performance evaluation explained.

Step 11: Improvement

Act on what the evaluation revealed. Address nonconformities, carry out corrective actions, and make improvements that keep the ISMS effective as risks and the business change. Continual improvement is a core principle of the standard — and the habit that keeps certification sustainable rather than a one-off scramble. Read nonconformity and corrective action.

Step 12: Certification Audit

The final step. An accredited certification body validates your ISMS through a two-stage audit — a documentation review (Stage 1) followed by an assessment of how the system works in practice (Stage 2). Pass it, and you earn the ISO 27001 certificate: third-party proof of everything the previous eleven steps built. Read the certification audit explained.

How long does implementation take?

Duration depends on scope size, existing maturity and how much time the responsible people can actually dedicate. As orientation: small organizations with a focused scope commonly need three to six months, mid-sized organizations six to twelve. One constraint is fixed and often overlooked: the ISMS must have operated before stage 2, because the auditor needs records to examine. Plan for at least the internal audit, the management review and a few months of routine records before the certification audit.

From the auditor’s chair

The most expensive mistake I see is sequence inversion: organizations buy and configure controls first, then write a risk assessment that justifies the purchases. The standard runs the other way, and the audit trail shows the difference. When the risk assessment references controls by their marketing names, or every identified risk happens to be treated by something already owned, the methodology loses credibility and stage 2 becomes uncomfortable. Follow the order: understand, decide, then implement.

Frequently asked questions

Do we need a consultant to implement ISO 27001?

No. The standard does not require external support. What it requires is competence, and clause 7.2 lets you build it internally. Many organizations implement with an internal lead who has been trained for the role.

Do all 93 Annex A controls apply to us?

Not necessarily. Applicability is decided through risk treatment and documented in the Statement of Applicability, with a justification for every inclusion and exclusion.

Can we change the order of the steps?

Within limits. Some dependencies are fixed: the scope precedes everything, the methodology precedes the assessment, and the assessment precedes treatment. The order in this guide reflects those dependencies.

From Roadmap to Execution

Knowing the 12 steps is the easy part. The hard part is execution: breaking each step into concrete tasks, producing the documents an auditor expects, and keeping the project moving without losing weeks to a blank page or a missed requirement. This is also where judgment matters most — AI can draft a policy in seconds, but it cannot scope your ISMS, defend your control selection to an auditor, or tell you whether its own output fits your organization. That applied understanding is what carries a project through.

Our ISO/IEC 27001 Lead Implementer Toolkit turns this roadmap into a working system: a customizable project plan with 400+ sequenced tasks and 7 milestones, more than 20 ISO-aligned policy and document templates, mind maps, and bonus control mappings. It is built for real implementations by a practising ISO 27001 Lead Auditor, so you start from a proven structure instead of a blank page. Pay once for lifetime access and updates — no subscription.

Ready to go deeper? Each of the 12 steps has its own detailed article in this guide, walking through the required activities, deliverables, and the relevant ISO 27001 clauses. Start with Step 1: Scope of the ISMS.