ISO 27001 Readiness Checklist
A practical first-pass checklist for SaaS and technology companies.
Use this to identify obvious readiness gaps before deciding whether you need a gap assessment, readiness project or internal audit.
ISMS foundation
- A defined ISMS scope and boundaries
- Relevant interested parties and security requirements identified
- Information-security policy approved
- Security roles and responsibilities assigned
Risk management
- Documented risk assessment method
- Current risk register
- Risk treatment decisions and owners
- Statement of Applicability maintained
Identity and access
- MFA coverage understood
- Privileged access identified and reviewed
- Joiner, mover and leaver process operating
- Guest, service and dormant accounts governed
Operations
- Asset inventory maintained
- Vulnerability and patch process operating
- Backups tested, not merely scheduled
- Logging and monitoring responsibilities defined
- Change control evidence retained
Suppliers and people
- Critical suppliers identified and reviewed
- Security requirements included in supplier process
- Security awareness and competence records retained
- Confidentiality obligations defined
Assurance
- Internal audit programme planned and executed
- Management review performed with recorded decisions
- Nonconformities and corrective actions tracked
- Evidence can be produced for control operation, not only policy existence
What the checklist cannot tell you.
A checklist does not establish whether evidence is sufficient, whether a control is effective, or whether the selected scope and risk treatment are appropriate.
Use it for triage. Use an assessment for evidence-based conclusions.