Implementing ISO/IEC 27001 means building and operating an information security management system (ISMS): define its scope and context, establish leadership and responsibilities, assess and treat risk, operate selected controls, evaluate performance and improve. Certification is optional and separate; an external certification body, not ISO, issues a certificate after its assessment.
ISO/IEC 27001:2022 is the current published edition and has Amendment 1:2024. ISO/IEC 27001:2013 is withdrawn. Use licensed standard text for implementation and audit work; this guide summarises the process without reproducing requirements or control wording.
1. Establish purpose, context and scope
Start with the reason for the ISMS: risk management, customer assurance, contract need, regulation or a combination. Identify interested parties and relevant legal, contractual and internal requirements.
Write a scope that names the covered entities, products or services, locations, processes and technology, plus material interfaces and dependencies. Exclusions at a boundary must be factual and defensible. Keep an architecture and responsibility view that allows an auditor and control owner to understand the scope.
2. Set governance and resources
Assign executive sponsorship, an accountable ISMS lead, risk owners, control owners and independent internal-audit responsibility. Establish information-security objectives that can be measured and connected to business goals. Plan competence, awareness, communication, document control and resources.
The ISMS should use existing governance where it works. Do not create committees or documents solely to imitate another organisation.
3. Assess and treat information-security risk
Define a repeatable method with risk criteria and risk-acceptance authority. Identify information and supporting assets, threats, vulnerabilities, existing controls, likelihood and consequences at a useful level. Record owners and decisions.
For each risk, decide whether to modify, retain, avoid or share it. Build a treatment plan with actions, owners, resources and due dates. Residual risk acceptance must follow defined authority.
Maintain a Statement of Applicability that records the necessary controls, justification for inclusion, implementation status and justification for excluded Annex A controls. It is not a copy of the risk register and does not make all Annex A controls automatically mandatory. Necessary controls can also come from other sources.
4. Implement controls and evidence
Translate each treatment into operating responsibilities, procedures, technology, awareness and records. Evidence should demonstrate both operation and effectiveness where applicable: approved access reviews, restore results, incident exercises, supplier decisions, vulnerability remediation, monitoring outcomes and corrective actions.
ISO/IEC 27001:2022 Annex A contains 93 reference controls grouped into organisational, people, physical and technological themes. Control selection remains risk-based and must be reconciled in the Statement of Applicability.
5. Operate and monitor the ISMS
Define what will be monitored and measured, by whom, how often, and how results are evaluated. Useful measures answer management questions—for example whether priority remediation is late, restore objectives are demonstrated, privileged access is reviewed, or critical suppliers have unresolved risk.
Control changes, incidents, new suppliers, acquisitions, products and legal requirements should feed back into scope, risk and treatment decisions.
6. Internal audit and management review
Plan internal audits based on importance, change, risk and previous results. Preserve auditor objectivity and impartiality; a person should not simply approve their own work. Report evidence, criteria, findings and corrective actions.
Management review should use the required ISMS inputs and result in decisions about suitability, adequacy, effectiveness, improvements and resource needs. Minutes should record decisions and owners, not only attendance.
7. Correct and improve
When a nonconformity occurs, correct it, address consequences, analyse causes, decide and implement action, then review effectiveness. Avoid closing findings because a document was edited when the operational cause remains.
8. Decide whether to certify
An organisation may implement the standard without certification. If certification supports the business objective, evaluate several certification bodies, confirm relevant competence and accreditation, and agree the intended certificate scope.
Initial certification commonly includes stage 1 and stage 2 activities, followed by surveillance and later recertification under the certification programme. The certification body defines the audit plan and determines certification; a consultant cannot guarantee the outcome.
ISO 27001 and NIS2
An ISMS can support NIS2 risk governance and many Article 21 measures, but certification is not a legal safe harbour or automatic proof of NIS2 compliance. NIS2 scope, management-body duties, significant-incident reporting, national transposition and supervision require separate analysis. Use our NIS2 compliance services for an entity- and Member-State-specific assessment.
Implementation evidence checklist
- approved scope and boundary information;
- requirements and interested-party records;
- risk method, assessments, treatment plan and approvals;
- Statement of Applicability with current status and justification;
- competence, awareness and communication evidence;
- controlled operational records and metrics;
- internal-audit programme and reports;
- management-review decisions;
- nonconformity, cause and corrective-action evidence; and
- change-driven updates and improvement records.
Sources and review
This guide was substantively reviewed on 8 August 2026. It confirms the 2022 edition and 2024 amendment, separates implementation from certification, and removes fixed timeline, cost and NIS2-overlap percentages.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.