Home | News | What are the initial requirements for ISO 27001 certification?

News

What are the initial requirements for ISO 27001 certification?

What Are The Initial Requirements For Iso 27001 Certification?

What are the initial requirements for ISO 27001 certification?

The initial requirements for ISO 27001 certification start long before an external auditor arrives. A business first needs to understand why it wants certification, what part of the organisation the Information Security Management System will cover, who will take responsibility for it, what information needs protection and which security risks matter most.

ISO/IEC 27001:2022 is the current international standard for information security management systems. ISO confirms that the standard helps organisations establish, implement, maintain and continually improve an Information Security Management System, commonly called an ISMS. The current publication also includes Amendment 1:2024 relating to climate action changes within management system requirements.

For businesses starting ISO 27001, the most important point is that certification does not begin with writing dozens of policies or working through all 93 Annex A controls. It begins with understanding the organisation and creating a structured approach to information security risk.

UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. The current platform provides structured workflows, guided risk assessment, residual risk tracking, control coverage, progress monitoring and audit-ready documentation.

UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.

Start by understanding what ISO 27001 actually requires

ISO 27001 asks an organisation to create and operate a management system for information security.

That management system needs to connect information security with the way the business actually works.

It should cover areas such as:

Leadership

Business context

Interested parties

Information security risk

Risk treatment

Security controls

Policies

Employees

Suppliers

Technology

Internal audit

Management review

Corrective action

Continual improvement

The objective is not to build a separate compliance operation that only exists for an auditor.

A good ISMS should help the organisation understand information security risk and make better business decisions every day.

what is iso 27001

ISO 27001 is an international standard for managing information security through a structured ISMS.

It helps organisations protect confidentiality, integrity and availability.

Confidentiality means information only reaches authorised people and systems.

Integrity means information remains accurate, complete and trustworthy.

Availability means authorised users can access information and services when they need them.

ISO confirms that conformity with ISO/IEC 27001 means an organisation has established a system for managing risks connected with the security of information it owns or handles.

This risk-based approach explains why ISO 27001 can work for very different organisations.

A cloud software company may focus heavily on service availability, development security and customer information.

A professional consultancy may focus on Microsoft 365, laptops, customer documents and employee access.

A manufacturer may depend on operational systems, suppliers and physical locations.

The framework remains the same, but each organisation applies it according to its own risks and business needs.

Decide why your organisation wants certification

The first practical requirement should be a clear business reason.

Ask why ISO 27001 matters to the organisation.

A customer may require certification.

A tender may request it.

A supply chain may expect recognised information security assurance.

Management may want a more structured security framework.

The organisation may want to improve customer confidence or strengthen governance.

The answer affects the scope and priorities of the project.

For example, if one major customer requires ISO 27001 for a particular managed service, the business may decide to build the initial ISMS around that service and the people, systems, suppliers and processes that support it.

A clear business driver helps prevent unnecessary work.

Secure leadership commitment early

ISO 27001 requires leadership involvement.

Senior management should understand the purpose of the ISMS and support its implementation.

This does not mean every director needs technical cyber security knowledge.

Leadership does need to understand the business importance of information security.

Senior management should support:

Information security objectives

Resource allocation

Risk management

Responsibility assignments

Policy direction

Management review

Corrective action

Continual improvement

Choose a senior sponsor at the beginning of the project.

That person can help resolve issues when ISO 27001 requires cooperation between departments.

For example, human resources may need to improve employee departure processes. Procurement may need to add supplier security checks. IT may need to strengthen access management. Managers may need to review permissions.

Leadership support makes these activities much easier.

Define who will manage the ISMS

Someone needs day-to-day responsibility for coordinating the management system.

This person does not need to perform every security task.

They should understand how the various parts fit together.

Typical responsibilities may include:

Coordinating risk assessments

Maintaining the ISMS structure

Tracking actions

Supporting control owners

Organising internal audit

Preparing management review information

Maintaining evidence

Coordinating certification activity

Other employees can own specific controls and risks.

For example, HR may own employee screening and departure processes.

IT may own technical controls.

Procurement may own supplier due diligence.

Senior management may own significant business risks.

Clear accountability prevents the ISMS from becoming one person’s document collection.

Define the ISMS scope

Scope is one of the earliest formal decisions an organisation needs to make.

The scope defines what the ISMS covers.

It might include the whole organisation.

Alternatively, it may cover a particular service, legal entity, department or operational function.

A useful scope considers:

Business services

People

Locations

Information

Technology

Cloud services

Suppliers

Supporting processes

Customer requirements

Interfaces with areas outside the ISMS

Do not make the scope artificially narrow simply to reduce the work.

If an external supplier, internal department or cloud service plays an essential role in delivering the scoped service, you need to consider that dependency.

UK Cyber Compliance’s current ISO 27001 guidance identifies setting a clear and credible ISMS scope as one of the core requirements for certification.

Understand the organisation’s context

ISO 27001 requires businesses to understand internal and external issues that can affect the ISMS.

Internal factors may include:

Business objectives

Organisational structure

Employee capability

Technology

Remote working

Existing security practices

Information handling

Business growth

External factors may include:

Customer requirements

Legal obligations

Contracts

Supplier dependencies

Cyber threats

Industry expectations

Regulatory requirements

Economic changes

The current standard also incorporates Amendment 1:2024, which adds climate-related consideration within management system context requirements.

The organisation should determine whether relevant climate-related issues affect its ISMS context or interested parties.

For many businesses, this may result in a straightforward documented consideration rather than a major security project.

Identify interested parties

Interested parties are people or organisations that have relevant information security expectations or requirements.

These might include:

Customers

Employees

Suppliers

Directors

Regulators

Insurers

Business partners

Certification bodies

Shareholders

For each relevant interested party, determine what information security requirements matter.

A customer may expect confidentiality.

A supplier contract may require incident reporting.

Employees need secure and reliable access to business systems.

A regulator may impose legal obligations.

These requirements influence risk assessment and control selection.

Identify legal, regulatory and contractual obligations

Before choosing controls, understand the obligations the organisation already has.

Depending on the business, this may include:

UK data protection law

Customer contracts

Employment requirements

Confidentiality agreements

Sector requirements

Intellectual property responsibilities

Supplier contracts

Information retention obligations

Security clauses in tenders

Create a structured way to identify and review these obligations.

The organisation does not need to memorise every law.

It needs to understand which obligations apply and how the ISMS addresses them.

Establish an information security policy

ISO 27001 requires an information security policy.

The policy should establish the organisation’s overall direction and commitment to information security.

It should support business objectives and provide a framework for setting information security objectives.

Senior management should approve it.

Keep the policy clear enough that employees can understand what the organisation is trying to achieve.

A policy should not exist only because an auditor expects to see it.

It should provide genuine direction for the ISMS.

Define roles and responsibilities

Information security becomes difficult when nobody knows who owns each activity.

Define responsibilities early.

Useful questions include:

Who owns the ISMS?

Who approves policies?

Who owns information security risks?

Who manages user access?

Who handles incidents?

Who reviews suppliers?

Who manages backups?

Who monitors vulnerabilities?

Who delivers awareness?

Who performs internal audit?

Who reports information security performance to management?

UK Cyber Compliance’s current guidance stresses the importance of leadership involvement and clearly assigned responsibilities within the ISMS.

Clear ownership also makes audit evidence much easier to organise.

Create the risk assessment methodology

This is one of the most important early requirements.

Before assessing individual risks, decide how the organisation will measure them.

A practical methodology normally defines:

Likelihood

Impact

Risk rating

Risk acceptance criteria

Risk ownership

Risk treatment

Residual risk

Review arrangements

The method should produce consistent results.

Do not create a scoring model that only one technical employee understands.

Managers and risk owners need to understand what the ratings mean.

For example, likelihood might reflect how realistically a security event could occur.

Impact might consider customer harm, business disruption, contractual consequences, confidentiality loss and operational impact.

The organisation then combines those factors using its chosen method.

Set risk acceptance criteria

Risk acceptance criteria tell the organisation when a risk needs additional treatment and when management may accept it.

Without clear criteria, different managers may make inconsistent decisions.

The business might define rules such as:

Lower risks may receive acceptance from the risk owner.

Moderate risks require regular monitoring.

Higher risks require treatment.

Particularly serious residual risks require senior approval.

The exact method should fit the organisation.

What matters is consistency and accountability.

Risk acceptance should always represent an informed management decision.

Complete the first information security risk assessment

Once the methodology exists, identify realistic risk scenarios.

Avoid vague entries such as:

Phishing

Ransomware

Cloud failure

Supplier risk

Describe what could actually happen.

For example:

An employee may respond to a convincing phishing email and disclose Microsoft 365 credentials, allowing an attacker to access confidential business information.

A cloud provider may suffer an extended outage that prevents customers from accessing an important service.

A supplier may experience a cyber incident that disrupts a service on which the organisation depends.

An employee may accidentally share confidential information with an unauthorised recipient.

Clear scenarios make risk assessment much easier.

They also lead to more meaningful control decisions.

Assign risk owners

Every significant risk should have an accountable owner.

The risk owner should understand the potential business consequences.

They should also have enough authority to make or escalate decisions.

IT does not need to own every risk.

An operations manager may own a service availability risk.

A finance leader may own risk connected with financial systems.

HR may better understand the business consequences of employee information exposure.

Technical specialists can support risk owners with security knowledge.

Business ownership keeps risk decisions connected with real consequences.

Record the controls that already operate

Before creating new safeguards, identify the controls already protecting the business.

A risk involving compromised accounts might already have:

Multi-factor authentication

Email filtering

Restricted administrator access

Security monitoring

Employee awareness

Incident response

These controls influence the current risk rating.

Only give them credit when they genuinely operate.

Do not treat planned activity as an existing safeguard.

If MFA will be enabled next month, the current risk rating should reflect the security environment today.

Create the risk treatment plan

Risks that exceed the organisation’s acceptance criteria need treatment.

The risk treatment plan records what the organisation intends to do.

Useful information may include:

Risk reference

Required action

Control

Owner

Target date

Current status

Expected residual risk

Supporting evidence

A treatment action should be specific.

“Improve access security” provides little value.

“Require MFA for all users of the customer service platform” gives the organisation a measurable action.

Understand the 93 Annex A controls

ISO/IEC 27001:2022 contains 93 controls within Annex A.

These cover organisational, people, physical and technological security.

Areas include:

Information security policies

Access management

Supplier relationships

Cloud services

Incident management

Business continuity

Employee awareness

Physical protection

Authentication

Malware protection

Backup

Logging

Monitoring

Vulnerability management

Network security

Secure development

Do not assume the organisation must implement every control.

The organisation first determines what controls it needs through risk treatment and other requirements.

It then compares those decisions against Annex A to make sure it has not overlooked something relevant.

Create the Statement of Applicability

The Statement of Applicability, often shortened to SoA, records the organisation’s control decisions.

It should identify the necessary controls and explain why the organisation needs them.

It should record whether those controls have been implemented.

It should also justify relevant Annex A exclusions.

This document connects risk assessment with the control environment.

Suppose the risk register identifies administrator account compromise as a major concern.

The SoA should reflect relevant authentication, access management and monitoring controls.

A supplier risk should connect with appropriate supplier controls.

The documents should support each other.

What is ISO 27001 Certification?

ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets ISO/IEC 27001 requirements within its defined scope.

Certification does not guarantee that the organisation will never experience a security incident.

Instead, it demonstrates that the business uses a structured and independently assessed approach to information security management.

ISO states that organisations can use ISO/IEC 27001 to demonstrate to interested parties that they have established a system for managing information security risks.

Customers often value this assurance because it gives them something stronger than a supplier simply saying that it takes cyber security seriously.

Build the required documented information

ISO 27001 requires documented information to support the ISMS.

The exact set should reflect the organisation.

Common records and documents may include:

ISMS scope

Information security policy

Risk methodology

Risk register

Risk treatment plan

Statement of Applicability

Information security objectives

Roles and responsibilities

Internal audit records

Management review records

Corrective actions

Evidence of control operation

Avoid producing unnecessary documents.

The strongest ISMS contains enough documentation to make responsibilities and processes clear without overwhelming employees.

Set information security objectives

Information security objectives turn management intent into measurable progress.

Examples could include:

Increasing MFA coverage

Reducing overdue vulnerabilities

Improving supplier security reviews

Completing access reviews

Improving recovery testing

Reducing overdue risk treatment actions

Each objective should have an owner and a way to measure progress.

Management should review results.

Objectives also provide valuable evidence that the organisation actively improves its ISMS.

Address competence and awareness

Employees whose work affects information security need appropriate competence.

The wider workforce also needs enough awareness to understand its responsibilities.

Training may cover:

Phishing

Authentication

Information handling

Incident reporting

Document sharing

Remote working

Data protection

Use of approved systems

Role-specific employees may need deeper knowledge.

An administrator needs stronger technical competence.

A risk owner needs to understand risk decisions.

An internal auditor needs appropriate audit competence.

Training should support actual responsibilities.

Start collecting evidence immediately

Do not wait until the external audit to think about evidence.

Evidence develops while controls operate.

Examples include:

Access review records

Training records

Supplier assessments

Backup tests

Incident records

Security monitoring information

Risk approvals

Vulnerability remediation

Policy acknowledgements

Management decisions

A written policy says what should happen.

Evidence demonstrates what happened.

This distinction becomes extremely important during certification.

Operate the ISMS before external audit

A new organisation cannot realistically create every document one day and expect to demonstrate a mature operating system the next.

Controls need time to generate evidence.

Risk treatment actions need implementation.

Employees need awareness.

Management needs information to review.

Internal audit needs something real to test.

Allow the ISMS to operate and produce records.

This gives an external auditor a much clearer picture of effectiveness.

Complete internal audit

Internal audit checks whether the ISMS meets ISO 27001 requirements and the organisation’s own requirements.

It should look at real processes.

For example:

Select a recent employee departure and check whether access ended correctly.

Review a supplier and check whether the expected security assessment took place.

Review an information security risk and check whether treatment aligns with the controls.

Inspect training records.

Review policy implementation.

Check evidence supporting the SoA.

Internal audit should identify genuine weaknesses.

Finding an issue internally gives the organisation an opportunity to improve before certification.

Hold management review

Senior management must review the ISMS.

Management review gives leaders a structured opportunity to assess whether information security remains effective and aligned with the business.

Useful areas include:

Audit results

Risks

Objectives

Incidents

Corrective actions

Changes affecting the ISMS

Supplier issues

Resource needs

Improvement opportunities

The review should produce decisions where appropriate.

A management meeting that simply records that everything is satisfactory provides limited value.

Correct nonconformities

When the organisation identifies a failure to meet a requirement, it needs to respond.

Correct the immediate issue where appropriate.

Then consider why it happened.

Suppose a former employee still has access to Microsoft 365.

Disabling the account fixes the immediate exposure.

A proper corrective action investigates why the departure process failed.

Perhaps HR did not notify IT.

Maybe nobody owned the account-removal activity.

Fixing the underlying process reduces the chance of recurrence.

Prepare for the external certification assessment

Once the ISMS operates effectively, the organisation can proceed towards independent certification.

The external assessment normally examines both readiness and operational effectiveness.

Auditors may review documentation, speak with employees, sample controls and inspect evidence.

They want to determine whether the ISMS genuinely works.

Do not train employees to memorise ISO terminology.

They should understand their actual responsibilities.

A member of staff should know how to report an incident even if they cannot name the clause that requires it.

How the Certification Works

The certification route normally starts with preparation and implementation.

The business defines scope, understands its context, assesses information security risks, treats unacceptable risks, selects controls, prepares the SoA and operates the management system.

Internal audit and management review then check readiness.

An independent certification body conducts the external assessment.

A successful assessment can result in ISO 27001 certification for the stated scope.

After certification, the organisation continues maintaining, auditing, reviewing and improving its ISMS.

UK Cyber Compliance’s current guidance describes the certification route as building a working ISMS, completing internal audit and management review, addressing corrective action and then proceeding to independent external assessment.

Certification therefore represents the start of ongoing assurance rather than the end of information security work.

ISO 27001 Certification Levels

ISO 27001 does not use official achievement bands such as bronze, silver or gold.

An organisation either achieves certification for the defined ISMS scope or it does not.

Businesses may still demonstrate different levels of security maturity.

One organisation may operate a recently established ISMS with straightforward controls.

Another may have years of audit evidence, advanced monitoring, mature supplier governance and highly developed risk management.

Both can hold certification to ISO/IEC 27001.

UK Cyber Compliance’s current ISO 27001 guidance also makes clear that the standard does not operate through formal achievement bands.

Continual improvement allows the ISMS to mature over time.

Current UK cyber statistics show why risk management matters

The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber security breach or attack during the previous 12 months. That represents approximately 612,000 UK businesses.

Reported incidence increased with organisation scale. The survey found that 65 per cent of medium businesses and 69 per cent of large businesses identified a breach or attack. Small businesses reported 46 per cent.

Phishing remained the most commonly identified attack, affecting 38 per cent of businesses.

Despite this exposure, only 30 per cent of businesses reported carrying out a cyber security risk assessment during the previous year. Only 15 per cent formally reviewed cyber risks from immediate suppliers, while 6 per cent reviewed the wider supply chain.

These figures show why structured security governance matters.

ISO 27001 gives businesses a repeatable process for understanding risk before an incident happens.

Who needs iso 27001 certification

ISO 27001 can benefit organisations that depend on information or need to demonstrate strong information security governance.

This may include:

Software companies

Technology providers

Managed service providers

Professional firms

Healthcare suppliers

Manufacturers

Charities

Financial organisations

Public sector suppliers

Defence suppliers

Cloud service providers

Certification can become particularly valuable when customers repeatedly request security assurance.

A recognised certification can support tenders, supplier assessments and customer confidence.

ISO confirms that organisations across public, private and not-for-profit sectors use ISO/IEC 27001.

The decision should still follow business need.

Some organisations implement ISO 27001 practices without seeking formal certification.

Others require the independent certificate for commercial reasons.

Small businesses should keep the process proportionate

ISO 27001 does not need to become an enormous bureaucracy.

A small company may have a focused scope, concise policies, a manageable risk register and straightforward management processes.

The key requirements remain the same, but implementation should reflect the organisation.

A smaller business might have one person coordinating several control areas.

A larger organisation may have dedicated teams.

Both can operate an effective ISMS when responsibilities remain clear and evidence supports the controls.

Complexity should follow business need rather than the desire to make the ISMS look impressive.

Cyber Essentials can provide useful foundations

Many UK businesses already hold Cyber Essentials.

That work can support ISO 27001.

Existing technical measures around secure configuration, access management, malware protection and security updates can provide useful controls.

Cyber Essentials does not replace ISO 27001.

ISO 27001 goes much further into management, risk, suppliers, business processes, audit, governance and continual improvement.

Existing Cyber Essentials evidence can still give the organisation a useful starting point.

Supplier security needs attention from the beginning

Most organisations depend on external providers.

These may include:

Cloud services

Managed IT

Software providers

Payroll services

Security monitoring

Telecommunications

Professional advisers

Data processors

Identify the suppliers that could materially affect information security.

Ask what information they access.

Consider what happens if they become unavailable.

Review whether contractual security requirements exist.

Decide how the organisation will assess supplier security.

The latest government survey found that formal supplier cyber-risk review remains relatively uncommon among UK businesses.

ISO 27001 gives organisations a framework for improving this area.

Do not forget business continuity

Availability forms part of information security.

Understand which services the business cannot easily operate without.

Identify supporting systems and suppliers.

Consider backup.

Review recovery arrangements.

Test important assumptions.

A backup process that has never successfully restored information provides weaker assurance than one that receives regular testing.

Continuity planning should follow business impact and information security risk.

Integrate security with employee processes

Connect the ISMS with everyday employment activity.

When someone joins, give them appropriate access and awareness.

When their role changes, review permissions.

When they leave, remove access promptly.

These processes create useful evidence and reduce risk.

The strongest ISO 27001 systems become embedded in normal operations rather than creating separate audit-only activity.

Make control ownership clear

Every important control should have someone responsible for making it work.

Examples include:

HR owning employee security processes.

IT owning authentication controls.

Procurement owning supplier assessments.

Operations owning continuity activity.

Security teams owning monitoring.

Managers owning access approvals.

Clear ownership prevents controls becoming neglected after the initial certification project.

Which UK-based firms offer ISO 27001 consultancy services?

UK businesses can obtain ISO 27001 assistance from information security consultancies, managed service providers, audit professionals and platform-led compliance providers.

UK Cyber Compliance provides structured ISO 27001 support through its automated and AI-driven platform.

Its current platform includes step-by-step workflows, guided risk assessment, residual risk tracking, control coverage, policy generation, progress monitoring and audit-ready evidence reporting.

A useful ISO 27001 provider should help the organisation understand its own ISMS rather than simply supply a collection of generic documents.

The business should remain capable of explaining:

Its scope

Its information security risks

Its risk acceptance criteria

Its controls

Its SoA

Its evidence

Its audit findings

Its improvement activity

External support works best when it builds internal understanding.

How UK Cyber Compliance supports the initial requirements

The early stages of ISO 27001 can become difficult when organisations rely on separate spreadsheets, shared folders and email messages.

Risk information may sit in one location.

Controls may sit somewhere else.

Policies may have different owners.

Audit evidence may become difficult to find.

UK Cyber Compliance brings this information together within a central platform.

Its current website describes guided workflows that walk organisations through ISO 27001 requirements, intelligent risk assessment, AI-powered policy generation, live progress monitoring and generation of audit-ready evidence packs, risk reports and Statement of Applicability documentation.

This can make the initial requirements easier to organise.

Technology does not remove management responsibility.

The business still needs to understand its context, define scope, assess risks and make informed decisions.

The platform helps structure and record that work.

A practical starting checklist

Before moving towards external certification, check that the organisation has addressed the following:

  1. The business understands why it wants ISO 27001.
  2. Senior management supports the ISMS.
  3. Someone coordinates implementation.
  4. The ISMS scope has been clearly defined.
  5. Internal and external business issues have been considered.
  6. Relevant interested parties have been identified.
  7. Relevant information security obligations are understood.
  8. The organisation has an information security policy.
  9. Security responsibilities have been assigned.
  10. A risk assessment methodology exists.
  11. Risk acceptance criteria have been agreed.
  12. Information security risks have been identified.
  13. Risk owners have been assigned.
  14. Current controls have been documented.
  15. Unacceptable risks have treatment plans.
  16. Annex A controls have been considered.
  17. The Statement of Applicability has been prepared.
  18. Relevant policies and processes reflect actual operations.
  19. Information security objectives have been established.
  20. Relevant employees have appropriate awareness and competence.
  21. Controls have operated long enough to produce useful evidence.
  22. Internal audit has taken place.
  23. Senior management has reviewed the ISMS.
  24. Identified weaknesses have received appropriate corrective action.
  25. Evidence remains organised and available for assessment.

An organisation that can answer these points clearly has built much of the foundation needed for certification.

Where should a business start first?

If your organisation has decided to pursue ISO 27001, start with four activities.

First, establish why certification matters.

Second, secure leadership support and nominate someone to coordinate the ISMS.

Third, define the proposed certification scope.

Fourth, complete a structured gap review against the current ISO/IEC 27001:2022 requirements.

Once those foundations exist, build the risk methodology and identify the information, services, systems, people and suppliers that need protection.

Risk assessment then drives treatment.

Treatment drives control selection.

Control decisions feed the Statement of Applicability.

Policies support those controls.

Operational activity generates evidence.

Internal audit tests the system.

Management review provides leadership oversight.

Independent certification can then assess whether the ISMS works as intended.

ISO confirms that ISO/IEC 27001:2022 remains the published current standard, with Amendment 1:2024 applying climate action changes to the management system requirements.

UK Cyber Compliance provides an automated and AI-driven platform that can help organisations organise this process through guided risk assessment, control management, policies, progress tracking and audit-ready evidence.

The initial requirements become far easier to manage when the business follows them in the right order. Start with context, leadership, scope and risk. Build the controls around real business needs. Gather evidence as the ISMS operates. That approach creates a management system that supports certification while also improving the organisation’s everyday information security.

UK Cyber Compliance is here to help

For more information, please do get in touch.

Please check out our Free Cyber Insurance

Other blog posts, Your ISO 27001 Questions AnsweredGet ISO 27001 Certified ,

If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.