What are the initial requirements for ISO 27001 certification?
The initial requirements for ISO 27001 certification start long before an external auditor arrives. A business first needs to understand why it wants certification, what part of the organisation the Information Security Management System will cover, who will take responsibility for it, what information needs protection and which security risks matter most.
ISO/IEC 27001:2022 is the current international standard for information security management systems. ISO confirms that the standard helps organisations establish, implement, maintain and continually improve an Information Security Management System, commonly called an ISMS. The current publication also includes Amendment 1:2024 relating to climate action changes within management system requirements.
For businesses starting ISO 27001, the most important point is that certification does not begin with writing dozens of policies or working through all 93 Annex A controls. It begins with understanding the organisation and creating a structured approach to information security risk.
UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. The current platform provides structured workflows, guided risk assessment, residual risk tracking, control coverage, progress monitoring and audit-ready documentation.
UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.
Start by understanding what ISO 27001 actually requires
ISO 27001 asks an organisation to create and operate a management system for information security.
That management system needs to connect information security with the way the business actually works.
It should cover areas such as:
Leadership
Business context
Interested parties
Information security risk
Risk treatment
Security controls
Policies
Employees
Suppliers
Technology
Internal audit
Management review
Corrective action
Continual improvement
The objective is not to build a separate compliance operation that only exists for an auditor.
A good ISMS should help the organisation understand information security risk and make better business decisions every day.
what is iso 27001
ISO 27001 is an international standard for managing information security through a structured ISMS.
It helps organisations protect confidentiality, integrity and availability.
Confidentiality means information only reaches authorised people and systems.
Integrity means information remains accurate, complete and trustworthy.
Availability means authorised users can access information and services when they need them.
ISO confirms that conformity with ISO/IEC 27001 means an organisation has established a system for managing risks connected with the security of information it owns or handles.
This risk-based approach explains why ISO 27001 can work for very different organisations.
A cloud software company may focus heavily on service availability, development security and customer information.
A professional consultancy may focus on Microsoft 365, laptops, customer documents and employee access.
A manufacturer may depend on operational systems, suppliers and physical locations.
The framework remains the same, but each organisation applies it according to its own risks and business needs.
Decide why your organisation wants certification
The first practical requirement should be a clear business reason.
Ask why ISO 27001 matters to the organisation.
A customer may require certification.
A tender may request it.
A supply chain may expect recognised information security assurance.
Management may want a more structured security framework.
The organisation may want to improve customer confidence or strengthen governance.
The answer affects the scope and priorities of the project.
For example, if one major customer requires ISO 27001 for a particular managed service, the business may decide to build the initial ISMS around that service and the people, systems, suppliers and processes that support it.
A clear business driver helps prevent unnecessary work.
Secure leadership commitment early
ISO 27001 requires leadership involvement.
Senior management should understand the purpose of the ISMS and support its implementation.
This does not mean every director needs technical cyber security knowledge.
Leadership does need to understand the business importance of information security.
Senior management should support:
Information security objectives
Resource allocation
Risk management
Responsibility assignments
Policy direction
Management review
Corrective action
Continual improvement
Choose a senior sponsor at the beginning of the project.
That person can help resolve issues when ISO 27001 requires cooperation between departments.
For example, human resources may need to improve employee departure processes. Procurement may need to add supplier security checks. IT may need to strengthen access management. Managers may need to review permissions.
Leadership support makes these activities much easier.
Define who will manage the ISMS
Someone needs day-to-day responsibility for coordinating the management system.
This person does not need to perform every security task.
They should understand how the various parts fit together.
Typical responsibilities may include:
Coordinating risk assessments
Maintaining the ISMS structure
Tracking actions
Supporting control owners
Organising internal audit
Preparing management review information
Maintaining evidence
Coordinating certification activity
Other employees can own specific controls and risks.
For example, HR may own employee screening and departure processes.
IT may own technical controls.
Procurement may own supplier due diligence.
Senior management may own significant business risks.
Clear accountability prevents the ISMS from becoming one person’s document collection.
Define the ISMS scope
Scope is one of the earliest formal decisions an organisation needs to make.
The scope defines what the ISMS covers.
It might include the whole organisation.
Alternatively, it may cover a particular service, legal entity, department or operational function.
A useful scope considers:
Business services
People
Locations
Information
Technology
Cloud services
Suppliers
Supporting processes
Customer requirements
Interfaces with areas outside the ISMS
Do not make the scope artificially narrow simply to reduce the work.
If an external supplier, internal department or cloud service plays an essential role in delivering the scoped service, you need to consider that dependency.
UK Cyber Compliance’s current ISO 27001 guidance identifies setting a clear and credible ISMS scope as one of the core requirements for certification.
Understand the organisation’s context
ISO 27001 requires businesses to understand internal and external issues that can affect the ISMS.
Internal factors may include:
Business objectives
Organisational structure
Employee capability
Technology
Remote working
Existing security practices
Information handling
Business growth
External factors may include:
Customer requirements
Legal obligations
Contracts
Supplier dependencies
Cyber threats
Industry expectations
Regulatory requirements
Economic changes
The current standard also incorporates Amendment 1:2024, which adds climate-related consideration within management system context requirements.
The organisation should determine whether relevant climate-related issues affect its ISMS context or interested parties.
For many businesses, this may result in a straightforward documented consideration rather than a major security project.
Identify interested parties
Interested parties are people or organisations that have relevant information security expectations or requirements.
These might include:
Customers
Employees
Suppliers
Directors
Regulators
Insurers
Business partners
Certification bodies
Shareholders
For each relevant interested party, determine what information security requirements matter.
A customer may expect confidentiality.
A supplier contract may require incident reporting.
Employees need secure and reliable access to business systems.
A regulator may impose legal obligations.
These requirements influence risk assessment and control selection.
Identify legal, regulatory and contractual obligations
Before choosing controls, understand the obligations the organisation already has.
Depending on the business, this may include:
UK data protection law
Customer contracts
Employment requirements
Confidentiality agreements
Sector requirements
Intellectual property responsibilities
Supplier contracts
Information retention obligations
Security clauses in tenders
Create a structured way to identify and review these obligations.
The organisation does not need to memorise every law.
It needs to understand which obligations apply and how the ISMS addresses them.
Establish an information security policy
ISO 27001 requires an information security policy.
The policy should establish the organisation’s overall direction and commitment to information security.
It should support business objectives and provide a framework for setting information security objectives.
Senior management should approve it.
Keep the policy clear enough that employees can understand what the organisation is trying to achieve.
A policy should not exist only because an auditor expects to see it.
It should provide genuine direction for the ISMS.
Define roles and responsibilities
Information security becomes difficult when nobody knows who owns each activity.
Define responsibilities early.
Useful questions include:
Who owns the ISMS?
Who approves policies?
Who owns information security risks?
Who manages user access?
Who handles incidents?
Who reviews suppliers?
Who manages backups?
Who monitors vulnerabilities?
Who delivers awareness?
Who performs internal audit?
Who reports information security performance to management?
UK Cyber Compliance’s current guidance stresses the importance of leadership involvement and clearly assigned responsibilities within the ISMS.
Clear ownership also makes audit evidence much easier to organise.
Create the risk assessment methodology
This is one of the most important early requirements.
Before assessing individual risks, decide how the organisation will measure them.
A practical methodology normally defines:
Likelihood
Impact
Risk rating
Risk acceptance criteria
Risk ownership
Risk treatment
Residual risk
Review arrangements
The method should produce consistent results.
Do not create a scoring model that only one technical employee understands.
Managers and risk owners need to understand what the ratings mean.
For example, likelihood might reflect how realistically a security event could occur.
Impact might consider customer harm, business disruption, contractual consequences, confidentiality loss and operational impact.
The organisation then combines those factors using its chosen method.
Set risk acceptance criteria
Risk acceptance criteria tell the organisation when a risk needs additional treatment and when management may accept it.
Without clear criteria, different managers may make inconsistent decisions.
The business might define rules such as:
Lower risks may receive acceptance from the risk owner.
Moderate risks require regular monitoring.
Higher risks require treatment.
Particularly serious residual risks require senior approval.
The exact method should fit the organisation.
What matters is consistency and accountability.
Risk acceptance should always represent an informed management decision.
Complete the first information security risk assessment
Once the methodology exists, identify realistic risk scenarios.
Avoid vague entries such as:
Phishing
Ransomware
Cloud failure
Supplier risk
Describe what could actually happen.
For example:
An employee may respond to a convincing phishing email and disclose Microsoft 365 credentials, allowing an attacker to access confidential business information.
A cloud provider may suffer an extended outage that prevents customers from accessing an important service.
A supplier may experience a cyber incident that disrupts a service on which the organisation depends.
An employee may accidentally share confidential information with an unauthorised recipient.
Clear scenarios make risk assessment much easier.
They also lead to more meaningful control decisions.
Assign risk owners
Every significant risk should have an accountable owner.
The risk owner should understand the potential business consequences.
They should also have enough authority to make or escalate decisions.
IT does not need to own every risk.
An operations manager may own a service availability risk.
A finance leader may own risk connected with financial systems.
HR may better understand the business consequences of employee information exposure.
Technical specialists can support risk owners with security knowledge.
Business ownership keeps risk decisions connected with real consequences.
Record the controls that already operate
Before creating new safeguards, identify the controls already protecting the business.
A risk involving compromised accounts might already have:
Multi-factor authentication
Email filtering
Restricted administrator access
Security monitoring
Employee awareness
Incident response
These controls influence the current risk rating.
Only give them credit when they genuinely operate.
Do not treat planned activity as an existing safeguard.
If MFA will be enabled next month, the current risk rating should reflect the security environment today.
Create the risk treatment plan
Risks that exceed the organisation’s acceptance criteria need treatment.
The risk treatment plan records what the organisation intends to do.
Useful information may include:
Risk reference
Required action
Control
Owner
Target date
Current status
Expected residual risk
Supporting evidence
A treatment action should be specific.
“Improve access security” provides little value.
“Require MFA for all users of the customer service platform” gives the organisation a measurable action.
Understand the 93 Annex A controls
ISO/IEC 27001:2022 contains 93 controls within Annex A.
These cover organisational, people, physical and technological security.
Areas include:
Information security policies
Access management
Supplier relationships
Cloud services
Incident management
Business continuity
Employee awareness
Physical protection
Authentication
Malware protection
Backup
Logging
Monitoring
Vulnerability management
Network security
Secure development
Do not assume the organisation must implement every control.
The organisation first determines what controls it needs through risk treatment and other requirements.
It then compares those decisions against Annex A to make sure it has not overlooked something relevant.
Create the Statement of Applicability
The Statement of Applicability, often shortened to SoA, records the organisation’s control decisions.
It should identify the necessary controls and explain why the organisation needs them.
It should record whether those controls have been implemented.
It should also justify relevant Annex A exclusions.
This document connects risk assessment with the control environment.
Suppose the risk register identifies administrator account compromise as a major concern.
The SoA should reflect relevant authentication, access management and monitoring controls.
A supplier risk should connect with appropriate supplier controls.
The documents should support each other.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets ISO/IEC 27001 requirements within its defined scope.
Certification does not guarantee that the organisation will never experience a security incident.
Instead, it demonstrates that the business uses a structured and independently assessed approach to information security management.
ISO states that organisations can use ISO/IEC 27001 to demonstrate to interested parties that they have established a system for managing information security risks.
Customers often value this assurance because it gives them something stronger than a supplier simply saying that it takes cyber security seriously.
Build the required documented information
ISO 27001 requires documented information to support the ISMS.
The exact set should reflect the organisation.
Common records and documents may include:
ISMS scope
Information security policy
Risk methodology
Risk register
Risk treatment plan
Statement of Applicability
Information security objectives
Roles and responsibilities
Internal audit records
Management review records
Corrective actions
Evidence of control operation
Avoid producing unnecessary documents.
The strongest ISMS contains enough documentation to make responsibilities and processes clear without overwhelming employees.
Set information security objectives
Information security objectives turn management intent into measurable progress.
Examples could include:
Increasing MFA coverage
Reducing overdue vulnerabilities
Improving supplier security reviews
Completing access reviews
Improving recovery testing
Reducing overdue risk treatment actions
Each objective should have an owner and a way to measure progress.
Management should review results.
Objectives also provide valuable evidence that the organisation actively improves its ISMS.
Address competence and awareness
Employees whose work affects information security need appropriate competence.
The wider workforce also needs enough awareness to understand its responsibilities.
Training may cover:
Phishing
Authentication
Information handling
Incident reporting
Document sharing
Remote working
Data protection
Use of approved systems
Role-specific employees may need deeper knowledge.
An administrator needs stronger technical competence.
A risk owner needs to understand risk decisions.
An internal auditor needs appropriate audit competence.
Training should support actual responsibilities.
Start collecting evidence immediately
Do not wait until the external audit to think about evidence.
Evidence develops while controls operate.
Examples include:
Access review records
Training records
Supplier assessments
Backup tests
Incident records
Security monitoring information
Risk approvals
Vulnerability remediation
Policy acknowledgements
Management decisions
A written policy says what should happen.
Evidence demonstrates what happened.
This distinction becomes extremely important during certification.
Operate the ISMS before external audit
A new organisation cannot realistically create every document one day and expect to demonstrate a mature operating system the next.
Controls need time to generate evidence.
Risk treatment actions need implementation.
Employees need awareness.
Management needs information to review.
Internal audit needs something real to test.
Allow the ISMS to operate and produce records.
This gives an external auditor a much clearer picture of effectiveness.
Complete internal audit
Internal audit checks whether the ISMS meets ISO 27001 requirements and the organisation’s own requirements.
It should look at real processes.
For example:
Select a recent employee departure and check whether access ended correctly.
Review a supplier and check whether the expected security assessment took place.
Review an information security risk and check whether treatment aligns with the controls.
Inspect training records.
Review policy implementation.
Check evidence supporting the SoA.
Internal audit should identify genuine weaknesses.
Finding an issue internally gives the organisation an opportunity to improve before certification.
Hold management review
Senior management must review the ISMS.
Management review gives leaders a structured opportunity to assess whether information security remains effective and aligned with the business.
Useful areas include:
Audit results
Risks
Objectives
Incidents
Corrective actions
Changes affecting the ISMS
Supplier issues
Resource needs
Improvement opportunities
The review should produce decisions where appropriate.
A management meeting that simply records that everything is satisfactory provides limited value.
Correct nonconformities
When the organisation identifies a failure to meet a requirement, it needs to respond.
Correct the immediate issue where appropriate.
Then consider why it happened.
Suppose a former employee still has access to Microsoft 365.
Disabling the account fixes the immediate exposure.
A proper corrective action investigates why the departure process failed.
Perhaps HR did not notify IT.
Maybe nobody owned the account-removal activity.
Fixing the underlying process reduces the chance of recurrence.
Prepare for the external certification assessment
Once the ISMS operates effectively, the organisation can proceed towards independent certification.
The external assessment normally examines both readiness and operational effectiveness.
Auditors may review documentation, speak with employees, sample controls and inspect evidence.
They want to determine whether the ISMS genuinely works.
Do not train employees to memorise ISO terminology.
They should understand their actual responsibilities.
A member of staff should know how to report an incident even if they cannot name the clause that requires it.
How the Certification Works
The certification route normally starts with preparation and implementation.
The business defines scope, understands its context, assesses information security risks, treats unacceptable risks, selects controls, prepares the SoA and operates the management system.
Internal audit and management review then check readiness.
An independent certification body conducts the external assessment.
A successful assessment can result in ISO 27001 certification for the stated scope.
After certification, the organisation continues maintaining, auditing, reviewing and improving its ISMS.
UK Cyber Compliance’s current guidance describes the certification route as building a working ISMS, completing internal audit and management review, addressing corrective action and then proceeding to independent external assessment.
Certification therefore represents the start of ongoing assurance rather than the end of information security work.
ISO 27001 Certification Levels
ISO 27001 does not use official achievement bands such as bronze, silver or gold.
An organisation either achieves certification for the defined ISMS scope or it does not.
Businesses may still demonstrate different levels of security maturity.
One organisation may operate a recently established ISMS with straightforward controls.
Another may have years of audit evidence, advanced monitoring, mature supplier governance and highly developed risk management.
Both can hold certification to ISO/IEC 27001.
UK Cyber Compliance’s current ISO 27001 guidance also makes clear that the standard does not operate through formal achievement bands.
Continual improvement allows the ISMS to mature over time.
Current UK cyber statistics show why risk management matters
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber security breach or attack during the previous 12 months. That represents approximately 612,000 UK businesses.
Reported incidence increased with organisation scale. The survey found that 65 per cent of medium businesses and 69 per cent of large businesses identified a breach or attack. Small businesses reported 46 per cent.
Phishing remained the most commonly identified attack, affecting 38 per cent of businesses.
Despite this exposure, only 30 per cent of businesses reported carrying out a cyber security risk assessment during the previous year. Only 15 per cent formally reviewed cyber risks from immediate suppliers, while 6 per cent reviewed the wider supply chain.
These figures show why structured security governance matters.
ISO 27001 gives businesses a repeatable process for understanding risk before an incident happens.
Who needs iso 27001 certification
ISO 27001 can benefit organisations that depend on information or need to demonstrate strong information security governance.
This may include:
Software companies
Technology providers
Managed service providers
Professional firms
Healthcare suppliers
Manufacturers
Charities
Financial organisations
Public sector suppliers
Defence suppliers
Cloud service providers
Certification can become particularly valuable when customers repeatedly request security assurance.
A recognised certification can support tenders, supplier assessments and customer confidence.
ISO confirms that organisations across public, private and not-for-profit sectors use ISO/IEC 27001.
The decision should still follow business need.
Some organisations implement ISO 27001 practices without seeking formal certification.
Others require the independent certificate for commercial reasons.
Small businesses should keep the process proportionate
ISO 27001 does not need to become an enormous bureaucracy.
A small company may have a focused scope, concise policies, a manageable risk register and straightforward management processes.
The key requirements remain the same, but implementation should reflect the organisation.
A smaller business might have one person coordinating several control areas.
A larger organisation may have dedicated teams.
Both can operate an effective ISMS when responsibilities remain clear and evidence supports the controls.
Complexity should follow business need rather than the desire to make the ISMS look impressive.
Cyber Essentials can provide useful foundations
Many UK businesses already hold Cyber Essentials.
That work can support ISO 27001.
Existing technical measures around secure configuration, access management, malware protection and security updates can provide useful controls.
Cyber Essentials does not replace ISO 27001.
ISO 27001 goes much further into management, risk, suppliers, business processes, audit, governance and continual improvement.
Existing Cyber Essentials evidence can still give the organisation a useful starting point.
Supplier security needs attention from the beginning
Most organisations depend on external providers.
These may include:
Cloud services
Managed IT
Software providers
Payroll services
Security monitoring
Telecommunications
Professional advisers
Data processors
Identify the suppliers that could materially affect information security.
Ask what information they access.
Consider what happens if they become unavailable.
Review whether contractual security requirements exist.
Decide how the organisation will assess supplier security.
The latest government survey found that formal supplier cyber-risk review remains relatively uncommon among UK businesses.
ISO 27001 gives organisations a framework for improving this area.
Do not forget business continuity
Availability forms part of information security.
Understand which services the business cannot easily operate without.
Identify supporting systems and suppliers.
Consider backup.
Review recovery arrangements.
Test important assumptions.
A backup process that has never successfully restored information provides weaker assurance than one that receives regular testing.
Continuity planning should follow business impact and information security risk.
Integrate security with employee processes
Connect the ISMS with everyday employment activity.
When someone joins, give them appropriate access and awareness.
When their role changes, review permissions.
When they leave, remove access promptly.
These processes create useful evidence and reduce risk.
The strongest ISO 27001 systems become embedded in normal operations rather than creating separate audit-only activity.
Make control ownership clear
Every important control should have someone responsible for making it work.
Examples include:
HR owning employee security processes.
IT owning authentication controls.
Procurement owning supplier assessments.
Operations owning continuity activity.
Security teams owning monitoring.
Managers owning access approvals.
Clear ownership prevents controls becoming neglected after the initial certification project.
Which UK-based firms offer ISO 27001 consultancy services?
UK businesses can obtain ISO 27001 assistance from information security consultancies, managed service providers, audit professionals and platform-led compliance providers.
UK Cyber Compliance provides structured ISO 27001 support through its automated and AI-driven platform.
Its current platform includes step-by-step workflows, guided risk assessment, residual risk tracking, control coverage, policy generation, progress monitoring and audit-ready evidence reporting.
A useful ISO 27001 provider should help the organisation understand its own ISMS rather than simply supply a collection of generic documents.
The business should remain capable of explaining:
Its scope
Its information security risks
Its risk acceptance criteria
Its controls
Its SoA
Its evidence
Its audit findings
Its improvement activity
External support works best when it builds internal understanding.
How UK Cyber Compliance supports the initial requirements
The early stages of ISO 27001 can become difficult when organisations rely on separate spreadsheets, shared folders and email messages.
Risk information may sit in one location.
Controls may sit somewhere else.
Policies may have different owners.
Audit evidence may become difficult to find.
UK Cyber Compliance brings this information together within a central platform.
Its current website describes guided workflows that walk organisations through ISO 27001 requirements, intelligent risk assessment, AI-powered policy generation, live progress monitoring and generation of audit-ready evidence packs, risk reports and Statement of Applicability documentation.
This can make the initial requirements easier to organise.
Technology does not remove management responsibility.
The business still needs to understand its context, define scope, assess risks and make informed decisions.
The platform helps structure and record that work.
A practical starting checklist
Before moving towards external certification, check that the organisation has addressed the following:
- The business understands why it wants ISO 27001.
- Senior management supports the ISMS.
- Someone coordinates implementation.
- The ISMS scope has been clearly defined.
- Internal and external business issues have been considered.
- Relevant interested parties have been identified.
- Relevant information security obligations are understood.
- The organisation has an information security policy.
- Security responsibilities have been assigned.
- A risk assessment methodology exists.
- Risk acceptance criteria have been agreed.
- Information security risks have been identified.
- Risk owners have been assigned.
- Current controls have been documented.
- Unacceptable risks have treatment plans.
- Annex A controls have been considered.
- The Statement of Applicability has been prepared.
- Relevant policies and processes reflect actual operations.
- Information security objectives have been established.
- Relevant employees have appropriate awareness and competence.
- Controls have operated long enough to produce useful evidence.
- Internal audit has taken place.
- Senior management has reviewed the ISMS.
- Identified weaknesses have received appropriate corrective action.
- Evidence remains organised and available for assessment.
An organisation that can answer these points clearly has built much of the foundation needed for certification.
Where should a business start first?
If your organisation has decided to pursue ISO 27001, start with four activities.
First, establish why certification matters.
Second, secure leadership support and nominate someone to coordinate the ISMS.
Third, define the proposed certification scope.
Fourth, complete a structured gap review against the current ISO/IEC 27001:2022 requirements.
Once those foundations exist, build the risk methodology and identify the information, services, systems, people and suppliers that need protection.
Risk assessment then drives treatment.
Treatment drives control selection.
Control decisions feed the Statement of Applicability.
Policies support those controls.
Operational activity generates evidence.
Internal audit tests the system.
Management review provides leadership oversight.
Independent certification can then assess whether the ISMS works as intended.
ISO confirms that ISO/IEC 27001:2022 remains the published current standard, with Amendment 1:2024 applying climate action changes to the management system requirements.
UK Cyber Compliance provides an automated and AI-driven platform that can help organisations organise this process through guided risk assessment, control management, policies, progress tracking and audit-ready evidence.
The initial requirements become far easier to manage when the business follows them in the right order. Start with context, leadership, scope and risk. Build the controls around real business needs. Gather evidence as the ISMS operates. That approach creates a management system that supports certification while also improving the organisation’s everyday information security.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

