ISO 27001 Implementation Methodology & Project Plan
Provides a phased implementation route from scoping to certification audit with the sequencing that avoids rework.
Available soon
- Format
- Word
- Size
- 70 KB
- Length
- 23 pages
- Version
- 1.1
- Updated
What's inside
- Purpose
- The rules
- Principles
- Inputs
- The phased route
- Sequencing that avoids rework
- Scoping decisions
- Measuring readiness
- Roles and effort
- What it costs
- Where other CISO Times packs help
- Worked examples
- Common failure modes
- How to defend the plan to an auditor
- Limitations
- Calibration and review
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This methodology is how [[Organisation Name]] takes its information security management system (ISMS) from a decision to a certificate under ISO/IEC 27001:2022. It sets the rules IS-01 to IS-10, the six phases and the order they run in, the decisions that make or break a first certification, who does what, and what it costs. It ends with a worked plan and the failure modes that most often turn a first audit into a second one.
It is written for the person who has to deliver the certificate: often an IT manager or a new head of security in an organisation of [[100 to 300]] people that already has some controls but no management system around them. Every other document in the ISO 27001 Implementation & Certification Readiness pack applies these rules and cites them by number.
The plan is built backwards from what an auditor needs to see: records of an ISMS that has been running, not a set of documents written for the audit. That is why the longest phase is the one in which nothing new is written.
Guidance — delete before approval
Replace the durations, ranges and dates in [[double brackets]] with your own before approval. The EXAMPLE plan shows how to compute them; your plan should be computed the same way, from your own start date and booked audit dates.
If a customer, tender or regulator has set a deadline, write it down now. Plan from that date backwards, phase by phase, as well as from today forwards (as Example 1 does), and tell top management at the first gate whether the two meet.
The rules
These ten rules are the method. The sections that follow explain each one; the rest of the pack quotes them by number.
IS-01 Top management must approve the scope, the policy and the resources before the project starts.
IS-02 The scope must name the organisation, locations, services and interfaces it covers, and anything excluded with the reason.
IS-03 Controls must be chosen from the risk assessment, not from the Annex A list; the Statement of Applicability must justify every inclusion and exclusion.
IS-04 Every required document and record (MANDATORY) must exist, be approved and be kept under document control.
IS-05 The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit.
IS-06 At least one full internal audit cycle and one management review must be completed before Stage 2.
IS-07 Internal auditors must not audit their own work.
IS-08 Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date.
IS-09 Nonconformities from audits must get a root cause, a correction, a corrective action and a check that it worked.
IS-10 Readiness must be reassessed monthly from the start of Phase 4 until certification.
In IS-04, MANDATORY means the documents and records the standard requires, listed by clause in the Mandatory ISMS Documentation Checklist.
Guidance — delete before approval
IS-05 carries a template default of [[3]] months. Ask your certification body what operating period it expects before Stage 2 and set the rule to that, never shorter. Change it here and in the Certification Readiness Self-Assessment together: its top readiness level uses the same period.
Principles
Most arguments about the plan are settled by one of these.
- Records, not documents. Most of the documented information the standard requires is evidence that something happened. An auditor samples records over time; a document written the week before the audit has no history (IS-05).
- Risk chooses the controls. Controls come from the risk assessment. Annex A is a list to check against so that nothing needed is missed, not a list to implement (IS-03).
- Scope decides the size of everything. A scope that is too wide multiplies the work; one that is too narrow produces a certificate customers do not value. Settle it first and change it only through top management (IS-01, IS-02).
- Top management owns it. The ISMS is a management system: approvals, objectives, resources and the review are top management's, and the auditor will ask them, not the ISMS manager (IS-01).
- Use what already exists. Most organisations have access reviews, backups, supplier checks and incident handling in some form. Bring them into the ISMS and start keeping records; do not rebuild them.
- Audit yourself first. The internal audit and the management review are rehearsals for Stage 2 and requirements in their own right (IS-06, IS-07).
- The plan is a measure, not a promise. Readiness is reassessed monthly and the Stage 2 date is moved deliberately, early, if the evidence says so (IS-08, IS-10).
Inputs
Gather these in Phase 1. Where one does not exist, the phase that creates it is shown.
Input | Why the plan needs it | Where it comes from | If it does not exist |
|---|---|---|---|
The reason for certifying | Sets the scope and the date: which customers, tenders or regulators will read the certificate, and by when. | Sales, contracts, the board, the regulator | Ask the sponsor to write one paragraph; do not start without it |
Services and locations | The raw material of the scope (IS-02). | Service catalogue, contracts, facilities list | List them in Phase 1 |
Legal, regulatory and contractual requirements | They shape the scope, the risks and the controls. | Legal, compliance, customer contracts | List them in Phase 1; see the regulated-entity note in 'Adapting this template' |
Existing policies and procedures | Many can be adopted rather than written. | The policy register; Policy Register & Review Schedule if you use it | Written in Phase 3, only where a chosen control needs one |
Existing risk register and method | Phase 2 starts from it. | Risk function; Information Security Risk Register if you use it | Created in Phase 2 |
Current controls and their records | Shows how far each requirement is from readiness 3. | Control owners | Scored in the Certification Readiness Self-Assessment |
Supplier list | Suppliers that touch in-scope information are part of the scope's interfaces. | Procurement; Supplier Security Risk Register if you use it | Listed in Phase 2 |
Budget and people | Top management approves them at the first gate (IS-01). | Sponsor | See 'Roles and effort' and 'What it costs' |
The phased route
Six phases, 38 weeks of work in total for an organisation of [[100 to 300]] people starting with some controls in place. Each phase ends at a gate: the next phase does not start until the gate's evidence exists.
Phase | Weeks | Output | Clauses it first satisfies |
|---|---|---|---|
Phase 1 — Decide and scope | 3 | Management commitment, ISMS scope (4.3), project plan | 4.1, 4.2, 4.3, 5.1, 5.3, 7.1 |
Phase 2 — Assess risk | 5 | Risk method, risk assessment, treatment plan (6.1) | 6.1.1, 6.1.2, 8.2 |
Phase 3 — Select and document controls | 6 | Statement of Applicability, policies and procedures | 5.2, 6.1.3, 6.2, 7.5, 4.4 |
Phase 4 — Implement and operate | 12 | Controls working and producing records (8.1) | 7.2, 7.3, 7.4, 8.1, 8.3, 9.1, 6.3 |
Phase 5 — Check | 4 | Internal audit (9.2) and management review (9.3) completed | 9.2, 9.3, 10.1, 10.2 |
Phase 6 — Certify | 8 | Stage 1 audit, fixes, Stage 2 audit, certificate | 10.2 |
Weeks are calendar weeks of elapsed time, not effort. Phase 4 cannot be compressed by adding people: it is the time the controls need to produce records (IS-05). Phases 1 to 3 can be shortened by a smaller organisation or one with more already in place.
Guidance — delete before approval
The durations are template defaults. Replace them with your own estimates after the first readiness assessment in the Certification Readiness Self-Assessment. Keep the time from the start of Phase 4 to the Stage 2 date at least as long as the IS-05 operating period.
Phase 1 — Decide and scope (3 weeks)
- Agree why the organisation wants the certificate, and what a customer or regulator will read it for.
- Record the issues and interested parties that shape the ISMS, and their requirements.
- Draft the scope statement (IS-02) and test it against the services customers buy.
- Name the sponsor, the ISMS manager and the control owners; agree the budget and the time they have.
- Take scope, policy direction and resources to top management for approval (IS-01).
Clauses: 4.1 Understanding the organization and its context; 4.2 Understanding the needs and expectations of interested parties; 4.3 Determining the scope of the information security management system; 5.1 Leadership and commitment; 5.3 Organizational roles, responsibilities and authorities; 7.1 Resources.
Gate: Top management has approved the scope, the policy direction and the resources, in a minute or signed record (IS-01).
Phase 2 — Assess risk (5 weeks)
- Approve the risk method before anyone scores a risk: criteria, scales, who may accept.
- Build the inventory of assets and services in scope, with owners.
- Assess risks with the owners who would feel the harm, and record the results.
- Draft the risk treatment plan: for each risk outside appetite, the treatment, owner and date.
Clauses: 6.1.1 General; 6.1.2 Information security risk assessment; 8.2 Information security risk assessment.
Gate: Every in-scope service has assessed risks with owners; the treatment plan is drafted; the risk owners have seen their risks.
Phase 3 — Select and document controls (6 weeks)
- Choose controls from the treatment plan, then compare them with Annex A so nothing needed is missed (IS-03).
- Complete the Statement of Applicability: every one of the 93 controls, included or excluded, with the reason and its status.
- Write or adapt only the policies and procedures the chosen controls need, and approve them (IS-04).
- Set the information security objectives, with measures, owners and dates.
- Select and book the certification body; agree the Stage 1 and Stage 2 dates.
Clauses: 5.2 Policy; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 7.5 Documented information; 4.4 Information security management system.
Gate: The Statement of Applicability, the treatment plan and the policy set are approved; risk owners have accepted the residual risks; the audit dates are booked.
Phase 4 — Implement and operate (12 weeks)
- Put the missing controls in place, in the order the gap tracker's critical path sets (IS-08).
- Run every control on its cycle so it produces records: reviews, logs, tickets, training, supplier checks.
- Start measuring the objectives and the headline measures, and reassess readiness every month (IS-10).
- Train the people in scope and record who completed what.
Clauses: 7.2 Competence; 7.3 Awareness; 7.4 Communication; 8.1 Operational planning and control; 8.3 Information security risk treatment; 9.1 Monitoring, measurement, analysis and evaluation; 6.3 Planning of changes.
Gate: Every applicable control is at readiness 2 or better, the blocking items are operating, and the ISMS has run for [[3]] months, or will have by Stage 2 (IS-05).
Phase 5 — Check (4 weeks)
- Run a full internal audit across the clauses and the applicable controls, by auditors who do not audit their own work (IS-06, IS-07).
- Raise nonconformities and start corrective action on each (IS-09).
- Hold the management review with the audit results, the measures and the risk position as inputs, and minute its decisions.
Clauses: 9.2 Internal audit; 9.3 Management review; 10.1 Continual improvement; 10.2 Nonconformity and corrective action.
Gate: The internal audit report and the management review minutes exist; every nonconformity has an owner, a date and a root cause.
Phase 6 — Certify (8 weeks)
- Stage 1: the certification body reviews the documentation and whether the organisation is ready for Stage 2.
- Close the Stage 1 concerns before Stage 2.
- Stage 2: the certification body samples controls in operation and their records.
- Answer any nonconformities with a correction and corrective action plan (IS-09); the certification body decides.
Clauses: 10.2 Nonconformity and corrective action.
Gate: The certification body has recommended certification and the certificate names the approved scope.
Sequencing that avoids rework
Most rework in a first certification comes from doing a step before the step it depends on. Keep this order even when a later step looks quicker.
Do this first | Before this | Because | Rule |
|---|---|---|---|
Scope (PH-1) | Asset inventory and risk assessment (PH-2) | Every inventory row and risk depends on what is in scope. A scope changed after the risk assessment means reassessing. | IS-02 |
Approved risk method | Scoring any risk | Risks scored before the criteria are fixed are scored again once they are, and the first scores confuse the owners. | IS-03 |
Risk assessment and treatment plan (PH-2) | Statement of Applicability (PH-3) | The Statement of Applicability justifies each control by the risk it treats. Written first, it becomes an Annex A checklist that has to be rewritten. | IS-03 |
Statement of Applicability (PH-3) | Writing policies and procedures | Only the controls chosen need documents. Writing a full policy set first produces documents nobody runs, which the auditor then samples. | IS-03, IS-04 |
Booking the certification body (PH-3) | Committing to a Stage 2 date | Auditors are booked weeks or months ahead; the date you want may not be available. | IS-08 |
Controls operating (PH-4) | Internal audit (PH-5) | An internal audit of controls with no records finds only that there are no records, and has to be repeated. | IS-05, IS-06 |
Internal audit (PH-5) | Management review (PH-5) | Audit results are an input to the review. A review held before the audit has to be held again. | IS-06 |
[[3]] months of operation (IS-05) | Stage 2 audit (PH-6) | The auditor samples records over time. Writing more documents does not create a history of operation. | IS-05 |
Stage 1 concerns closed | Stage 2 audit | A concern left open at Stage 1 is likely to return as a nonconformity at Stage 2. | IS-09 |
Two things can run alongside the phases rather than after them: staff awareness training, which can start as soon as the policy direction is approved, and the asset inventory, which can start as soon as the scope is drafted.
Scoping decisions
IS-02: The scope must name the organisation, locations, services and interfaces it covers, and anything excluded with the reason.
The scope is the first thing the certification body reads and the only thing a customer reads on the certificate. It is decided in Phase 1 and approved by top management (IS-01). The standard's requirement is clause 4.3 Determining the scope of the information security management system.
What the scope statement names
Element | What to write | Common mistake |
|---|---|---|
Organisation | The legal entities or business units covered. | Naming the group when only one company is ready. |
Services and activities | What is delivered to customers, in the customers' words. | Listing departments instead of services. |
Locations | Offices, data centres and remote working, including cloud regions if they matter to customers. | Leaving out home working, which almost every scope includes in practice. |
Technology | The platforms the services run on, including cloud services. | Treating the cloud provider's platform as out of scope rather than as an interface. |
Interfaces and dependencies | Where the scope meets things outside it: group IT, suppliers, shared services, customers' systems. | Not naming them, so the auditor cannot tell where responsibility changes hands. |
Exclusions | Anything left out, with the reason. | Excluding something the in-scope services depend on. |
Include or exclude
Decision | Include it when | Exclude it when | If excluded |
|---|---|---|---|
A second site | In-scope services are delivered or supported from it. | It does no work for the in-scope services. | State that it is excluded and why; control any access it has to in-scope systems. |
Development | You build the software you deliver. | You buy it and only configure it. | Treat the software supplier under your supplier controls. |
A subsidiary or group IT | It runs systems the scope depends on and will give the auditor access. | It is a separate business with its own management. | Name it as an interface, with an agreement covering the services it provides. |
Corporate functions (HR, finance, legal) | Almost always: people, contracts and legal duties touch every scope. | Rarely justified. | Expect the auditor to ask how screening, contracts and legal requirements are met. |
A new service not yet live | It will be live and producing records by Stage 2. | It will not have run for the IS-05 period. | Add it at a surveillance audit once it has records. |
Tests a scope should pass
- A customer reading the certificate would recognise the service they buy.
- Every exclusion has a reason that does not amount to 'not ready'.
- Nothing excluded is something an in-scope service cannot run without; where it is, it is named as an interface and controlled.
- It can be delivered in the plan's time: every in-scope service can have records for the IS-05 period by Stage 2.
- Top management has approved it and knows what it leaves out (IS-01).
EXAMPLE scope statement. The design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. The EXAMPLE firm is a software services company with 240 staff in two offices, an NIS2 important entity; its corporate functions support every service and are in scope. Its main interface is the provider of the cloud platform its services run on, which the scope names and which is managed as a supplier.
Guidance — delete before approval
Exclusions of Annex A controls are a different thing from exclusions from the scope. A control is excluded in the Statement of Applicability when no risk in scope needs it; a part of the organisation is excluded from the scope when it plays no part in the in-scope services. Do not use one to avoid the other.
A first scope can be narrower than the organisation's eventual ambition. Widening it later is normal and is audited at a surveillance or recertification audit. Narrowing it after Stage 1 is expensive.
Measuring readiness
The readiness scale
Every clause requirement and every applicable Annex A control is scored on one scale in the Certification Readiness Self-Assessment. The scale is what IS-10's monthly reassessment uses.
Score | Level | Meaning |
|---|---|---|
0 | Not started | Nothing exists yet. |
1 | Planned | Owner and approach agreed; not yet in place. |
2 | In place | Documented and working, but little or no record yet. |
3 | Operating | Working, with records covering at least [[3]] months, and an auditor could sample it. |
A requirement reaches 3 only with records an auditor could sample. Because it takes [[3]] months of records, any control first put in place after 1 December 2026 cannot be at 3 by the EXAMPLE Stage 2 date of 1 March 2027.
Blocking items
A blocking item is one without which a Stage 2 audit cannot pass. All 8 must reach readiness 3 (Operating) before the Stage 2 date.
Clause | Title | Phase that creates it |
|---|---|---|
4.3 | Determining the scope of the information security management system | PH-1 |
5.2 | Policy | PH-3 |
6.1.2 | Information security risk assessment | PH-2 |
6.1.3 | Information security risk treatment | PH-3 |
6.2 | Information security objectives and planning to achieve them | PH-3 |
9.2.2 | Internal audit programme | PH-5 |
9.3.3 | Management review results | PH-5 |
10.2 | Nonconformity and corrective action | PH-5, PH-6 |
Headline measures
Reported to top management every month from the start of Phase 4 (IS-10), and to the executive sponsor at every gate.
Measure | Definition | Target |
|---|---|---|
ISM-01 Blocking items operating | Blocking items at readiness 3, out of all blocking items. | All, before the Stage 2 date |
ISM-02 Requirements operating | Clause requirements and applicable Annex A controls at readiness 3, out of all of them. | Rising monthly |
ISM-03 Gaps overdue | Open gaps past their date. | Zero on the critical path |
ISM-04 Weeks to certification | Estimated weeks to the Stage 2 audit from the open gaps and IS-05. | On or before the planned date |
Decision logic
ISM-04 (Weeks to certification) is worked out each month as follows, and compared with the booked Stage 2 date.
- (a) Work finished. Each owner works through their open gaps one after another, blocking items first, then in the standard's order (IS-08). The date the last gap reaches readiness 2 (In place) is (a).
- (b) Operating period. The date the last blocking item reaches readiness 2, plus [[3]] months (IS-05), is (b): the earliest date every blocking item could be Operating.
- (c) Internal audit and management review. The later of: the date the internal audit programme is in place plus the Check phase (4 weeks), the planned end of audit fieldwork, and the planned management review (IS-06). That is (c).
- The estimate is the latest of (a), (b) and (c): the earliest date Stage 2 could pass. ISM-04 is the weeks from today to that date, rounded up.
- The critical path is every gap whose slip of 2 weeks or less would move the estimate. If the estimate falls after the booked Stage 2 date, tell the executive sponsor the same month and decide: add resource, narrow the scope, or move the date. Do not wait for Stage 1 to decide for you.
The Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker compute this with the same steps, from the same scores, so all three documents give the same date.
Go and no-go
Before | Go when | Otherwise |
|---|---|---|
Confirming Stage 1 (decided at the management review) | Every item in the Mandatory ISMS Documentation Checklist exists and is approved (IS-04); the internal audit and management review are complete (IS-06); ISM-01 shows every blocking item at readiness 2 or better. | Move Stage 1. A Stage 1 that finds missing documents costs a second Stage 1. |
Confirming Stage 2 | ISM-01: every blocking item at readiness 3; the IS-05 period is met; every Stage 1 concern is closed or has an agreed plan. | Move Stage 2, with the certification body's agreement, rather than go in expecting a major nonconformity. |
Roles and effort
One person per role, named in the plan. In a small organisation one person may hold two roles, but the internal auditor never audits their own work (IS-07).
Role | EXAMPLE holder | Responsible for | Typical effort |
|---|---|---|---|
Executive sponsor | [[e.g. Chief Operating Officer]] | Securing people and money; clearing blockers; taking decisions to top management; approving the internal audit programme; deciding when the Stage 2 date moves. | [[1–2]] hours per month, plus the approvals at each gate |
Top management | [[e.g. Executive Committee]] | Approving the scope, policy and resources (IS-01); accepting residual risk; setting objectives; holding the management review. | [[2–4]] hours per month; half a day for the management review |
ISMS manager | [[e.g. Head of Information Security]] | Running the project and the plan; the Statement of Applicability; the readiness reports (IS-10); owning the internal audit programme (clause 9.2.2) without performing its audits; the evidence room; the certification body relationship. | [[Half to full]] time for the length of the project |
Control owners | [[the managers who run each control]] | Putting their controls in place, running them, keeping the records, and answering the auditor about them. | [[1–3]] days per month each while their controls are being put in place; less once they run |
Internal auditor | [[independent of the area audited; internal or contracted]] | Performing the audits in the programme, independent of the areas audited (IS-06, IS-07); reporting nonconformities. | [[5–10]] days for the first full internal audit |
Certification body | [[an accredited certification body]] | Stage 1 and Stage 2, the certification decision and later surveillance audits. | Audit days set by the certification body: see 'What it costs' |
Guidance — delete before approval
Name people, not roles, in your approved plan. Where the ISMS manager is also a control owner, ask another control owner or the internal auditor to check the readiness scores for their controls.
What it costs
Every figure below is an estimate, not a price or a quote, with money in euros, for an organisation of [[100 to 300]] people, stated so you can plan and challenge a quote. Replace each with your own estimates and with quotes from accredited certification bodies before the budget goes to top management.
Item | Estimated range (confirm with quotes) | Notes |
|---|---|---|
Internal effort, all roles | An estimated [[150–300]] person-days in total | The largest cost. Mostly the ISMS manager and the control owners' time. |
Certification body: initial audit (Stage 1 and Stage 2) | An estimated [[10–15]] audit days; an estimated [[€10,000–€25,000]] | Audit days depend mainly on the number of people in scope and the complexity of the scope. Obtain at least [[2]] quotes from accredited certification bodies. |
Certification body: surveillance audits in years two and three | An estimated [[a third]] of the initial fee, each year | Budget for these at the start; the certificate lapses without them. |
Certification body: recertification | An estimated [[two thirds]] of the initial fee, every [[3]] years | A full reassessment before the certificate expires. |
Training | An estimated [[€1,500–€3,000]] per person for a lead implementer or internal auditor course | Optional. Useful for the ISMS manager and at least one internal auditor. |
Contracted internal auditor | An estimated [[5–10]] days at [[day rate]] | Optional. Often the simplest way to meet IS-07 in a small team. |
Consultancy or compliance software | [[€0 upwards]] | Optional. Neither is required by the standard or by the certification body. |
Closing gaps | [[from the gap tracker]] | Tools and services the treatment plan needs, for example backup or logging. Budgeted per gap, not per project. |
The certification body works out audit days from the number of people in scope, the number of sites and the complexity of the scope, following the rules it is accredited under. Ask each body quoting for the days per stage and per surveillance audit, not only the total, and check that the quote covers the three-year cycle (see Stage 1 and Stage 2 Audit Preparation Guide).
Guidance — delete before approval
A lower quote with fewer audit days than other accredited bodies offer for the same scope is worth questioning. A certificate from a body without recognised accreditation may not be accepted by the customers you are certifying for.
Internal effort is usually larger than every external cost together. Budget it as time released from other work, or the project will slip in Phase 4.
Where other CISO Times packs help
Several requirements already have a CISO Times pack. Once running, their records are evidence for the audit. None is required; each is a starting point you adapt.
Requirement | Pack | What it gives you |
|---|---|---|
5.2, 7.5 and A.5.1 Policies for information security | the Security Policy Management pack (P04) | A policy framework (Policy Framework Standard), a template for each document (Security Policy Document Template), and a register with review dates (Policy Register & Review Schedule): the document control IS-04 needs. |
6.1.2, 6.1.3, 8.2 and 8.3 | the Information Security Risk Management pack (P05) | A risk method with criteria (Risk Assessment Methodology & Scoring Model), the register (Information Security Risk Register), the treatment plan (Risk Treatment Plan) and signed acceptances (Risk Acceptance Form & Approval Record): the evidence behind IS-03. |
A.5.19 to A.5.22 on suppliers | the Third-Party Security Risk Management pack (P06) | Supplier tiering (Supplier Criticality & Tiering Model), assessment and a supplier risk register (Supplier Security Risk Register): the records an auditor samples for the scope's interfaces. |
A.5.18 Access rights | the User Access Review pack (P07) | A method for periodic access reviews and the campaign records they produce: the most commonly sampled record of a control in operation. |
The Vulnerability & Exposure Management pack (P01) supports A.8.8, the Security Exception, Waiver & Segregation of Duties pack (P02) supports A.5.36 and the handling of controls not yet met, and the Board Cybersecurity Reporting pack (P03) supports reporting to top management.
EXAMPLE. The EXAMPLE firm already runs the P04 policy register: 10 documents. As at 30 September 2026, 7 are approved and in date, 2 are past their review date (AUP-001 Acceptable Use Policy; BKP-001 Backup Standard) and 1 awaits approval (SUP-001 Supplier Security Policy). Under IS-04 each of these 3 is a gap in the ISMS Gap & Remediation Tracker, with an owner and a date before Stage 1 (IS-08). The Information Security Policy (ISP-001), approved on 12 March 2026 before the project started, is the policy clause 5.2 needs.
Worked examples
Both examples use the EXAMPLE firm used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. All 240 staff are in scope. The project started on 6 April 2026; the certification body has booked Stage 1 for 18 January 2027 and Stage 2 for 1 March 2027. Example 1 is the plan as approved; Example 2 is where the firm actually is, from the same readiness position the Mandatory ISMS Documentation Checklist, the Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker use. All dates are EXAMPLE: replace them with your own.
Example 1 — the plan as approved
Phases 1 to 4 run back to back from the start date, each ending on the Friday of its last week. Phase 5 runs on the dates the internal audit programme fixed (ISMS Internal Audit Programme & Procedure). Phase 6 begins with Stage 1 on its booked date.
Phase | Planned weeks | Starts | Ends |
|---|---|---|---|
Phase 1 — Decide and scope | 3 | 6 April 2026 | 24 April 2026 |
Phase 2 — Assess risk | 5 | 27 April 2026 | 29 May 2026 |
Phase 3 — Select and document controls | 6 | 1 June 2026 | 10 July 2026 |
Phase 4 — Implement and operate | 12 | 13 July 2026 | 2 October 2026 |
Phase 5 — Check | 4 (runs over 10) | 4 November 2026 | 12 January 2027 |
Phase 6 — Certify | 8 | 18 January 2027 | 12 March 2027 |
Phase 5 in detail: audits from 4 November 2026 to 9 December 2026; the programme report on 23 December 2026; the management review on 6 January 2027, which is also the Stage 1 go or no-go; and IA-07, the audit of the management review itself, on 12 January 2027. The checks:
Check | Result | Holds? |
|---|---|---|
Buffer between the planned end of Phase 4 and the first audit | 30 calendar days (5 October 2026 to 4 November 2026) | Yes |
Length of Phase 5 | 10 weeks against 4 planned: the audits are spread out and the report and review fall either side of the year-end closure ([[2]] weeks) | Accepted |
Slack between the last check step and Stage 1 | 6 calendar days (IA-07 on 12 January 2027, Stage 1 on 18 January 2027) | Tight |
IS-05: [[3]] months of operation before Stage 2 | 7 full months, counting from the planned start of Phase 4 on 13 July 2026 | Yes |
IS-06: internal audit and management review before Stage 2 | Management review 6 January 2027, before Stage 1 | Yes |
Stage 1 to Stage 2 | 6 weeks to close Stage 1 concerns; Stage 2 falls in week 7 of Phase 6 | Yes |
Certification body booked | By the end of Phase 3 (10 July 2026): 27 weeks before Stage 1, beyond a typical lead time of [[8 to 12]] weeks | Yes |
IS-10: monthly readiness reassessments | 8 between 13 July 2026 and Stage 2 | Yes |
Latest date a control can start and still have the IS-05 records by Stage 2 | 1 December 2026 | Plan for it |
Where the contingency is. The plan has 30 days of buffer before the audits, only 6 days between the last check step and Stage 1, and 6 weeks between Stage 1 and Stage 2. A slip in Phase 4 can be absorbed before the audits; a slip in Phase 5 moves Stage 1. That is why the check dates are fixed early and protected.
What the certificate date looks like. The certification decision usually follows Stage 2 by [[2 to 6]] weeks, if no major nonconformity is open.
Example 2 — where the firm actually is, and the forecast
As at 30 September 2026 (EXAMPLE; replace with today's date), the project is in week 26 and has held 3 monthly readiness reassessments. It is not on plan:
Gate evidence | Planned by | Actual | Late by |
|---|---|---|---|
Scope approved (ISMS-01, Phase 1 gate) | 24 April 2026 | 11 May 2026 | 2 weeks |
Statement of Applicability and treatment plan approved (ISMS-03, ISMS-04; Phase 3 gate) | 10 July 2026 | 24 August 2026 | 6 weeks |
Phase 4 gate: every applicable control In place, every blocking item Operating | 2 October 2026 | Not met: 40 of 122 applicable requirements below In place; 5 of 8 blocking items below Operating | Open |
The blocking items:
Clause | Title | Readiness |
|---|---|---|
4.3 | Determining the scope of the information security management system | 3 Operating |
5.2 | Policy | 3 Operating |
6.1.2 | Information security risk assessment | 3 Operating |
6.1.3 | Information security risk treatment | 2 In place |
6.2 | Information security objectives and planning to achieve them | 1 Planned |
9.2.2 | Internal audit programme | 1 Planned |
9.3.3 | Management review results | 1 Planned |
10.2 | Nonconformity and corrective action | 1 Planned |
ISM-04, worked by the decision logic above from the same position:
Step | Date | What sets it |
|---|---|---|
(a) Work finished | 3 February 2027 | The last open gap In place, with each owner working through their gaps in turn |
(b) Operating period | 11 February 2027 | The last blocking item In place on 11 November 2026, plus [[3]] months (IS-05) |
(c) Internal audit and management review | 6 January 2027 | The later of the Check phase after the audit programme is in place and the planned audit and review dates (IS-06) |
Earliest Stage 2 | 11 February 2027 | The latest of (a), (b) and (c): 20 weeks from 30 September 2026 |
The estimate of 11 February 2027 is 18 calendar days inside the booked Stage 2 date of 1 March 2027, so the booking holds. But the firm is behind its approved plan, the margin is small, and 3 gaps are on the critical path (9.2.2, 10.2, A.5.7). The executive sponsor is told this month (IS-10), each critical gap is reviewed weekly in the ISMS Gap & Remediation Tracker, and the Phase 4 gate is re-dated rather than declared met.
Common failure modes
Each of these is common in a first certification. Most show up at Stage 1, when they are still cheap to fix.
Failure | How it shows at the audit | How the method prevents it |
|---|---|---|
Controls copied from Annex A | The Statement of Applicability cannot say which risk each control treats; exclusions have no reason. | IS-03; risk assessment before the Statement of Applicability (Sequencing). |
A scope nobody can explain | The auditor cannot tell where the ISMS ends, or finds in-scope services depending on excluded ones. | IS-02; the scope tests; approval by top management (IS-01). |
Documents without records | Policies are approved but there are no reviews, logs or training records to sample. | IS-05: [[3]] months from the start of Phase 4 to Stage 2; readiness 3 needs records. |
A policy toolkit bought whole | Dozens of documents describe processes nobody runs; the auditor samples one and finds it is not followed. | IS-03 and IS-04: write only what the chosen controls need. |
Top management not involved | Nobody at the top can say what the objectives are or what the management review decided. | IS-01; objectives in Phase 3; the management review in Phase 5. |
The internal audit done by the ISMS manager | The auditor finds the ISMS manager audited the ISMS they run. | IS-07; contract an internal auditor if there is nobody independent. |
The internal audit left until the last week | No time to correct what it found; nonconformities are still open at Stage 2. | IS-06; audit dates fixed early, with time after them before Stage 1. |
A Stage 2 date fixed before the plan | The ISMS has run for weeks, not months, when the auditor arrives. | IS-05; plan backwards from the date; go and no-go before Stage 2. |
Gaps with no owner or date | The same gaps are open at every readiness check; the Stage 2 date arrives with blockers open. | IS-08; the ISMS Gap & Remediation Tracker; ISM-03. |
The plan never reassessed | The slip is discovered at Stage 1. | IS-10; ISM-04 every month. |
Findings patched, not fixed | The same nonconformity returns at the first surveillance audit. | IS-09: root cause, correction, corrective action and a check that it worked. |
How to defend the plan to an auditor
The certification body does not audit your project plan, but it will test what the plan produced. It will usually ask how top management showed leadership and commitment (clause 5.1 Leadership and commitment), how the scope was decided (4.3), how controls were chosen from risk (6.1.2 and 6.1.3), what the objectives are and how progress is planned and measured (6.2), and whether the internal audit programme and the management review have run (9.2.2 and 9.3.3).
Evidence to have ready
- The approval by top management of the scope, the policy and the resources, dated before Phase 2 started (IS-01).
- The scope statement, with its interfaces and exclusions and the reason for each (IS-02).
- The risk assessment, the treatment plan and the Statement of Applicability, showing each control traced to a risk (IS-03).
- The Mandatory ISMS Documentation Checklist, completed, with every item approved and under document control (IS-04).
- The monthly readiness reports and headline measures from the start of Phase 4 (IS-10), and the ISMS Gap & Remediation Tracker with an owner and date on every gap (IS-08).
- The internal audit programme, the audit report, the auditors' independence (IS-06, IS-07) and the management review minutes.
- For each nonconformity: the root cause, the correction, the corrective action and the check that it worked (IS-09).
Questions auditors commonly ask about the programme
Question | Answer the method gives |
|---|---|
Why is this the scope? | The scope statement and the Phase 1 approval: the services customers buy, the interfaces and each exclusion with its reason (IS-02). |
How were the controls chosen? | From the treatment plan; Annex A was used as a check (IS-03). The Statement of Applicability names the risk each control treats. |
How long has the ISMS been running? | Since the start of Phase 4; the records sampled cover at least [[3]] months (IS-05). |
How does top management know where you are? | The monthly readiness report with ISM-01, ISM-02, ISM-03, ISM-04 (IS-10), and the management review. |
What happens when something slips? | The gap tracker shows the owner and date; the sponsor decides at the next gate; the Stage 2 date moves early if it must (IS-08). |
Limitations
Limitation | Effect | How it is managed |
|---|---|---|
The durations are typical, not measured for you. | A larger scope, fewer controls in place or less time from control owners makes every phase longer. | Replace them after the first readiness assessment; reassess monthly (IS-10). |
Weeks are elapsed time, not effort. | A plan can be on time while the people doing it are overloaded. | Track effort against 'Roles and effort' at each gate. |
Holidays and busy seasons are not in the arithmetic. | A phase over a holiday period takes longer than its weeks, as the EXAMPLE's Phase 5 does. | Plan the dates, not only the weeks, and keep a buffer. |
Readiness is self-assessed. | Owners tend to score their own controls high. | Evidence for every score of 3; a second person checks; the internal audit tests the scores. |
The certification body's availability is outside your control. | The date you want may not exist. | Book by the end of Phase 3; ask for dates with a lead time of [[8 to 12]] weeks. |
The cost ranges are estimates. | Quotes vary with scope, sites and the body chosen. | Obtain quotes; replace the ranges before the budget is approved. |
Calibration and review
During the project
- At every gate, record the planned and actual weeks for the phase, and recompute the plan from the actual dates.
- Every month from the start of Phase 4, reassess readiness and report the headline measures (IS-10). Recompute ISM-04 with the decision logic above.
- If ISM-04's estimate comes within [[4]] weeks of the booked Stage 2 date, or a blocking item has no date before the Stage 2 date, the sponsor decides the same month: add resource, narrow the scope, or move the date.
- After Stage 2, compare the actual durations with the defaults in this document and record what you would plan differently.
Review of this methodology
This methodology is reviewed at least every 12 months, when the scope changes, after each certification body audit, and when a new edition of the standard is published. After certification it becomes the plan for keeping the ISMS running between surveillance audits: the phases repeat as the yearly cycle of risk assessment, operation, internal audit and management review.
Plan record
Phase | Planned weeks | Actual weeks | Gate date | Approved by | What changed |
|---|---|---|---|---|---|
Phase 1 — Decide and scope | 3 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Phase 2 — Assess risk | 5 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Phase 3 — Select and document controls | 6 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Phase 4 — Implement and operate | 12 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Phase 5 — Check | 4 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Phase 6 — Certify | 8 | [[n]] | [[YYYY-MM-DD]] | [[Name]] | [[—]] |
Related documents
Document | Relationship |
|---|---|
Annex A Control Implementation Library | How to put each Annex A control in place once the Statement of Applicability includes it (Phase 4) |
Statement of Applicability Template | Records the decision and reason for all 93 controls (IS-03, Phase 3) |
Mandatory ISMS Documentation Checklist | The required documents and records, by clause, that IS-04 checks |
Certification Readiness Self-Assessment | Scores readiness on the scale above; the monthly reassessment (IS-10) |
ISMS Gap & Remediation Tracker | Every gap with an owner and a date, and the critical path (IS-08) |
ISMS Internal Audit Programme & Procedure | Plans and runs the internal audit (IS-06, IS-07; Phase 5) |
Management Review Meeting Pack | The management review's agenda, inputs and decisions (IS-06; Phase 5) |
Stage 1 and Stage 2 Audit Preparation Guide | What the certification body asks, samples and challenges at Stage 1 and Stage 2 (Phase 6) |
Adapting this template
Guidance — delete before approval
Small organisation: fewer people shorten Phases 1 to 3, not the IS-05 operating period. A whole-organisation scope is usually simpler than a partial one. One person may be ISMS manager and a control owner, but contract an internal auditor for [[3–5]] days rather than audit your own work (IS-07). Expect fewer audit days and a lower fee.
Regulated entity: ISO/IEC 27001:2022 is the requirement this plan certifies against. Laws such as NIS2 or DORA set their own obligations, for example incident reporting to an authority, that a certificate does not prove. Certification is evidence that a management system is working; it is not compliance with a law. List the legal and regulatory requirements in Phase 1, bring them into the risk assessment, and make sure the scope covers the services the regulation covers, or the certificate will evidence little of what the regulator asks. The EXAMPLE firm is an important entity under NIS2 and plans this way.
IT run by a service provider: the provider's services are interfaces of your scope. Check that each provider's own certificate covers the service you buy; ask for its Statement of Applicability or a summary. Agree in the contract that the provider will supply records for your auditor to sample, such as access reviews and backup tests, because the certification body will sample them as your controls. Manage providers under your supplier controls (the Third-Party Security Risk Management pack (P06)).
If your organisation is already certified to another management system standard, reuse its document control, internal audit and management review arrangements, and ask the certification body about an integrated audit.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 4.3 — Determining the scope of the information security management system | Scoping decisions; IS-02; Phase 1 |
ISO/IEC 27001:2022 | Clause 5.1 — Leadership and commitment | IS-01; roles; the gates; how to defend the plan |
ISO/IEC 27001:2022 | Clause 6.1.2 — Information security risk assessment | Phase 2; sequencing: approved risk method first |
ISO/IEC 27001:2022 | Clause 6.1.3 — Information security risk treatment | IS-03; Phase 3; the Statement of Applicability traced to risk |
ISO/IEC 27001:2022 | Clause 6.2 — Information security objectives and planning to achieve them | Phase 3 objectives; headline measures; decision logic |
ISO/IEC 27001:2022 | Clause 9.2.2 — Internal audit programme | IS-06, IS-07; Phase 5 |
ISO/IEC 27001:2022 | Clause 9.3.3 — Management review results | IS-06; Phase 5; management review minutes as evidence |
NIST CSF 2.0 | GV.OC-01 — “The organizational mission is understood and informs cybersecurity risk management” | Purpose and inputs: the reason for certifying informs the scope |
NIST CSF 2.0 | GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed” | Inputs: legal, regulatory and contractual requirements; regulated-entity tailoring |
NIST CSF 2.0 | GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving” | IS-01; roles: top management accountable for the ISMS |
Definitions
Term | Meaning in this methodology |
|---|---|
Blocking item | A requirement without which a Stage 2 audit cannot pass: clauses 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2. |
Certification body | An organisation accredited to audit and certify management systems against ISO/IEC 27001. |
Control owner | The manager who runs a control and keeps its records. |
Critical path | The chain of gaps and phases whose delay moves the Stage 2 date. |
Gate | The evidence that closes a phase and lets the next one start. |
Information security management system (ISMS) | The policies, processes, people and records through which an organisation manages information security risk. |
Interface | A point where the scope depends on something outside it, such as a supplier or a group function. |
Nonconformity | A requirement not met, found by an internal or certification audit. |
Operating period | The time the ISMS has run and produced records before Stage 2; at least [[3]] months (IS-05). |
Readiness | A score from 0 (Not started) to 3 (Operating) for each requirement. |
Scope | The part of the organisation, its services, locations and technology that the ISMS and the certificate cover. |
Slack | Time between one fixed date in the plan and the next that a slip can use up without moving the audits: the plan's contingency. |
Stage 1 audit | The certification body's review of the documentation and of readiness for Stage 2. |
Stage 2 audit | The certification body's audit of the ISMS in operation, by sampling controls and records. |
Statement of Applicability | The record of every Annex A control: included or excluded, why, and its status. |