Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

ISO 27001 Implementation Methodology & Project Plan

Provides a phased implementation route from scoping to certification audit with the sequencing that avoids rework.

Available soon

Format
Word
Size
70 KB
Length
23 pages
Version
1.1
Updated

What's inside

  • Purpose
  • The rules
  • Principles
  • Inputs
  • The phased route
  • Sequencing that avoids rework
  • Scoping decisions
  • Measuring readiness
  • Roles and effort
  • What it costs
  • Where other CISO Times packs help
  • Worked examples
  • Common failure modes
  • How to defend the plan to an auditor
  • Limitations
  • Calibration and review
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This methodology is how [[Organisation Name]] takes its information security management system (ISMS) from a decision to a certificate under ISO/IEC 27001:2022. It sets the rules IS-01 to IS-10, the six phases and the order they run in, the decisions that make or break a first certification, who does what, and what it costs. It ends with a worked plan and the failure modes that most often turn a first audit into a second one.

It is written for the person who has to deliver the certificate: often an IT manager or a new head of security in an organisation of [[100 to 300]] people that already has some controls but no management system around them. Every other document in the ISO 27001 Implementation & Certification Readiness pack applies these rules and cites them by number.

The plan is built backwards from what an auditor needs to see: records of an ISMS that has been running, not a set of documents written for the audit. That is why the longest phase is the one in which nothing new is written.

Guidance — delete before approval

Replace the durations, ranges and dates in [[double brackets]] with your own before approval. The EXAMPLE plan shows how to compute them; your plan should be computed the same way, from your own start date and booked audit dates.

If a customer, tender or regulator has set a deadline, write it down now. Plan from that date backwards, phase by phase, as well as from today forwards (as Example 1 does), and tell top management at the first gate whether the two meet.

The rules

These ten rules are the method. The sections that follow explain each one; the rest of the pack quotes them by number.

IS-01 Top management must approve the scope, the policy and the resources before the project starts.

IS-02 The scope must name the organisation, locations, services and interfaces it covers, and anything excluded with the reason.

IS-03 Controls must be chosen from the risk assessment, not from the Annex A list; the Statement of Applicability must justify every inclusion and exclusion.

IS-04 Every required document and record (MANDATORY) must exist, be approved and be kept under document control.

IS-05 The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit.

IS-06 At least one full internal audit cycle and one management review must be completed before Stage 2.

IS-07 Internal auditors must not audit their own work.

IS-08 Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date.

IS-09 Nonconformities from audits must get a root cause, a correction, a corrective action and a check that it worked.

IS-10 Readiness must be reassessed monthly from the start of Phase 4 until certification.

In IS-04, MANDATORY means the documents and records the standard requires, listed by clause in the Mandatory ISMS Documentation Checklist.

Guidance — delete before approval

IS-05 carries a template default of [[3]] months. Ask your certification body what operating period it expects before Stage 2 and set the rule to that, never shorter. Change it here and in the Certification Readiness Self-Assessment together: its top readiness level uses the same period.

Principles

Most arguments about the plan are settled by one of these.

  1. Records, not documents. Most of the documented information the standard requires is evidence that something happened. An auditor samples records over time; a document written the week before the audit has no history (IS-05).
  2. Risk chooses the controls. Controls come from the risk assessment. Annex A is a list to check against so that nothing needed is missed, not a list to implement (IS-03).
  3. Scope decides the size of everything. A scope that is too wide multiplies the work; one that is too narrow produces a certificate customers do not value. Settle it first and change it only through top management (IS-01, IS-02).
  4. Top management owns it. The ISMS is a management system: approvals, objectives, resources and the review are top management's, and the auditor will ask them, not the ISMS manager (IS-01).
  5. Use what already exists. Most organisations have access reviews, backups, supplier checks and incident handling in some form. Bring them into the ISMS and start keeping records; do not rebuild them.
  6. Audit yourself first. The internal audit and the management review are rehearsals for Stage 2 and requirements in their own right (IS-06, IS-07).
  7. The plan is a measure, not a promise. Readiness is reassessed monthly and the Stage 2 date is moved deliberately, early, if the evidence says so (IS-08, IS-10).

Inputs

Gather these in Phase 1. Where one does not exist, the phase that creates it is shown.

Input

Why the plan needs it

Where it comes from

If it does not exist

The reason for certifying

Sets the scope and the date: which customers, tenders or regulators will read the certificate, and by when.

Sales, contracts, the board, the regulator

Ask the sponsor to write one paragraph; do not start without it

Services and locations

The raw material of the scope (IS-02).

Service catalogue, contracts, facilities list

List them in Phase 1

Legal, regulatory and contractual requirements

They shape the scope, the risks and the controls.

Legal, compliance, customer contracts

List them in Phase 1; see the regulated-entity note in 'Adapting this template'

Existing policies and procedures

Many can be adopted rather than written.

The policy register; Policy Register & Review Schedule if you use it

Written in Phase 3, only where a chosen control needs one

Existing risk register and method

Phase 2 starts from it.

Risk function; Information Security Risk Register if you use it

Created in Phase 2

Current controls and their records

Shows how far each requirement is from readiness 3.

Control owners

Scored in the Certification Readiness Self-Assessment

Supplier list

Suppliers that touch in-scope information are part of the scope's interfaces.

Procurement; Supplier Security Risk Register if you use it

Listed in Phase 2

Budget and people

Top management approves them at the first gate (IS-01).

Sponsor

See 'Roles and effort' and 'What it costs'

The phased route

Six phases, 38 weeks of work in total for an organisation of [[100 to 300]] people starting with some controls in place. Each phase ends at a gate: the next phase does not start until the gate's evidence exists.

Phase

Weeks

Output

Clauses it first satisfies

Phase 1 — Decide and scope

3

Management commitment, ISMS scope (4.3), project plan

4.1, 4.2, 4.3, 5.1, 5.3, 7.1

Phase 2 — Assess risk

5

Risk method, risk assessment, treatment plan (6.1)

6.1.1, 6.1.2, 8.2

Phase 3 — Select and document controls

6

Statement of Applicability, policies and procedures

5.2, 6.1.3, 6.2, 7.5, 4.4

Phase 4 — Implement and operate

12

Controls working and producing records (8.1)

7.2, 7.3, 7.4, 8.1, 8.3, 9.1, 6.3

Phase 5 — Check

4

Internal audit (9.2) and management review (9.3) completed

9.2, 9.3, 10.1, 10.2

Phase 6 — Certify

8

Stage 1 audit, fixes, Stage 2 audit, certificate

10.2

Weeks are calendar weeks of elapsed time, not effort. Phase 4 cannot be compressed by adding people: it is the time the controls need to produce records (IS-05). Phases 1 to 3 can be shortened by a smaller organisation or one with more already in place.

Guidance — delete before approval

The durations are template defaults. Replace them with your own estimates after the first readiness assessment in the Certification Readiness Self-Assessment. Keep the time from the start of Phase 4 to the Stage 2 date at least as long as the IS-05 operating period.

Phase 1 — Decide and scope (3 weeks)

  • Agree why the organisation wants the certificate, and what a customer or regulator will read it for.
  • Record the issues and interested parties that shape the ISMS, and their requirements.
  • Draft the scope statement (IS-02) and test it against the services customers buy.
  • Name the sponsor, the ISMS manager and the control owners; agree the budget and the time they have.
  • Take scope, policy direction and resources to top management for approval (IS-01).

Clauses: 4.1 Understanding the organization and its context; 4.2 Understanding the needs and expectations of interested parties; 4.3 Determining the scope of the information security management system; 5.1 Leadership and commitment; 5.3 Organizational roles, responsibilities and authorities; 7.1 Resources.

Gate: Top management has approved the scope, the policy direction and the resources, in a minute or signed record (IS-01).

Phase 2 — Assess risk (5 weeks)

  • Approve the risk method before anyone scores a risk: criteria, scales, who may accept.
  • Build the inventory of assets and services in scope, with owners.
  • Assess risks with the owners who would feel the harm, and record the results.
  • Draft the risk treatment plan: for each risk outside appetite, the treatment, owner and date.

Clauses: 6.1.1 General; 6.1.2 Information security risk assessment; 8.2 Information security risk assessment.

Gate: Every in-scope service has assessed risks with owners; the treatment plan is drafted; the risk owners have seen their risks.

Phase 3 — Select and document controls (6 weeks)

  • Choose controls from the treatment plan, then compare them with Annex A so nothing needed is missed (IS-03).
  • Complete the Statement of Applicability: every one of the 93 controls, included or excluded, with the reason and its status.
  • Write or adapt only the policies and procedures the chosen controls need, and approve them (IS-04).
  • Set the information security objectives, with measures, owners and dates.
  • Select and book the certification body; agree the Stage 1 and Stage 2 dates.

Clauses: 5.2 Policy; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 7.5 Documented information; 4.4 Information security management system.

Gate: The Statement of Applicability, the treatment plan and the policy set are approved; risk owners have accepted the residual risks; the audit dates are booked.

Phase 4 — Implement and operate (12 weeks)

  • Put the missing controls in place, in the order the gap tracker's critical path sets (IS-08).
  • Run every control on its cycle so it produces records: reviews, logs, tickets, training, supplier checks.
  • Start measuring the objectives and the headline measures, and reassess readiness every month (IS-10).
  • Train the people in scope and record who completed what.

Clauses: 7.2 Competence; 7.3 Awareness; 7.4 Communication; 8.1 Operational planning and control; 8.3 Information security risk treatment; 9.1 Monitoring, measurement, analysis and evaluation; 6.3 Planning of changes.

Gate: Every applicable control is at readiness 2 or better, the blocking items are operating, and the ISMS has run for [[3]] months, or will have by Stage 2 (IS-05).

Phase 5 — Check (4 weeks)

  • Run a full internal audit across the clauses and the applicable controls, by auditors who do not audit their own work (IS-06, IS-07).
  • Raise nonconformities and start corrective action on each (IS-09).
  • Hold the management review with the audit results, the measures and the risk position as inputs, and minute its decisions.

Clauses: 9.2 Internal audit; 9.3 Management review; 10.1 Continual improvement; 10.2 Nonconformity and corrective action.

Gate: The internal audit report and the management review minutes exist; every nonconformity has an owner, a date and a root cause.

Phase 6 — Certify (8 weeks)

  • Stage 1: the certification body reviews the documentation and whether the organisation is ready for Stage 2.
  • Close the Stage 1 concerns before Stage 2.
  • Stage 2: the certification body samples controls in operation and their records.
  • Answer any nonconformities with a correction and corrective action plan (IS-09); the certification body decides.

Clauses: 10.2 Nonconformity and corrective action.

Gate: The certification body has recommended certification and the certificate names the approved scope.

Sequencing that avoids rework

Most rework in a first certification comes from doing a step before the step it depends on. Keep this order even when a later step looks quicker.

Do this first

Before this

Because

Rule

Scope (PH-1)

Asset inventory and risk assessment (PH-2)

Every inventory row and risk depends on what is in scope. A scope changed after the risk assessment means reassessing.

IS-02

Approved risk method

Scoring any risk

Risks scored before the criteria are fixed are scored again once they are, and the first scores confuse the owners.

IS-03

Risk assessment and treatment plan (PH-2)

Statement of Applicability (PH-3)

The Statement of Applicability justifies each control by the risk it treats. Written first, it becomes an Annex A checklist that has to be rewritten.

IS-03

Statement of Applicability (PH-3)

Writing policies and procedures

Only the controls chosen need documents. Writing a full policy set first produces documents nobody runs, which the auditor then samples.

IS-03, IS-04

Booking the certification body (PH-3)

Committing to a Stage 2 date

Auditors are booked weeks or months ahead; the date you want may not be available.

IS-08

Controls operating (PH-4)

Internal audit (PH-5)

An internal audit of controls with no records finds only that there are no records, and has to be repeated.

IS-05, IS-06

Internal audit (PH-5)

Management review (PH-5)

Audit results are an input to the review. A review held before the audit has to be held again.

IS-06

[[3]] months of operation (IS-05)

Stage 2 audit (PH-6)

The auditor samples records over time. Writing more documents does not create a history of operation.

IS-05

Stage 1 concerns closed

Stage 2 audit

A concern left open at Stage 1 is likely to return as a nonconformity at Stage 2.

IS-09

Two things can run alongside the phases rather than after them: staff awareness training, which can start as soon as the policy direction is approved, and the asset inventory, which can start as soon as the scope is drafted.

Scoping decisions

IS-02: The scope must name the organisation, locations, services and interfaces it covers, and anything excluded with the reason.

The scope is the first thing the certification body reads and the only thing a customer reads on the certificate. It is decided in Phase 1 and approved by top management (IS-01). The standard's requirement is clause 4.3 Determining the scope of the information security management system.

What the scope statement names

Element

What to write

Common mistake

Organisation

The legal entities or business units covered.

Naming the group when only one company is ready.

Services and activities

What is delivered to customers, in the customers' words.

Listing departments instead of services.

Locations

Offices, data centres and remote working, including cloud regions if they matter to customers.

Leaving out home working, which almost every scope includes in practice.

Technology

The platforms the services run on, including cloud services.

Treating the cloud provider's platform as out of scope rather than as an interface.

Interfaces and dependencies

Where the scope meets things outside it: group IT, suppliers, shared services, customers' systems.

Not naming them, so the auditor cannot tell where responsibility changes hands.

Exclusions

Anything left out, with the reason.

Excluding something the in-scope services depend on.

Include or exclude

Decision

Include it when

Exclude it when

If excluded

A second site

In-scope services are delivered or supported from it.

It does no work for the in-scope services.

State that it is excluded and why; control any access it has to in-scope systems.

Development

You build the software you deliver.

You buy it and only configure it.

Treat the software supplier under your supplier controls.

A subsidiary or group IT

It runs systems the scope depends on and will give the auditor access.

It is a separate business with its own management.

Name it as an interface, with an agreement covering the services it provides.

Corporate functions (HR, finance, legal)

Almost always: people, contracts and legal duties touch every scope.

Rarely justified.

Expect the auditor to ask how screening, contracts and legal requirements are met.

A new service not yet live

It will be live and producing records by Stage 2.

It will not have run for the IS-05 period.

Add it at a surveillance audit once it has records.

Tests a scope should pass

  • A customer reading the certificate would recognise the service they buy.
  • Every exclusion has a reason that does not amount to 'not ready'.
  • Nothing excluded is something an in-scope service cannot run without; where it is, it is named as an interface and controlled.
  • It can be delivered in the plan's time: every in-scope service can have records for the IS-05 period by Stage 2.
  • Top management has approved it and knows what it leaves out (IS-01).

EXAMPLE scope statement. The design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. The EXAMPLE firm is a software services company with 240 staff in two offices, an NIS2 important entity; its corporate functions support every service and are in scope. Its main interface is the provider of the cloud platform its services run on, which the scope names and which is managed as a supplier.

Guidance — delete before approval

Exclusions of Annex A controls are a different thing from exclusions from the scope. A control is excluded in the Statement of Applicability when no risk in scope needs it; a part of the organisation is excluded from the scope when it plays no part in the in-scope services. Do not use one to avoid the other.

A first scope can be narrower than the organisation's eventual ambition. Widening it later is normal and is audited at a surveillance or recertification audit. Narrowing it after Stage 1 is expensive.

Measuring readiness

The readiness scale

Every clause requirement and every applicable Annex A control is scored on one scale in the Certification Readiness Self-Assessment. The scale is what IS-10's monthly reassessment uses.

Score

Level

Meaning

0

Not started

Nothing exists yet.

1

Planned

Owner and approach agreed; not yet in place.

2

In place

Documented and working, but little or no record yet.

3

Operating

Working, with records covering at least [[3]] months, and an auditor could sample it.

A requirement reaches 3 only with records an auditor could sample. Because it takes [[3]] months of records, any control first put in place after 1 December 2026 cannot be at 3 by the EXAMPLE Stage 2 date of 1 March 2027.

Blocking items

A blocking item is one without which a Stage 2 audit cannot pass. All 8 must reach readiness 3 (Operating) before the Stage 2 date.

Clause

Title

Phase that creates it

4.3

Determining the scope of the information security management system

PH-1

5.2

Policy

PH-3

6.1.2

Information security risk assessment

PH-2

6.1.3

Information security risk treatment

PH-3

6.2

Information security objectives and planning to achieve them

PH-3

9.2.2

Internal audit programme

PH-5

9.3.3

Management review results

PH-5

10.2

Nonconformity and corrective action

PH-5, PH-6

Headline measures

Reported to top management every month from the start of Phase 4 (IS-10), and to the executive sponsor at every gate.

Measure

Definition

Target

ISM-01 Blocking items operating

Blocking items at readiness 3, out of all blocking items.

All, before the Stage 2 date

ISM-02 Requirements operating

Clause requirements and applicable Annex A controls at readiness 3, out of all of them.

Rising monthly

ISM-03 Gaps overdue

Open gaps past their date.

Zero on the critical path

ISM-04 Weeks to certification

Estimated weeks to the Stage 2 audit from the open gaps and IS-05.

On or before the planned date

Decision logic

ISM-04 (Weeks to certification) is worked out each month as follows, and compared with the booked Stage 2 date.

  1. (a) Work finished. Each owner works through their open gaps one after another, blocking items first, then in the standard's order (IS-08). The date the last gap reaches readiness 2 (In place) is (a).
  2. (b) Operating period. The date the last blocking item reaches readiness 2, plus [[3]] months (IS-05), is (b): the earliest date every blocking item could be Operating.
  3. (c) Internal audit and management review. The later of: the date the internal audit programme is in place plus the Check phase (4 weeks), the planned end of audit fieldwork, and the planned management review (IS-06). That is (c).
  4. The estimate is the latest of (a), (b) and (c): the earliest date Stage 2 could pass. ISM-04 is the weeks from today to that date, rounded up.
  5. The critical path is every gap whose slip of 2 weeks or less would move the estimate. If the estimate falls after the booked Stage 2 date, tell the executive sponsor the same month and decide: add resource, narrow the scope, or move the date. Do not wait for Stage 1 to decide for you.

The Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker compute this with the same steps, from the same scores, so all three documents give the same date.

Go and no-go

Before

Go when

Otherwise

Confirming Stage 1 (decided at the management review)

Every item in the Mandatory ISMS Documentation Checklist exists and is approved (IS-04); the internal audit and management review are complete (IS-06); ISM-01 shows every blocking item at readiness 2 or better.

Move Stage 1. A Stage 1 that finds missing documents costs a second Stage 1.

Confirming Stage 2

ISM-01: every blocking item at readiness 3; the IS-05 period is met; every Stage 1 concern is closed or has an agreed plan.

Move Stage 2, with the certification body's agreement, rather than go in expecting a major nonconformity.

Roles and effort

One person per role, named in the plan. In a small organisation one person may hold two roles, but the internal auditor never audits their own work (IS-07).

Role

EXAMPLE holder

Responsible for

Typical effort

Executive sponsor

[[e.g. Chief Operating Officer]]

Securing people and money; clearing blockers; taking decisions to top management; approving the internal audit programme; deciding when the Stage 2 date moves.

[[1–2]] hours per month, plus the approvals at each gate

Top management

[[e.g. Executive Committee]]

Approving the scope, policy and resources (IS-01); accepting residual risk; setting objectives; holding the management review.

[[2–4]] hours per month; half a day for the management review

ISMS manager

[[e.g. Head of Information Security]]

Running the project and the plan; the Statement of Applicability; the readiness reports (IS-10); owning the internal audit programme (clause 9.2.2) without performing its audits; the evidence room; the certification body relationship.

[[Half to full]] time for the length of the project

Control owners

[[the managers who run each control]]

Putting their controls in place, running them, keeping the records, and answering the auditor about them.

[[1–3]] days per month each while their controls are being put in place; less once they run

Internal auditor

[[independent of the area audited; internal or contracted]]

Performing the audits in the programme, independent of the areas audited (IS-06, IS-07); reporting nonconformities.

[[5–10]] days for the first full internal audit

Certification body

[[an accredited certification body]]

Stage 1 and Stage 2, the certification decision and later surveillance audits.

Audit days set by the certification body: see 'What it costs'

Guidance — delete before approval

Name people, not roles, in your approved plan. Where the ISMS manager is also a control owner, ask another control owner or the internal auditor to check the readiness scores for their controls.

What it costs

Every figure below is an estimate, not a price or a quote, with money in euros, for an organisation of [[100 to 300]] people, stated so you can plan and challenge a quote. Replace each with your own estimates and with quotes from accredited certification bodies before the budget goes to top management.

Item

Estimated range (confirm with quotes)

Notes

Internal effort, all roles

An estimated [[150–300]] person-days in total

The largest cost. Mostly the ISMS manager and the control owners' time.

Certification body: initial audit (Stage 1 and Stage 2)

An estimated [[10–15]] audit days; an estimated [[€10,000–€25,000]]

Audit days depend mainly on the number of people in scope and the complexity of the scope. Obtain at least [[2]] quotes from accredited certification bodies.

Certification body: surveillance audits in years two and three

An estimated [[a third]] of the initial fee, each year

Budget for these at the start; the certificate lapses without them.

Certification body: recertification

An estimated [[two thirds]] of the initial fee, every [[3]] years

A full reassessment before the certificate expires.

Training

An estimated [[€1,500–€3,000]] per person for a lead implementer or internal auditor course

Optional. Useful for the ISMS manager and at least one internal auditor.

Contracted internal auditor

An estimated [[5–10]] days at [[day rate]]

Optional. Often the simplest way to meet IS-07 in a small team.

Consultancy or compliance software

[[€0 upwards]]

Optional. Neither is required by the standard or by the certification body.

Closing gaps

[[from the gap tracker]]

Tools and services the treatment plan needs, for example backup or logging. Budgeted per gap, not per project.

The certification body works out audit days from the number of people in scope, the number of sites and the complexity of the scope, following the rules it is accredited under. Ask each body quoting for the days per stage and per surveillance audit, not only the total, and check that the quote covers the three-year cycle (see Stage 1 and Stage 2 Audit Preparation Guide).

Guidance — delete before approval

A lower quote with fewer audit days than other accredited bodies offer for the same scope is worth questioning. A certificate from a body without recognised accreditation may not be accepted by the customers you are certifying for.

Internal effort is usually larger than every external cost together. Budget it as time released from other work, or the project will slip in Phase 4.

Where other CISO Times packs help

Several requirements already have a CISO Times pack. Once running, their records are evidence for the audit. None is required; each is a starting point you adapt.

Requirement

Pack

What it gives you

5.2, 7.5 and A.5.1 Policies for information security

the Security Policy Management pack (P04)

A policy framework (Policy Framework Standard), a template for each document (Security Policy Document Template), and a register with review dates (Policy Register & Review Schedule): the document control IS-04 needs.

6.1.2, 6.1.3, 8.2 and 8.3

the Information Security Risk Management pack (P05)

A risk method with criteria (Risk Assessment Methodology & Scoring Model), the register (Information Security Risk Register), the treatment plan (Risk Treatment Plan) and signed acceptances (Risk Acceptance Form & Approval Record): the evidence behind IS-03.

A.5.19 to A.5.22 on suppliers

the Third-Party Security Risk Management pack (P06)

Supplier tiering (Supplier Criticality & Tiering Model), assessment and a supplier risk register (Supplier Security Risk Register): the records an auditor samples for the scope's interfaces.

A.5.18 Access rights

the User Access Review pack (P07)

A method for periodic access reviews and the campaign records they produce: the most commonly sampled record of a control in operation.

The Vulnerability & Exposure Management pack (P01) supports A.8.8, the Security Exception, Waiver & Segregation of Duties pack (P02) supports A.5.36 and the handling of controls not yet met, and the Board Cybersecurity Reporting pack (P03) supports reporting to top management.

EXAMPLE. The EXAMPLE firm already runs the P04 policy register: 10 documents. As at 30 September 2026, 7 are approved and in date, 2 are past their review date (AUP-001 Acceptable Use Policy; BKP-001 Backup Standard) and 1 awaits approval (SUP-001 Supplier Security Policy). Under IS-04 each of these 3 is a gap in the ISMS Gap & Remediation Tracker, with an owner and a date before Stage 1 (IS-08). The Information Security Policy (ISP-001), approved on 12 March 2026 before the project started, is the policy clause 5.2 needs.

Worked examples

Both examples use the EXAMPLE firm used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. All 240 staff are in scope. The project started on 6 April 2026; the certification body has booked Stage 1 for 18 January 2027 and Stage 2 for 1 March 2027. Example 1 is the plan as approved; Example 2 is where the firm actually is, from the same readiness position the Mandatory ISMS Documentation Checklist, the Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker use. All dates are EXAMPLE: replace them with your own.

Example 1 — the plan as approved

Phases 1 to 4 run back to back from the start date, each ending on the Friday of its last week. Phase 5 runs on the dates the internal audit programme fixed (ISMS Internal Audit Programme & Procedure). Phase 6 begins with Stage 1 on its booked date.

Phase

Planned weeks

Starts

Ends

Phase 1 — Decide and scope

3

6 April 2026

24 April 2026

Phase 2 — Assess risk

5

27 April 2026

29 May 2026

Phase 3 — Select and document controls

6

1 June 2026

10 July 2026

Phase 4 — Implement and operate

12

13 July 2026

2 October 2026

Phase 5 — Check

4 (runs over 10)

4 November 2026

12 January 2027

Phase 6 — Certify

8

18 January 2027

12 March 2027

Phase 5 in detail: audits from 4 November 2026 to 9 December 2026; the programme report on 23 December 2026; the management review on 6 January 2027, which is also the Stage 1 go or no-go; and IA-07, the audit of the management review itself, on 12 January 2027. The checks:

Check

Result

Holds?

Buffer between the planned end of Phase 4 and the first audit

30 calendar days (5 October 2026 to 4 November 2026)

Yes

Length of Phase 5

10 weeks against 4 planned: the audits are spread out and the report and review fall either side of the year-end closure ([[2]] weeks)

Accepted

Slack between the last check step and Stage 1

6 calendar days (IA-07 on 12 January 2027, Stage 1 on 18 January 2027)

Tight

IS-05: [[3]] months of operation before Stage 2

7 full months, counting from the planned start of Phase 4 on 13 July 2026

Yes

IS-06: internal audit and management review before Stage 2

Management review 6 January 2027, before Stage 1

Yes

Stage 1 to Stage 2

6 weeks to close Stage 1 concerns; Stage 2 falls in week 7 of Phase 6

Yes

Certification body booked

By the end of Phase 3 (10 July 2026): 27 weeks before Stage 1, beyond a typical lead time of [[8 to 12]] weeks

Yes

IS-10: monthly readiness reassessments

8 between 13 July 2026 and Stage 2

Yes

Latest date a control can start and still have the IS-05 records by Stage 2

1 December 2026

Plan for it

Where the contingency is. The plan has 30 days of buffer before the audits, only 6 days between the last check step and Stage 1, and 6 weeks between Stage 1 and Stage 2. A slip in Phase 4 can be absorbed before the audits; a slip in Phase 5 moves Stage 1. That is why the check dates are fixed early and protected.

What the certificate date looks like. The certification decision usually follows Stage 2 by [[2 to 6]] weeks, if no major nonconformity is open.

Example 2 — where the firm actually is, and the forecast

As at 30 September 2026 (EXAMPLE; replace with today's date), the project is in week 26 and has held 3 monthly readiness reassessments. It is not on plan:

Gate evidence

Planned by

Actual

Late by

Scope approved (ISMS-01, Phase 1 gate)

24 April 2026

11 May 2026

2 weeks

Statement of Applicability and treatment plan approved (ISMS-03, ISMS-04; Phase 3 gate)

10 July 2026

24 August 2026

6 weeks

Phase 4 gate: every applicable control In place, every blocking item Operating

2 October 2026

Not met: 40 of 122 applicable requirements below In place; 5 of 8 blocking items below Operating

Open

The blocking items:

Clause

Title

Readiness

4.3

Determining the scope of the information security management system

3 Operating

5.2

Policy

3 Operating

6.1.2

Information security risk assessment

3 Operating

6.1.3

Information security risk treatment

2 In place

6.2

Information security objectives and planning to achieve them

1 Planned

9.2.2

Internal audit programme

1 Planned

9.3.3

Management review results

1 Planned

10.2

Nonconformity and corrective action

1 Planned

ISM-04, worked by the decision logic above from the same position:

Step

Date

What sets it

(a) Work finished

3 February 2027

The last open gap In place, with each owner working through their gaps in turn

(b) Operating period

11 February 2027

The last blocking item In place on 11 November 2026, plus [[3]] months (IS-05)

(c) Internal audit and management review

6 January 2027

The later of the Check phase after the audit programme is in place and the planned audit and review dates (IS-06)

Earliest Stage 2

11 February 2027

The latest of (a), (b) and (c): 20 weeks from 30 September 2026

The estimate of 11 February 2027 is 18 calendar days inside the booked Stage 2 date of 1 March 2027, so the booking holds. But the firm is behind its approved plan, the margin is small, and 3 gaps are on the critical path (9.2.2, 10.2, A.5.7). The executive sponsor is told this month (IS-10), each critical gap is reviewed weekly in the ISMS Gap & Remediation Tracker, and the Phase 4 gate is re-dated rather than declared met.

Common failure modes

Each of these is common in a first certification. Most show up at Stage 1, when they are still cheap to fix.

Failure

How it shows at the audit

How the method prevents it

Controls copied from Annex A

The Statement of Applicability cannot say which risk each control treats; exclusions have no reason.

IS-03; risk assessment before the Statement of Applicability (Sequencing).

A scope nobody can explain

The auditor cannot tell where the ISMS ends, or finds in-scope services depending on excluded ones.

IS-02; the scope tests; approval by top management (IS-01).

Documents without records

Policies are approved but there are no reviews, logs or training records to sample.

IS-05: [[3]] months from the start of Phase 4 to Stage 2; readiness 3 needs records.

A policy toolkit bought whole

Dozens of documents describe processes nobody runs; the auditor samples one and finds it is not followed.

IS-03 and IS-04: write only what the chosen controls need.

Top management not involved

Nobody at the top can say what the objectives are or what the management review decided.

IS-01; objectives in Phase 3; the management review in Phase 5.

The internal audit done by the ISMS manager

The auditor finds the ISMS manager audited the ISMS they run.

IS-07; contract an internal auditor if there is nobody independent.

The internal audit left until the last week

No time to correct what it found; nonconformities are still open at Stage 2.

IS-06; audit dates fixed early, with time after them before Stage 1.

A Stage 2 date fixed before the plan

The ISMS has run for weeks, not months, when the auditor arrives.

IS-05; plan backwards from the date; go and no-go before Stage 2.

Gaps with no owner or date

The same gaps are open at every readiness check; the Stage 2 date arrives with blockers open.

IS-08; the ISMS Gap & Remediation Tracker; ISM-03.

The plan never reassessed

The slip is discovered at Stage 1.

IS-10; ISM-04 every month.

Findings patched, not fixed

The same nonconformity returns at the first surveillance audit.

IS-09: root cause, correction, corrective action and a check that it worked.

How to defend the plan to an auditor

The certification body does not audit your project plan, but it will test what the plan produced. It will usually ask how top management showed leadership and commitment (clause 5.1 Leadership and commitment), how the scope was decided (4.3), how controls were chosen from risk (6.1.2 and 6.1.3), what the objectives are and how progress is planned and measured (6.2), and whether the internal audit programme and the management review have run (9.2.2 and 9.3.3).

Evidence to have ready

  • The approval by top management of the scope, the policy and the resources, dated before Phase 2 started (IS-01).
  • The scope statement, with its interfaces and exclusions and the reason for each (IS-02).
  • The risk assessment, the treatment plan and the Statement of Applicability, showing each control traced to a risk (IS-03).
  • The Mandatory ISMS Documentation Checklist, completed, with every item approved and under document control (IS-04).
  • The monthly readiness reports and headline measures from the start of Phase 4 (IS-10), and the ISMS Gap & Remediation Tracker with an owner and date on every gap (IS-08).
  • The internal audit programme, the audit report, the auditors' independence (IS-06, IS-07) and the management review minutes.
  • For each nonconformity: the root cause, the correction, the corrective action and the check that it worked (IS-09).

Questions auditors commonly ask about the programme

Question

Answer the method gives

Why is this the scope?

The scope statement and the Phase 1 approval: the services customers buy, the interfaces and each exclusion with its reason (IS-02).

How were the controls chosen?

From the treatment plan; Annex A was used as a check (IS-03). The Statement of Applicability names the risk each control treats.

How long has the ISMS been running?

Since the start of Phase 4; the records sampled cover at least [[3]] months (IS-05).

How does top management know where you are?

The monthly readiness report with ISM-01, ISM-02, ISM-03, ISM-04 (IS-10), and the management review.

What happens when something slips?

The gap tracker shows the owner and date; the sponsor decides at the next gate; the Stage 2 date moves early if it must (IS-08).

Limitations

Limitation

Effect

How it is managed

The durations are typical, not measured for you.

A larger scope, fewer controls in place or less time from control owners makes every phase longer.

Replace them after the first readiness assessment; reassess monthly (IS-10).

Weeks are elapsed time, not effort.

A plan can be on time while the people doing it are overloaded.

Track effort against 'Roles and effort' at each gate.

Holidays and busy seasons are not in the arithmetic.

A phase over a holiday period takes longer than its weeks, as the EXAMPLE's Phase 5 does.

Plan the dates, not only the weeks, and keep a buffer.

Readiness is self-assessed.

Owners tend to score their own controls high.

Evidence for every score of 3; a second person checks; the internal audit tests the scores.

The certification body's availability is outside your control.

The date you want may not exist.

Book by the end of Phase 3; ask for dates with a lead time of [[8 to 12]] weeks.

The cost ranges are estimates.

Quotes vary with scope, sites and the body chosen.

Obtain quotes; replace the ranges before the budget is approved.

Calibration and review

During the project

  1. At every gate, record the planned and actual weeks for the phase, and recompute the plan from the actual dates.
  2. Every month from the start of Phase 4, reassess readiness and report the headline measures (IS-10). Recompute ISM-04 with the decision logic above.
  3. If ISM-04's estimate comes within [[4]] weeks of the booked Stage 2 date, or a blocking item has no date before the Stage 2 date, the sponsor decides the same month: add resource, narrow the scope, or move the date.
  4. After Stage 2, compare the actual durations with the defaults in this document and record what you would plan differently.

Review of this methodology

This methodology is reviewed at least every 12 months, when the scope changes, after each certification body audit, and when a new edition of the standard is published. After certification it becomes the plan for keeping the ISMS running between surveillance audits: the phases repeat as the yearly cycle of risk assessment, operation, internal audit and management review.

Plan record

Phase

Planned weeks

Actual weeks

Gate date

Approved by

What changed

Phase 1 — Decide and scope

3

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Phase 2 — Assess risk

5

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Phase 3 — Select and document controls

6

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Phase 4 — Implement and operate

12

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Phase 5 — Check

4

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Phase 6 — Certify

8

[[n]]

[[YYYY-MM-DD]]

[[Name]]

[[—]]

Related documents

Document

Relationship

Annex A Control Implementation Library

How to put each Annex A control in place once the Statement of Applicability includes it (Phase 4)

Statement of Applicability Template

Records the decision and reason for all 93 controls (IS-03, Phase 3)

Mandatory ISMS Documentation Checklist

The required documents and records, by clause, that IS-04 checks

Certification Readiness Self-Assessment

Scores readiness on the scale above; the monthly reassessment (IS-10)

ISMS Gap & Remediation Tracker

Every gap with an owner and a date, and the critical path (IS-08)

ISMS Internal Audit Programme & Procedure

Plans and runs the internal audit (IS-06, IS-07; Phase 5)

Management Review Meeting Pack

The management review's agenda, inputs and decisions (IS-06; Phase 5)

Stage 1 and Stage 2 Audit Preparation Guide

What the certification body asks, samples and challenges at Stage 1 and Stage 2 (Phase 6)

Adapting this template

Guidance — delete before approval

Small organisation: fewer people shorten Phases 1 to 3, not the IS-05 operating period. A whole-organisation scope is usually simpler than a partial one. One person may be ISMS manager and a control owner, but contract an internal auditor for [[3–5]] days rather than audit your own work (IS-07). Expect fewer audit days and a lower fee.

Regulated entity: ISO/IEC 27001:2022 is the requirement this plan certifies against. Laws such as NIS2 or DORA set their own obligations, for example incident reporting to an authority, that a certificate does not prove. Certification is evidence that a management system is working; it is not compliance with a law. List the legal and regulatory requirements in Phase 1, bring them into the risk assessment, and make sure the scope covers the services the regulation covers, or the certificate will evidence little of what the regulator asks. The EXAMPLE firm is an important entity under NIS2 and plans this way.

IT run by a service provider: the provider's services are interfaces of your scope. Check that each provider's own certificate covers the service you buy; ask for its Statement of Applicability or a summary. Agree in the contract that the provider will supply records for your auditor to sample, such as access reviews and backup tests, because the certification body will sample them as your controls. Manage providers under your supplier controls (the Third-Party Security Risk Management pack (P06)).

If your organisation is already certified to another management system standard, reuse its document control, internal audit and management review arrangements, and ask the certification body about an integrated audit.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 4.3 — Determining the scope of the information security management system

Scoping decisions; IS-02; Phase 1

ISO/IEC 27001:2022

Clause 5.1 — Leadership and commitment

IS-01; roles; the gates; how to defend the plan

ISO/IEC 27001:2022

Clause 6.1.2 — Information security risk assessment

Phase 2; sequencing: approved risk method first

ISO/IEC 27001:2022

Clause 6.1.3 — Information security risk treatment

IS-03; Phase 3; the Statement of Applicability traced to risk

ISO/IEC 27001:2022

Clause 6.2 — Information security objectives and planning to achieve them

Phase 3 objectives; headline measures; decision logic

ISO/IEC 27001:2022

Clause 9.2.2 — Internal audit programme

IS-06, IS-07; Phase 5

ISO/IEC 27001:2022

Clause 9.3.3 — Management review results

IS-06; Phase 5; management review minutes as evidence

NIST CSF 2.0

GV.OC-01 — “The organizational mission is understood and informs cybersecurity risk management”

Purpose and inputs: the reason for certifying informs the scope

NIST CSF 2.0

GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed”

Inputs: legal, regulatory and contractual requirements; regulated-entity tailoring

NIST CSF 2.0

GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving”

IS-01; roles: top management accountable for the ISMS

Definitions

Term

Meaning in this methodology

Blocking item

A requirement without which a Stage 2 audit cannot pass: clauses 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2.

Certification body

An organisation accredited to audit and certify management systems against ISO/IEC 27001.

Control owner

The manager who runs a control and keeps its records.

Critical path

The chain of gaps and phases whose delay moves the Stage 2 date.

Gate

The evidence that closes a phase and lets the next one start.

Information security management system (ISMS)

The policies, processes, people and records through which an organisation manages information security risk.

Interface

A point where the scope depends on something outside it, such as a supplier or a group function.

Nonconformity

A requirement not met, found by an internal or certification audit.

Operating period

The time the ISMS has run and produced records before Stage 2; at least [[3]] months (IS-05).

Readiness

A score from 0 (Not started) to 3 (Operating) for each requirement.

Scope

The part of the organisation, its services, locations and technology that the ISMS and the certificate cover.

Slack

Time between one fixed date in the plan and the next that a slip can use up without moving the audits: the plan's contingency.

Stage 1 audit

The certification body's review of the documentation and of readiness for Stage 2.

Stage 2 audit

The certification body's audit of the ISMS in operation, by sampling controls and records.

Statement of Applicability

The record of every Annex A control: included or excluded, why, and its status.