Mandatory ISMS Documentation Checklist
Lists every document and record the standard requires, with the common substitutions auditors accept and the gaps they reliably find.
Available soon
- Format
- Excel
- Size
- 74 KB
- Length
- 10 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Required Documents
- Annex A Documents
- Summary & Sign-off
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Scope: check against your approved ISMS scope (clause 4.3). Every row on the Required Documents sheet applies to every organisation. On the Annex A Documents sheet, answer N/A for a control your Statement of Applicability excludes, and give the reason in the notes. |
| 2 | For each row, enter your document or record in 'Your document or record' (reference and title, or where the records are kept). Where one document covers several items, name it in each. |
| 3 | Answer the four checks from the drop-down lists: Yes, Partly, No, or N/A where the check does not apply (a record is not approved like a policy; a document not yet in use cannot show evidence of use). 'Pass when' says what an auditor needs to see. |
| 4 | Read the Result and 'What is missing'. For every Fail or Missing, name an owner and a target date, and copy the item into the ISMS Gap & Remediation Tracker. |
| 5 | Record the evidence you looked at in the last column (for example 'register entry, approval minutes 2026-05-11'), so the next check, and the Stage 1 auditor, can follow it. |
| 6 | Summary & Sign-off: read the counts, then have the person who carried out the check and the ISMS manager sign off with the date. Repeat the check before Stage 1 and before Stage 2. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The four checks (IS-04: "Every required document and record (MANDATORY) must exist, be approved and be kept under document control."):
Exists? — Yes: it exists and covers the whole item. Partly: it exists in draft or covers part. No: nothing exists (the result is Missing).
Approved? — Yes: approved by the person or body it names as approver. Partly: some parts or some documents are approved. No: a draft. N/A: a record, which is kept rather than approved.
Under document control? — Yes: identified, versioned, stored where the right people can find it, with access, retention and a review date that has not passed (clause 7.5.3). Partly: some of that, or past its review date. No: none.
Evidence of use? — Yes: the auditor could sample it being followed or produced over at least [[3]] months. Partly: in use for less than that. No: not yet in use.
Result — Pass: exists, and every other check is Yes or N/A. Fail: exists, but at least one check is Partly or No. Missing: does not exist. N/A: the control is excluded in your Statement of Applicability (give the reason). Not answered: the Exists check is blank.
The EXAMPLE rows are a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30, about six months into its ISMS project. Its policies are the Security Policy Management (P04) example register; its other ISMS documents are ISMS-01 to ISMS-08. Document control shows Partly where a document is approved but past its review date (AUP-001, BKP-001), and No where it has never been approved (the Supplier Security Policy, P04 register SUP-001): a document awaiting approval is not yet under control. Owners and target dates come from the same readiness position as the Certification Readiness Self-Assessment. To clear the example, delete the contents of the 'Row' column and every yellow column; the item text stays.
Tailoring — small organisation: one short ISMS manual can hold the scope, roles, the risk method and the objectives; name it against each item. What matters is that each item is there, approved and used, not that it is a separate document.
Tailoring — regulated entity: ISO/IEC 27001:2022 certification is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Keep the register of legal requirements (Annex A 5.31) complete, since supervisors and auditors both start there; the regulator may expect documents this checklist does not list.
Tailoring — IT run by a service provider: documents the provider keeps count only if you can see them and they are covered by your document control, or by the contract. Name the provider's document and where you hold your copy; ask for its records for the period the auditor will sample.
Required Documents
The 16 items of documented information the standard requires, by clause (number and title only; read the standard for the requirement). Yellow columns are yours.
| Row | Item ID | Clause | Clause title | Documented information (in our words) | Document or record | Typical form | Substitutions auditors commonly accept | Gaps auditors reliably find | Pass when | CISO Times template that helps | Your document or record | Exists? | Approved? | Under document control? | Evidence of use? | Result | What is missing | Owner | Target date | Evidence reference and notes | Action order (working) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | MD-01 | 4.3 | Determining the scope of the information security management system | Scope of the ISMS | Document | A scope statement of one or two pages, often a section of an ISMS manual, with a diagram of locations and interfaces. | A scope section inside the ISMS manual or the policy, if it is approved and says everything a scope statement must. | Interfaces and dependencies on other organisations missing; exclusions with no reason; cloud services not mentioned; the scope on the certification application differs from the approved one. | Names the organisation, locations, services, interfaces and exclusions with reasons (IS-02); approved by top management (IS-01). | ISO 27001 Implementation Methodology & Project Plan (this pack) | ISMS-01 ISMS Scope Statement (Approved 2026-05-11) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | MD-02 | 5.2 | Policy | Information security policy | Document | A short top-level policy signed by top management, with topic-specific policies beneath it. | A combined policy with an information security section, if it contains the commitments the standard asks for and is communicated. | No objectives or framework for setting them; no commitment to continual improvement; signed by someone other than top management; not available to the people it applies to; review date passed. | Approved by top management, communicated and acknowledged, and within its review date. | P04-A04 Security Policy Document Template; P04-A02 Policy Framework Standard | Information Security Policy (P04 register ISP-001) v3.0 (Approved, review 2027-03-12) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | MD-03 | 6.1.2 | Information security risk assessment | Risk assessment process | Document | A risk methodology: the criteria for accepting risk and for performing assessments, how risks are identified, analysed and evaluated, and who owns them. | A group-wide enterprise risk method, if it covers information security risk and states the acceptance criteria. | Acceptance criteria missing or not measurable; a method that gives different results when repeated; risk owners not named. | Sets acceptance criteria and a method that gives consistent, comparable results; approved. | P05-A02 Risk Assessment Methodology & Scoring Model; P05-A03 Risk Identification & Assessment Operating Procedure | ISMS-02 Risk Management Methodology (Approved 2026-06-15) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | MD-04 | 6.1.3 | Information security risk treatment | Risk treatment process | Document | Usually part of the same methodology: treatment options, how controls are chosen and compared with Annex A, who approves the plan and accepts residual risk. | The same document as the risk assessment process. | No record that chosen controls were compared with Annex A; residual risk not accepted by the risk owners. | Describes how treatment is chosen, compared with Annex A and approved; risk owners accept residual risk. | P05-A02 Risk Assessment Methodology & Scoring Model; P05-A07 Risk Treatment Plan | ISMS-02 Risk Management Methodology (Approved 2026-06-15) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2007 |
| EXAMPLE | MD-05 | 6.1.3 | Information security risk treatment | Statement of Applicability | Document | A table of all 93 Annex A controls: applicable or not, why, and implemented or not, each linked to a risk or requirement. | An export from a tool, if it holds every control, the justification and the implementation status, and is under version control. | Exclusions justified only with 'not relevant'; implementation status out of date; controls included with no link to a risk (IS-03); a different version from the one sent to the certification body. | Every control listed with applicability, justification and status; approved; status current. | Statement of Applicability Template (this pack) | ISMS-03 Statement of Applicability (Approved 2026-08-24) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2008 |
| EXAMPLE | MD-06 | 6.1.3 | Information security risk treatment | Risk treatment plan | Document | A list of treatment actions: the risk, the action, owner, due date and the residual risk, with the risk owners' approval. | A section of the risk register, or the gap tracker, if each action links to a risk and the approval is recorded. | Actions without owners or dates; no record that risk owners approved the plan; the plan not updated as actions close. | Every treatment action owned and dated; approved by the risk owners; kept up to date. | ISMS Gap & Remediation Tracker (this pack); P05-A07 Risk Treatment Plan | ISMS-04 Risk Treatment Plan (Approved 2026-08-24) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2009 |
| EXAMPLE | MD-07 | 6.2 | Information security objectives and planning to achieve them | Information security objectives | Document | Five to ten objectives, each with a measure, a target, an owner, the resources, a date and how results will be evaluated. | Objectives in the policy or a board paper, if they are measurable and monitored. | Objectives that cannot be measured; no evidence they are monitored; not communicated to the people who deliver them. | Measurable, owned and dated; approved and communicated; results monitored. | ISO 27001 Implementation Methodology & Project Plan (this pack) | ISMS-05 Information Security Objectives (Draft) | Yes | No | No | No | Fail | Not approved. Not under document control. No evidence of use yet. | Head of Information Security | 21 Oct 2026 | EXAMPLE — Planned in the readiness assessment. | 2010 |
| EXAMPLE | MD-08 | 7.2 | Competence | Evidence of competence | Record | Competence requirements for each ISMS role, and training records, certificates, CVs or appraisals showing the people meet them. | HR system or training platform records, if they cover the ISMS roles, including contractors. | No competence requirements for the ISMS manager, internal auditor or control owners; nothing for contractors; no check that training worked. | Requirements set for every ISMS role, and evidence that each person meets them. | — | HR system training and competence records | Yes | N/A | Yes | Partly | Fail | In use for less than 3 months. | HR Director | 1 Dec 2026 | EXAMPLE — In place in the readiness assessment. | 2011 |
| EXAMPLE | MD-09 | 7.5.1 | General | Documented information the organisation decides it needs for the ISMS to be effective | Document | A document register listing every policy, procedure and record the ISMS relies on, with owner, version and review date. | A policy register extended to procedures and records. | Procedures that policies refer to do not exist; documents past their review date; drafts in use. | Every document the ISMS relies on is listed, approved, in date and under control. | P04-A06 Policy Register & Review Schedule; P04-A05 Security Policy Hierarchy & Document Map | P04 policy register; ISMS-01 to ISMS-08 | Yes | Partly | Partly | Yes | Fail | Approval incomplete. Document control incomplete or review overdue. | Head of Information Security | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2012 |
| EXAMPLE | MD-10 | 8.1 | Operational planning and control | Evidence that processes have been carried out as planned | Record | The records the processes and controls produce: tickets, logs, change records, minutes, reports. | System logs and tickets, if they can be retrieved for the period the auditor samples. | Records for only part of the period; outsourced processes with no records the organisation can see. | Records exist for every planned process over the period an auditor samples. | — | Service desk tickets, change records and backup logs | Yes | N/A | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 6 Oct 2026 | EXAMPLE — In place in the readiness assessment. | 2013 |
| EXAMPLE | MD-11 | 8.2 | Information security risk assessment | Results of risk assessments | Record | The risk register with dated assessments, and records of reassessment at planned intervals or after a significant change. | A dated export from a risk tool. | Only one assessment ever carried out; no reassessment after a significant change. | Dated results, reassessed at the planned interval and after significant change. | P05-A05 Information Security Risk Register; P05-A06 Risk Assessment Workbook | ISMS-07 Information Security Risk Register (Approved 2026-07-20) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 20 Oct 2026 | EXAMPLE — In place in the readiness assessment. | 2014 |
| EXAMPLE | MD-12 | 8.3 | Information security risk treatment | Results of risk treatment | Record | Risk register updates showing the treatment done and the residual risk, accepted by the risk owner. | Tracker entries linked to the risk references. | Treatment marked complete with no evidence; residual risk not re-scored. | Each completed treatment recorded with evidence and the residual risk accepted. | P05-A07 Risk Treatment Plan; P05-A08 Risk Acceptance Form & Approval Record | ISMS-04 progress entries | Partly | N/A | Yes | No | Fail | Covers only part of the item, or is a draft. No evidence of use yet. | Head of Information Security | 2 Dec 2026 | EXAMPLE — Planned in the readiness assessment. | 2015 |
| EXAMPLE | MD-13 | 9.1 | Monitoring, measurement, analysis and evaluation | Results of monitoring and measurement | Record | A measurement plan (what is measured, how, when, and who analyses it) and the periodic reports. | Dashboard exports, if dated and kept. | Measures defined but never analysed or evaluated; no record of who reviewed the results. | Results recorded, analysed and evaluated at the planned frequency. | — | No | Missing | Create it, have it approved and put it under document control. | Head of Information Security | 23 Dec 2026 | EXAMPLE — Planned in the readiness assessment. | 1016 | ||||
| EXAMPLE | MD-14 | 9.2.2 | Internal audit programme | Internal audit programme and audit results | Record | The audit programme (frequency, methods, responsibilities, criteria and scope), the audit plans, reports and findings. | A contracted auditor's report, if the programme is the organisation's own and the auditor is independent (IS-07). | Audits that cover Annex A but not clauses 4 to 10; auditors auditing their own work; findings not followed up. | An approved programme covering the whole ISMS, and at least one complete audit with its report (IS-06). | ISMS Internal Audit Programme & Procedure (this pack) | ISMS-08 Internal Audit Programme (Draft) | Partly | No | No | No | Fail | Covers only part of the item, or is a draft. Not approved. Not under document control. No evidence of use yet. | Head of Information Security | 23 Dec 2026 | EXAMPLE — Planned in the readiness assessment. | 2017 |
| EXAMPLE | MD-15 | 9.3.3 | Management review results | Results of management reviews | Record | Minutes showing every required input was considered, and the decisions on improvement and change. | Executive committee or board minutes, if every required input was considered and the decisions are recorded. | Required inputs missing from the minutes (for example changes in interested parties' needs, or audit results); decisions with no actions. | At least one review held, every input covered, decisions and actions recorded (IS-06). | Management Review Meeting Pack (this pack) | No | Missing | Create it, have it approved and put it under document control. | Chief Operating Officer | 6 Jan 2027 | EXAMPLE — Planned in the readiness assessment. | 1018 | ||||
| EXAMPLE | MD-16 | 10.2 | Nonconformity and corrective action | Nonconformities, actions taken and results of corrective action | Record | A log of nonconformities: what happened, the correction, the root cause, the corrective action, owner, date and the effectiveness check. | The gap tracker or a ticket queue, if it records the root cause and the effectiveness check. | No root cause recorded; effectiveness never checked; only audit findings logged, not incidents or complaints. | Every nonconformity logged with root cause, correction, corrective action and an effectiveness check (IS-09). | ISMS Gap & Remediation Tracker (this pack) | Incident log: post-incident actions only | Partly | N/A | Yes | No | Fail | Covers only part of the item, or is a draft. No evidence of use yet. | Head of Information Security | 11 Nov 2026 | EXAMPLE — Planned in the readiness assessment. | 2019 |
Annex A Documents
Documented information auditors commonly expect for Annex A controls, where the control usually produces a document or record (control number and title only). Answer N/A for a control your Statement of Applicability excludes.
| Row | Item ID | Control | Control title | Documented information commonly expected (in our words) | Document or record | CISO Times template that helps | Your document or record | Exists? | Approved? | Under document control? | Evidence of use? | Result | What is missing | Owner | Target date | Evidence reference and notes | Action order (working) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | AD-01 | A.5.1 | Policies for information security | The information security policy and the topic-specific policies | Document | P04-A01 Security Policy Management Pack — Guide; P04-A02 Policy Framework Standard | Information Security Policy (P04 register ISP-001) v3.0 (Approved, review 2027-03-12); Acceptable Use Policy (P04 register AUP-001) v2.1 (Review overdue, review 2026-07-01); Access Control Policy (P04 register ACP-001) v2.0 (Approved, review 2027-01-20); Incident Management Policy (P04 register INC-001) v1.2 (Approved, review 2027-05-04); Supplier Security Policy (P04 register SUP-001) v1.0 (Awaiting approval) | Yes | Partly | Partly | Yes | Fail | Approval incomplete. Document control incomplete or review overdue. | Head of Information Security | 18 Nov 2026 | EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews). | 2004 |
| EXAMPLE | AD-02 | A.5.2 | Information security roles and responsibilities | Security roles and responsibilities | Document | P02-A09 Exception & SoD Responsibility Matrix; P04-A09 Policy Development & Approval Responsibility Matrix | ISMS-06 ISMS Manual (processes, roles and responsibilities) (Approved 2026-08-03) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 3 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2005 |
| EXAMPLE | AD-03 | A.5.9 | Inventory of information and other associated assets | Inventory of information and other assets, with owners | Record | P01-A05 Scan Coverage & Asset Scope Register; P07-A04 Access Review Scope & System Inventory | Asset inventory (configuration management database export) | Yes | N/A | Yes | Partly | Fail | In use for less than 3 months. | Head of IT | 20 Oct 2026 | EXAMPLE — In place in the readiness assessment. | 2006 |
| EXAMPLE | AD-04 | A.5.10 | Acceptable use of information and other associated assets | Rules for acceptable use | Document | Coming: P24 AI Security Governance & Acceptable Use | Acceptable Use Policy (P04 register AUP-001) v2.1 (Review overdue, review 2026-07-01) | Yes | Yes | Partly | Yes | Fail | Document control incomplete or review overdue. | Head of Information Security | 18 Nov 2026 | EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews). | 2007 |
| EXAMPLE | AD-05 | A.5.12 | Classification of information | Classification scheme | Document | Coming: P15 Information Classification & Handling; P24 AI Security Governance & Acceptable Use | Information classification scheme | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 17 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2008 |
| EXAMPLE | AD-06 | A.5.15 | Access control | Rules for access control | Document | P07-A02 Access Review Methodology | Access Control Policy (P04 register ACP-001) v2.0 (Approved, review 2027-01-20) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-07 | A.5.18 | Access rights | Records of access rights granted, changed, reviewed and removed | Record | P07-A01 User Access Review Pack — Guide; P07-A02 Access Review Methodology | Quarterly access review records | Yes | N/A | Yes | Partly | Fail | In use for less than 3 months. | Head of IT | 3 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2010 |
| EXAMPLE | AD-08 | A.5.19 | Information security in supplier relationships | Rules for managing information security risk from suppliers | Document | P06-A01 Third-Party Security Risk Pack — Guide; P06-A02 Third-Party Security Policy | Supplier Security Policy (P04 register SUP-001) v1.0 (Awaiting approval) | Yes | No | No | No | Fail | Not approved. Not under document control. No evidence of use yet. | Head of Procurement | 7 Oct 2026 | EXAMPLE — Planned in the readiness assessment. | 2011 |
| EXAMPLE | AD-09 | A.5.20 | Addressing information security within supplier agreements | Security requirements in supplier agreements | Document | P06-A02 Third-Party Security Policy; P06-A07 Supplier Contract Security Clause Library | Security clauses in Tier 1 supplier contracts | Partly | N/A | Partly | No | Fail | Covers only part of the item, or is a draft. Document control incomplete or review overdue. No evidence of use yet. | Head of Procurement | 4 Nov 2026 | EXAMPLE — Planned in the readiness assessment. | 2012 |
| EXAMPLE | AD-10 | A.5.24 | Information security incident management planning and preparation | Incident management plan: roles, procedures and communication | Document | Coming: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario Library | Incident Management Policy (P04 register INC-001) v1.2 (Approved, review 2027-05-04) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-11 | A.5.26 | Response to information security incidents | Records of incidents and how they were handled | Record | Coming: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario Library | Incident log | Yes | N/A | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-12 | A.5.30 | ICT readiness for business continuity | ICT continuity plans and records of their tests | Document | Coming: P10 Cyber Incident Exercises & Tabletop Scenario Library; P21 DORA ICT Risk & Resilience Readiness | ICT recovery plan (not yet tested) | Yes | Yes | Yes | No | Fail | No evidence of use yet. | IT Operations Manager | 28 Oct 2026 | EXAMPLE — Planned in the readiness assessment. | 2015 |
| EXAMPLE | AD-13 | A.5.31 | Legal, statutory, regulatory and contractual requirements | Register of legal, statutory, regulatory and contractual requirements | Record | Coming: P12 NIS2 Implementation & Readiness; P18 Regulatory Incident Notification & Reporting | No | Missing | Create it, have it approved and put it under document control. | Legal Counsel | 28 Oct 2026 | EXAMPLE — Planned in the readiness assessment. | 1016 | ||||
| EXAMPLE | AD-14 | A.5.34 | Privacy and protection of PII | Records of processing of personal data | Record | Coming: P09 Security Incident Management; P10 Cyber Incident Exercises & Tabletop Scenario Library | Records of processing activities | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Legal Counsel | 6 Oct 2026 | EXAMPLE — In place in the readiness assessment. | 2017 |
| EXAMPLE | AD-15 | A.5.36 | Compliance with policies, rules and standards for information security | Records of compliance checks and approved exceptions | Record | P01-A02 Vulnerability & Exposure Management Standard; P02-A01 Security Exception, Waiver & SoD Toolkit — Guide | Security Exception & Waiver Standard (P04 register EXC-STD) v1.0 (Approved, review 2027-09-10) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 10 Dec 2026 | EXAMPLE — In place in the readiness assessment. | 2018 |
| EXAMPLE | AD-16 | A.5.37 | Documented operating procedures | Documented operating procedures for IT operations | Document | P04-A03 Policy Lifecycle Operating Procedure | Backup Standard (P04 register BKP-001) v1.3 (Review overdue, review 2026-08-15); IT operating procedures | Yes | Yes | Partly | Partly | Fail | Document control incomplete or review overdue. In use for less than 3 months. | IT Operations Manager | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2019 |
| EXAMPLE | AD-17 | A.6.1 | Screening | Records of background checks | Record | — | HR screening records | Yes | N/A | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-18 | A.6.3 | Information security awareness, education and training | Records of awareness and training completed | Record | P04-A07 Policy Attestation & Acknowledgement Tracker; P07-A05 Reviewer Instruction Pack & Campaign Communications | Awareness campaign completion records | Yes | N/A | Yes | Partly | Fail | In use for less than 3 months. | Head of Information Security | 14 Dec 2026 | EXAMPLE — In place in the readiness assessment. | 2021 |
| EXAMPLE | AD-19 | A.6.5 | Responsibilities after termination or change of employment | Leaver and mover procedure and its records | Document | Coming: P10 Cyber Incident Exercises & Tabletop Scenario Library; P13 Joiner-Mover-Leaver & Access Provisioning | Joiner, Mover, Leaver Procedure (P04 register JML-PRC) v2.2 (Approved, review 2027-02-03) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-20 | A.6.6 | Confidentiality or non-disclosure agreements | Signed confidentiality or non-disclosure agreements | Record | — | Signed confidentiality agreements | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | HR Director | 6 Oct 2026 | EXAMPLE — In place in the readiness assessment. | 2023 |
| EXAMPLE | AD-21 | A.6.7 | Remote working | Rules for remote working | Document | — | Remote Working Guideline (P04 register RMT-GDL) v1.1 (Approved, review 2027-11-18) | Yes | Yes | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. | |||
| EXAMPLE | AD-22 | A.8.8 | Management of technical vulnerabilities | Rules for technical vulnerability management, and scan and remediation records | Document | P01-A01 Vulnerability Management Operating Pack — Guide; P01-A02 Vulnerability & Exposure Management Standard | Vulnerability & Exposure Management Standard (P04 register VMS-001) v1.0 (Approved, review 2027-09-10) | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of IT | 10 Dec 2026 | EXAMPLE — In place in the readiness assessment. | 2025 |
| EXAMPLE | AD-23 | A.8.9 | Configuration management | Approved baseline configurations | Document | P01-A07 Vulnerability Scanner Configuration Review Checklist | No | Missing | Create it, have it approved and put it under document control. | Head of IT | 11 Nov 2026 | EXAMPLE — Planned in the readiness assessment. | 1026 | ||||
| EXAMPLE | AD-24 | A.8.13 | Information backup | Backup rules and records of restore tests | Document | Coming: P22 Cyber Resilience & Recovery; P23 Backup & Restore Assurance | Backup Standard (P04 register BKP-001) v1.3 (Review overdue, review 2026-08-15) | Yes | Yes | Partly | Yes | Fail | Document control incomplete or review overdue. | Head of Information Security | 18 Nov 2026 | EXAMPLE — Operating in the readiness assessment. Fixed with the clause 7.5.3 gap (overdue reviews). | 2027 |
| EXAMPLE | AD-25 | A.8.15 | Logging | Logging rules and log retention | Document | Coming: P14 Privileged Access Management | Platform logging and retention settings | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of IT | 10 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2028 |
| EXAMPLE | AD-26 | A.8.24 | Use of cryptography | Rules for cryptography and key management | Document | — | Cryptography rules in the engineering handbook | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of IT | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2029 |
| EXAMPLE | AD-27 | A.8.25 | Secure development life cycle | Secure development rules | Document | Coming: P25 Generative AI Security | Secure development procedure in the engineering handbook | Yes | Yes | Yes | Partly | Fail | In use for less than 3 months. | Head of Engineering | 24 Nov 2026 | EXAMPLE — In place in the readiness assessment. | 2030 |
| EXAMPLE | AD-28 | A.8.32 | Change management | Change management procedure and change records | Record | Coming: P17 Patch Management; P29 Secure Configuration, Hardening & Baselines | Pull request and deployment records | Yes | N/A | Yes | Yes | Pass | Nothing: keep it in date. | EXAMPLE — Operating in the readiness assessment. |
Summary & Sign-off
Summary and sign-off
The results as counts, the items to act on, and the sign-off. Everything above the sign-off is calculated.
EXAMPLE: the example organisation, as at 2026-09-30. Clear the EXAMPLE answers to use your own.
Results
| Area | Pass | Fail | Missing | N/A | Not answered | Result |
|---|---|---|---|---|---|---|
| Required by the clauses | 3 | 11 | 2 | 0 | 0 | 3 of 16 items pass |
| Commonly expected for Annex A | 7 | 19 | 2 | 0 | 0 | 7 of 28 items pass |
Items with no Item ID are not counted. N/A items are left out of the total they are measured against.
Required documents to act on — missing first
| Item | Result | Owner | Target date | Map row | What is missing | |
|---|---|---|---|---|---|---|
| MD-13 9.1 — Results of monitoring and measurement | Missing | Head of Information Security | 23 Dec 2026 | 13 | Create it, have it approved and put it under document control. | |
| MD-15 9.3.3 — Results of management reviews | Missing | Chief Operating Officer | 6 Jan 2027 | 15 | Create it, have it approved and put it under document control. | |
| MD-04 6.1.3 — Risk treatment process | Fail | Head of Information Security | 24 Nov 2026 | 4 | In use for less than 3 months. | |
| MD-05 6.1.3 — Statement of Applicability | Fail | Head of Information Security | 24 Nov 2026 | 5 | In use for less than 3 months. | |
| MD-06 6.1.3 — Risk treatment plan | Fail | Head of Information Security | 24 Nov 2026 | 6 | In use for less than 3 months. | |
| MD-07 6.2 — Information security objectives | Fail | Head of Information Security | 21 Oct 2026 | 7 | Not approved. Not under document control. No evidence of use yet. | |
| MD-08 7.2 — Evidence of competence | Fail | HR Director | 1 Dec 2026 | 8 | In use for less than 3 months. | |
| MD-09 7.5.1 — Documented information the organisation decides it needs for the ISMS to be effective | Fail | Head of Information Security | 24 Nov 2026 | 9 | Approval incomplete. Document control incomplete or review overdue. | |
| MD-10 8.1 — Evidence that processes have been carried out as planned | Fail | Head of Information Security | 6 Oct 2026 | 10 | In use for less than 3 months. | |
| MD-11 8.2 — Results of risk assessments | Fail | Head of Information Security | 20 Oct 2026 | 11 | In use for less than 3 months. | |
| MD-12 8.3 — Results of risk treatment | Fail | Head of Information Security | 2 Dec 2026 | 12 | Covers only part of the item, or is a draft. No evidence of use yet. | |
| MD-14 9.2.2 — Internal audit programme and audit results | Fail | Head of Information Security | 23 Dec 2026 | 14 | Covers only part of the item, or is a draft. Not approved. Not under document control. No evidence of use yet. | |
| MD-16 10.2 — Nonconformities, actions taken and results of corrective action | Fail | Head of Information Security | 11 Nov 2026 | 16 | Covers only part of the item, or is a draft. No evidence of use yet. | |
Annex A documents to act on — missing first
| Item | Result | Owner | Target date | Map row | What is missing | |
|---|---|---|---|---|---|---|
| AD-13 A.5.31 — Register of legal, statutory, regulatory and contractual requirements | Missing | Legal Counsel | 28 Oct 2026 | 13 | Create it, have it approved and put it under document control. | |
| AD-23 A.8.9 — Approved baseline configurations | Missing | Head of IT | 11 Nov 2026 | 23 | Create it, have it approved and put it under document control. | |
| AD-01 A.5.1 — The information security policy and the topic-specific policies | Fail | Head of Information Security | 18 Nov 2026 | 1 | Approval incomplete. Document control incomplete or review overdue. | |
| AD-02 A.5.2 — Security roles and responsibilities | Fail | Head of Information Security | 3 Nov 2026 | 2 | In use for less than 3 months. | |
| AD-03 A.5.9 — Inventory of information and other assets, with owners | Fail | Head of IT | 20 Oct 2026 | 3 | In use for less than 3 months. | |
| AD-04 A.5.10 — Rules for acceptable use | Fail | Head of Information Security | 18 Nov 2026 | 4 | Document control incomplete or review overdue. | |
| AD-05 A.5.12 — Classification scheme | Fail | Head of Information Security | 17 Nov 2026 | 5 | In use for less than 3 months. | |
| AD-07 A.5.18 — Records of access rights granted, changed, reviewed and removed | Fail | Head of IT | 3 Nov 2026 | 7 | In use for less than 3 months. | |
| AD-08 A.5.19 — Rules for managing information security risk from suppliers | Fail | Head of Procurement | 7 Oct 2026 | 8 | Not approved. Not under document control. No evidence of use yet. | |
| AD-09 A.5.20 — Security requirements in supplier agreements | Fail | Head of Procurement | 4 Nov 2026 | 9 | Covers only part of the item, or is a draft. Document control incomplete or review overdue. No evidence of use yet. | |
| AD-12 A.5.30 — ICT continuity plans and records of their tests | Fail | IT Operations Manager | 28 Oct 2026 | 12 | No evidence of use yet. | |
| AD-14 A.5.34 — Records of processing of personal data | Fail | Legal Counsel | 6 Oct 2026 | 14 | In use for less than 3 months. | |
| AD-15 A.5.36 — Records of compliance checks and approved exceptions | Fail | Head of Information Security | 10 Dec 2026 | 15 | In use for less than 3 months. | |
| AD-16 A.5.37 — Documented operating procedures for IT operations | Fail | IT Operations Manager | 24 Nov 2026 | 16 | Document control incomplete or review overdue. In use for less than 3 months. | |
| AD-18 A.6.3 — Records of awareness and training completed | Fail | Head of Information Security | 14 Dec 2026 | 18 | In use for less than 3 months. | |
| AD-20 A.6.6 — Signed confidentiality or non-disclosure agreements | Fail | HR Director | 6 Oct 2026 | 20 | In use for less than 3 months. | |
| AD-22 A.8.8 — Rules for technical vulnerability management, and scan and remediation records | Fail | Head of IT | 10 Dec 2026 | 22 | In use for less than 3 months. | |
| AD-24 A.8.13 — Backup rules and records of restore tests | Fail | Head of Information Security | 18 Nov 2026 | 24 | Document control incomplete or review overdue. | |
| AD-25 A.8.15 — Logging rules and log retention | Fail | Head of IT | 10 Nov 2026 | 25 | In use for less than 3 months. | |
| AD-26 A.8.24 — Rules for cryptography and key management | Fail | Head of IT | 24 Nov 2026 | 26 | In use for less than 3 months. | |
| AD-27 A.8.25 — Secure development rules | Fail | Head of Engineering | 24 Nov 2026 | 27 | In use for less than 3 months. | |
Sign-off
| Role | Name | Date | Signature or approval reference | |||
|---|---|---|---|---|---|---|
| Checked by | [[Name]] | [[YYYY-MM-DD]] | [[Reference]] | |||
| Reviewed by (ISMS manager) | [[Name]] | [[YYYY-MM-DD]] | [[Reference]] | |||
| Next check due | [[Before Stage 1 / before Stage 2]] | [[YYYY-MM-DD]] | ||||
Lists
| Check | CheckNA | CheckExists | ItemType | Result |
|---|---|---|---|---|
| Yes | Yes | Yes | Document | Pass |
| Partly | Partly | Partly | Record | Fail |
| No | No | No | Missing | |
| N/A | N/A | N/A |
Not answered
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Documented information | Information the organisation must control and keep, and the medium it is on (clause 7.5): documents that say what will be done, and records that show what was done. |
| Document | Documented information that says what will be done, such as a policy, a procedure or the scope. It is approved and reviewed. |
| Record | Documented information that shows something was done, such as an audit report or training record. It is kept, protected and retained, not approved. |
| Document control | Identification, versioning, review and approval, distribution, access, storage, retention and disposal (clause 7.5.2 and 7.5.3). |
| Evidence of use | Proof that a document is followed or a record is produced, over long enough for an auditor to sample: this checklist uses [[3]] months (IS-05). |
| Statement of Applicability (SoA) | The document listing every Annex A control, whether it is applied and why (clause 6.1.3): see the Statement of Applicability Template. |
| Stage 1 audit | The first part of the certification audit, which reviews the ISMS documents and readiness; missing required documents are usually found here. |
| EXAMPLE | Values for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Replace them with your own. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 7.5 — Documented information | Whole workbook: the documented information the ISMS needs, and the four checks |
| ISO/IEC 27001:2022 | Clause 7.5.3 — Control of documented information | Check 3: under document control |
| ISO/IEC 27001:2022 | Clause 4.3 — Determining the scope of the information security management system | Item MD-01: the scope |
| ISO/IEC 27001:2022 | Clause 6.1.3 — Information security risk treatment | Items MD-04 to MD-06: risk treatment process, Statement of Applicability and risk treatment plan |
| NIST CSF 2.0 | GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed” | Annex A Documents: the register of legal, regulatory and contractual requirements (AD for 5.31) |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0