Skip to content

ISO 27001 implementation roadmap

Eight practical steps connect scope, risk, controls and evidence. Certification requires an external assessment; software alone cannot provide it.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

This eight-step roadmap organises the work of building an ISMS. It is a practical sequence, not a promise that certification can be completed within a fixed number of weeks. Progress depends on actual scope and available evidence.

1. Define scope and context

Describe the services, locations, information systems and boundaries of the ISMS. Identify relevant stakeholders and contractual or legal requirements.

2. Assign responsibilities

Have management establish ownership and decision rights. Identify who accepts risks, allocates resources and monitors progress.

3. Assess information security risks

Choose a repeatable assessment method. Describe risks, existing safeguards, consequences and priorities within the defined scope.

4. Select controls and document applicability

Record relevant control choices and implementation in the Statement of Applicability. Explain the decisions through risks and applicable requirements.

5. Implement controls and collect evidence

Connect working practices to operational systems. Keep examples of access decisions, changes, incident handling and checks that actually took place.

6. Conduct an internal audit

Plan an independent assessment of the work. Record criteria, samples, findings and owners responsible for corrective action.

7. Review and improve with management

Discuss performance, risks, findings and resources. Keep decisions, action owners and follow-up rather than only a slide presentation.

8. Prepare for external assessment

Agree scope and timing with the certification body. Address relevant findings and maintain the internal review cycle after certification.

Budget and readiness

The existing small-scope budget indication is EUR 4,000–15,000 in external first-year expenditure plus internal time. This is an editorial estimate, not a guaranteed price. Use the cost guide to compare quotations. Schedule the audit around completed work, available evidence and the certification body’s availability.

Primary sources for this topic

Frequently asked questions

Must all eight steps be completed strictly in sequence?
Some preparations can run in parallel, provided the decisions remain consistent. You can explore certification bodies while building the system, for example. Control choices must still follow the actual scope and risk assessment, and external assessment should reflect implemented work. Treat the roadmap as a sequence of evidence and decisions, not as a rigid promise about project duration.
When should the external audit be booked?
Agree timing with the certification body while checking the readiness of scope, operational evidence, internal audit and management review. Allow room for corrective action. A completed document pack or a software subscription does not establish that the system is operating effectively. The booking should reflect both genuine readiness and the certification body’s available capacity.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)