This eight-step roadmap organises the work of building an ISMS. It is a practical sequence, not a promise that certification can be completed within a fixed number of weeks. Progress depends on actual scope and available evidence.
1. Define scope and context
Describe the services, locations, information systems and boundaries of the ISMS. Identify relevant stakeholders and contractual or legal requirements.
2. Assign responsibilities
Have management establish ownership and decision rights. Identify who accepts risks, allocates resources and monitors progress.
3. Assess information security risks
Choose a repeatable assessment method. Describe risks, existing safeguards, consequences and priorities within the defined scope.
4. Select controls and document applicability
Record relevant control choices and implementation in the Statement of Applicability. Explain the decisions through risks and applicable requirements.
5. Implement controls and collect evidence
Connect working practices to operational systems. Keep examples of access decisions, changes, incident handling and checks that actually took place.
6. Conduct an internal audit
Plan an independent assessment of the work. Record criteria, samples, findings and owners responsible for corrective action.
7. Review and improve with management
Discuss performance, risks, findings and resources. Keep decisions, action owners and follow-up rather than only a slide presentation.
8. Prepare for external assessment
Agree scope and timing with the certification body. Address relevant findings and maintain the internal review cycle after certification.
Budget and readiness
The existing small-scope budget indication is EUR 4,000–15,000 in external first-year expenditure plus internal time. This is an editorial estimate, not a guaranteed price. Use the cost guide to compare quotations. Schedule the audit around completed work, available evidence and the certification body’s availability.