Guide

How do you implement ISO 27001? A realistic step-by-step guide

How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.

Summary

An ISO 27001 implementation typically runs through scope, gap analysis, risk assessment, control selection and Statement of Applicability, implementation of measures, awareness, internal audit, management review and the two-stage certification audit. Many small and mid-sized organizations need six to twelve months. What decides success is less the documentation than whether the ISMS fits how the organization works.

ISO/IEC 27001 implementation follows a recognizable sequence. The steps below are what most successful projects have in common — plus the points where projects typically stall.

1. Clarify the goal and scope

Why do you need ISO/IEC 27001 — for a customer, a tender, NIS2, or to get information security under control? The answer shapes the scope: which organizational units, locations, systems and services are included.

A good scope is meaningful to your customers and manageable for your team. Too broad, and the project drowns. Too narrow, and the certificate does not answer the question customers actually ask.

2. Understand what already exists

Before writing anything new, look at what you already have: IT policies, access processes, backup concepts, supplier contracts, a quality management system, a wiki, a ticketing system. Integrate before you replace — existing structures are often a solid basis.

3. Gap analysis

The gap analysis compares your current state with the requirements of ISO/IEC 27001 — the management system clauses and the Annex A controls. The result is a prioritized list of what is missing, with a realistic estimate of effort.

4. Risk assessment and treatment

This is the heart of the ISMS:

  • Identify relevant assets (information, systems, services, people, suppliers).
  • Identify risks and assess them by likelihood and impact.
  • Decide how to treat each risk: reduce, avoid, transfer or accept.
  • Document the decisions in a risk treatment plan with owners and deadlines.

The method should be simple enough that risk owners can apply it themselves. A method only the consultant understands will not survive the first year.

5. Controls and Statement of Applicability

Based on the risks, you select controls — using the 93 reference controls in Annex A as a checklist. The Statement of Applicability (SoA) records which controls apply, why, and their implementation status. It should reflect reality, not intentions.

6. Implement measures

Now the actual work happens: policies and procedures are written, access rights cleaned up, backups tested, suppliers reviewed, logging improved. Many measures are organizational; some require technology. Where technology is needed, check existing tools first before buying new ones.

This is the phase where purely advisory projects often stall — because the task list is long and the internal team is busy. It helps to work on measures together, with clear owners and a steady rhythm.

7. Awareness and competence

Employees need to know the relevant rules and why they exist. Process and system owners need to understand their role in the ISMS. Training works best when it is connected to your real systems and policies — and when knowledge is transferred during the work, not only in a yearly session.

8. Objectives, KPIs and monitoring

Define a small number of measurable information security objectives and indicators that management actually looks at — for example patch times, completed training or closed corrective actions.

9. Internal audit and management review

Before certification, an internal audit checks whether the ISMS meets the requirements and works in practice. The management review evaluates results, decides on improvements and confirms resources. Both must be documented.

10. Certification audit

An accredited certification body carries out the audit in two stages. Findings are addressed with corrective actions. After certification, annual surveillance audits follow.

What makes the difference

  • Fit — an ISMS that describes how you really work, not a template company.
  • Ownership — risk and process owners understand and carry their part.
  • Integration — ISMS tasks live in the tools people already use.
  • Momentum — someone coordinates, follows up and keeps the work moving.
  • Knowledge transfer — your team can run the ISMS after the project.

Certification is the starting point. A working management system is the goal.

Frequently asked questions

How long does ISO 27001 implementation take?

It depends on scope, size and starting point. For many small and mid-sized organizations, six to twelve months from kick-off to certification readiness is realistic. Existing structures — for example an ISO 9001 system — can shorten this.

What does the certification audit look like?

It usually has two stages. Stage 1 reviews documentation and readiness; stage 2 checks whether the ISMS is actually implemented and effective. Afterwards, surveillance audits follow annually and a recertification after three years.

What is a gap analysis?

A structured comparison between your current state and the requirements of ISO/IEC 27001. It shows what is missing — and, just as important, what already exists and can be reused.

Talk to us

Want to tackle this in your organization? We help — together with your team.

contact@feldmanncyber.com · +49 (0)151 6275 6121