Skip to content

ISO/IEC 27001:2022 Implementation Kit

A complete paper set for taking an organisation from nothing to certified. Seventeen Word documents and one Excel workbook, built so your own team does the work and understands it afterwards. Free, no sign-up, adapt it as you like.

Download the kit (ZIP, ~470 KB)

Why it is built this way: The hard part of ISO 27001 is not the policies.

Everything is a working file, not a sample. Text in [square brackets] is yours to complete; shaded GUIDANCE boxes explain the decision and are meant to be deleted before you issue the document.

The design decision behind it

Most template packs give you a folder of policies and leave the hard part — proving each requirement is met — as an exercise. This one inverts that.

Every requirement of Clauses 4 to 10, and all 93 Annex A controls, exists as its own row, with its own owner, status, date and evidence pointer. Fifty-four requirement rows and ninety-three control rows. Nothing can be quietly skipped, because a skipped row is visibly blank, and the dashboard counts it.

That is the whole idea. The documents hang off the workbook, not the other way round.

What is in it

What it is
Implementation & Assessment Workbook Excel, 27 tabs. The centre of the kit
01 How to Use This Kit Milestones, working sessions, the questions that get real answers, warning signs, FAQ
02 ISMS Scope Document Clause 4.3, with the four-step ISO/IEC 27003 route to a scope
03 Information Security Policy Clause 5.2. Three to five pages, deliberately
04 Risk Management Methodology Clauses 6.1.2 and 6.1.3, aligned with ISO/IEC 27005:2022
05 Topic-Specific Policy Pack Seventeen policies, one owner each
06 Gap Analysis Report Where you are today, with effort estimates
07 Internal Audit Plan and Report Clause 9.2, including the independence trap
08 Management Review Pack and Minutes Clause 9.3, structured on the required inputs
09 Nonconformity and Corrective Action Report Clause 10.2, one per finding
10 Measurement Plan Clause 9.1, structured on ISO/IEC 27004:2016
11 Document Control Procedure Clauses 7.5.2 and 7.5.3
12 Incident Response Plan and Runbooks A.5.24 to A.5.28
13 Business Continuity and ICT Recovery Plan A.5.29 and A.5.30, with a BIA that assesses impact over time
14 Contract Security Schedule A.5.19 to A.5.22. A contract annex, usable in either direction
15 Operating Procedure Template One copy per procedure
16 ISO 27003 and 27004 Conformance Matrix Reference: what the guidance standards expect, and where this kit answers them
17 Current Standard Supplement Reference: the 2024 climate amendment, and the 2022 control changes

The workbook

Twenty-seven tabs. The ones people miss are marked.

Tab What it carries
00 Read Me · 01 Dashboard How the wiring works; a formula-driven view of completion by clause, control and milestone
02 Clauses 4-10 54 requirement rows in plain English, each with what "done" looks like and typical evidence. Includes the 4.1 climate amendment row
03 Annex A and SoA All 93 controls. Becomes your Statement of Applicability
04 Mandatory Documents The 27 documents and records an auditor will ask for by name
05 Document Register 52 entries, including the external-origin documents most registers forget
06 Interested Parties · 07 Asset Inventory Clause 4.2; the inventory the risk work starts from
08 Risks and Opportunities Risks to the management system, not to your information. Clause 6.1.1, and the most-missed requirement in the standard
09 Risk Register · 10 Risk Treatment Plan The risk work, wired to the SoA
11 RACI · 12 Competence Matrix · 13 Communication Plan Clause 5.3 and Clause 7. Quick, and easy to forget
14 Implementation Plan · 15 Evidence Log · 16 Nonconformities The delivery layer
17 Objectives · 18 Measurement Plan Clauses 6.2 and 9.1, with the ISO/IEC 27004 measurement roles named per measure
19 ISMS Change Log · 20 Exceptions Register Both requirements in disguise. Clause 6.3, and the evidence that exceptions are decisions rather than drift
21 Legal Register · 22 Supplier Register · 23 Retention Schedule · 24 Cloud Responsibility The registers that answer the questions auditors actually ask
25 Continual Improvement · 26 Lookups Clause 10.1; the dropdown source lists

Pale cells are yours to complete. Grey cells are reference material — the requirement, the guidance, the milestone. The Dashboard is entirely formulas.

On the control attributes

Tab 03 carries control type, information security properties, cybersecurity concepts, operational capabilities and security domains, so the control set can be filtered by any of them. Filtering by operational capability turns a list of 93 into eight or nine work packages. Those values are this kit's assignment following the ISO/IEC 27002:2022 scheme, not a reproduction of ISO's attribute tables. Where you need ISO's exact values, reconcile against your licensed copy.

The shape of the work

Six milestones. The timings assume a 30 to 250 person organisation, a moderate scope and one part-time ISMS owner. Halve them for a well-resourced 20-person SaaS company; double or triple them for a multi-site, multi-entity, regulated organisation.

Milestone Weeks Where it goes wrong
M1 Mandate & Scope 1-4 Scope creep in reverse — everything goes in scope "to look good"
M2 Risk & Applicability 3-10 Risk assessment done as a paper exercise by one person in a room
M3 Core Documentation 6-16 A 90-page policy nobody has opened
M4 Control Build-out 8-30 Underestimated by a factor of two, every time
M5 Operate & Evidence 20-38 Cannot be compressed. Documents all dated the same fortnight are the clearest possible tell
M6 Audit & Certify 34-52 Internal audit performed by the person who built the ISMS

The guide breaks these into ten working sessions, each with named attendees, a stated input, a stated output, and the questions that open the room up.

What this kit will not do for you

  • It will not shorten M5. A certification body expects to see the ISMS having operated, which in practice means at least three months of dated records. Nothing shortens that.
  • It is not a substitute for the standard. You need licensed copies of ISO/IEC 27001:2022 and ISO/IEC 27002:2022. The kit restates requirements in plain English for working purposes; the standard is the authority.
  • It has no NIS2 or national content. It is pure ISO 27001. If you are also in NIS2 scope, this is the management-system half of the job, not all of it.
  • It does not decide anything for you. Applicability, scope and risk acceptance are decisions the kit structures and records. It does not make them.

This kit uses the clause numbering and the Annex A control reference numbers and short titles from ISO/IEC 27001:2022 as identifiers. All requirement restatements, guidance, evidence suggestions, questions and commentary are original text written for this kit. No part of ISO/IEC 27001:2022 or ISO/IEC 27002:2022 is reproduced.

  • ISO/IEC 27001:2022 — the requirements
  • ISO/IEC 27001:2022/Amd 1:2024 — climate action changes. Free, one page, and it amends Clause 4
  • ISO/IEC 27002:2022 — control implementation guidance
  • ISO/IEC 27003:2017 (implementation guidance), ISO/IEC 27004:2016 (measurement), ISO/IEC 27005:2022 (risk) — used to structure documents 04, 10, 16 and 17

Verify before you rely on it

Practitioner material, not legal advice, and not a guarantee of certification. Check every clause and control reference against the current published standard before operational use.