SecurSentry
← All notes
Cyber Essentials

An ISO 27001 Checklist for Small Businesses

ISO 27001 looks enormous from the outside. Broken into phases and taken in order, it becomes a series of manageable jobs. Here's the sequence.

The short version

If ISO 27001 has landed on your desk because a big customer or a tender asked for it, the first feeling is usually the same: this looks enormous. And from the outside, it is a lot. The good news is that most of the size comes from the standard being written for organisations of every shape, so a fair chunk of it simply won’t apply to a business of your size. The rest becomes manageable once you stop treating it as one giant wall and start treating it as a sequence of smaller jobs, done in a sensible order.

That order matters more than people expect. ISO 27001 isn’t a checklist you tick off and file away. It certifies an information security management system, an ISMS, which is really just a tidy, repeatable way of running your security so it keeps working after the initial push. But the path to being ready for certification can be sequenced, and each phase below builds on the one before it. Work through them in order and you avoid the classic trap of writing pages of policy before you’ve worked out what you’re actually protecting. Here’s the running order.

Phase 1: Foundations

Before any of the security work, decide what you’re protecting, get leadership genuinely behind it, and put a name against the effort.

Scope is a lever, not a formality

The single biggest influence on how much work certification takes is how wide you draw the scope. A well-chosen scope keeps the whole exercise proportionate to your business. Widen it later, once the system is running smoothly, rather than starting broad and struggling.

Phase 2: Risk

Work out what could realistically go wrong with your information, decide what you’ll do about each risk, and record those decisions in a Statement of Applicability.

You are not obliged to use all 93 controls. The SoA is precisely where you justify leaving out the ones that don’t fit your business. That flexibility is deliberate, and using it honestly is part of doing this well.

Phase 3: Policies and controls

Turn your risk decisions into the actual policies, procedures and technical measures that put the chosen controls into practice.

Phase 4: People

Your controls only work if the people around them understand their part, so build awareness and record that you’ve done it.

Records are the quiet backbone

Right through ISO 27001, the difference between "we do this" and "we can prove we do this" is written records. Get into the habit early of logging decisions, reviews and completed tasks. It feels like admin now and saves you badly during the audit.

Phase 5: Run it

An ISMS has to be seen working before it can be certified, so operate it for a while and check it yourself first.

Phase 6: Certification

When your system has been running and you’ve ironed out your own findings, bring in an accredited certification body for the two-stage external audit.

Common trip-ups

A few things catch small businesses out. Drawing the scope too wide is the big one, turning a proportionate project into a slog. Writing polished policies that describe an ideal business rather than your real one is another, because auditors talk to your team and the gap shows. Leaving records as an afterthought bites late, when you can’t evidence work you genuinely did. And treating certification as a finish line rather than a habit means the second year feels as hard as the first. None of these are hard to avoid once you know they’re there. Pace yourself, keep the scope honest, and write things down as you go.

If you’re still weighing up whether ISO 27001 is the right target at all, ISO 27001 for SMEs is a gentler starting point, and what ISO 27001 certification costs sets out the money side plainly.


SecurSentry is launching soon to help UK SMEs work through a path like this without the overwhelm, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.

This article is for general information only and does not constitute legal or compliance advice. Scope and steps vary by organisation; where in doubt, consult a qualified professional or an accredited certification body.

Frequently asked questions

Is ISO 27001 a checklist you can just tick off?

Not quite. ISO 27001 certifies a management system, which is an ongoing way of running your security rather than a one-off form. That said, the path to being ready can absolutely be sequenced into checklist-style phases, which is what this guide does. You build the system, run it for a while, then have it audited.

How long does getting ISO 27001-ready usually take?

It varies a lot by size and starting point, but many small businesses spend several months preparing before the external audit. The standard also expects your management system to have been running and generating records for a period first, so a realistic plan is measured in months rather than weeks. Treat any promise of near-instant certification with caution.

Do I need a UKAS-accredited certification body?

If you want a certificate that customers and partners recognise, yes. UKAS is the UK's national accreditation body, and a certificate from a UKAS-accredited body carries independent oversight and international recognition. A non-accredited certificate may cost less but tends to carry far less weight with the people asking you for proof.

Will my Cyber Essentials work count towards ISO 27001?

The technical controls behind Cyber Essentials, such as firewalls, secure configuration, access control, malware protection and keeping software updated, line up with several of ISO 27001's technology controls. The certifications are separate and ISO 27001 asks for a good deal more around risk and management, but the groundwork genuinely carries forward rather than being redone.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.