SecurSentry
← All notes
Cyber Essentials

ISO 27001 Requirements: What the Standard Asks of an SME

The mandatory parts of ISO 27001 are smaller and more sensible than they first look, and the standard scales to a business your size.

The short version

If you have started reading about ISO 27001, you have probably met two scary-sounding numbers: seven clauses of formal requirements and ninety-three controls. It is easy to assume you must do all of it, to the letter, before anyone will take you seriously. The good news is that the ISO 27001 requirements are more sensible than that first impression suggests, and once you see how the pieces fit together, the whole thing becomes a lot less daunting.

This guide walks through what the standard genuinely asks of a UK small or medium business, in plain English. We will separate the parts you must do from the parts you choose, cover the documents you need to hold, bust a few myths, and show why the standard scales down to a business your size.

What “requirements” actually means in ISO 27001

The true requirements are the “shall” statements in clauses 4 to 10, which set out how to run a management system, while the Annex A controls are a menu you select from.

This distinction is the single most useful thing to understand. The current version of the standard, ISO/IEC 27001:2022, is built in two parts. The first part, the numbered clauses from 4 through 10, contains the mandatory requirements. These are the auditable “shall” statements a certification body checks you against. The second part, Annex A, lists 93 reference controls you can draw on to treat your risks. You are not required to apply all of them.

People trip up here constantly. They see 93 controls and start building a project plan to implement every one, when the standard never asks for that. The clauses tell you to run a proper information security management system, or ISMS. The controls are simply the toolbox you reach into once you know what you are protecting against.

The one-line version

Clauses 4 to 10 are what you must do. Annex A is what you may choose to do about it. Your risk assessment decides which controls make the cut, and your Statement of Applicability records those choices.

The seven clauses, in plain English

Clauses 4 to 10 describe a sensible management cycle: understand your situation, take charge of it, plan around risk, support the work, run it, check it, and improve it.

Here is what each mandatory clause is really asking.

Clause 4, Context and scope. Work out what your business does, who cares about your information security (customers, regulators, staff), and where the boundaries of your ISMS sit. Scope is your friend here. You define what is in and what is out, and a tight, honest scope keeps the whole exercise manageable.

Clause 5, Leadership and policy. Someone senior has to own this and mean it. You produce a short information security policy and make sure roles and responsibilities are clear. For a small firm this might be the founder and one other person, and that is perfectly acceptable.

Clause 6, Planning and risk. This is the engine room. You assess the risks to your information, decide how to treat each one, and set some security objectives. The risk assessment is what drives your choice of controls, so it earns its place at the heart of the standard.

Clause 7, Support. Give the ISMS what it needs to function: competent people, some awareness across the team, and the documented information the standard calls for. This is also where the rules about keeping and controlling your documents live.

Clause 8, Operation. Actually do the things you planned. Run your risk assessment at planned intervals, carry out your risk treatment, and keep the day-to-day security running as intended.

Clause 9, Performance evaluation. Check that it works. This clause covers monitoring, an internal audit of your own ISMS, and a management review where leadership sits down and looks at how things are going.

Clause 10, Improvement. When something goes wrong or falls short, deal with it, record it, and stop it recurring. The standard expects continual improvement rather than a one-off effort that gathers dust.

Spot the pattern

Those seven clauses are a Plan, Do, Check, Act loop dressed in formal language. If your business already reviews how it works and fixes what breaks, you are closer to ISO 27001 than you think.

Risk assessment and the Statement of Applicability

Your risk assessment identifies what could go wrong, and the Statement of Applicability records which Annex A controls you are using to address it and why.

The risk assessment does not need to be a fifty-page technical treatise. It needs to be honest and repeatable. Identify your information assets, think about what could threaten them, judge how likely and how damaging each risk is, and decide what to do: reduce it, accept it, avoid it, or share it.

Once you know how you are treating each risk, you pick the controls that help. That is where the Statement of Applicability, or SoA, comes in. The SoA is a required document under the standard. It lists the Annex A controls, states whether each one applies to you, gives your reason for including or excluding it, and notes how the applicable ones are handled. The 93 controls sit across four themes: organisational, people, physical, and technological. Many small businesses find that a fair few controls genuinely do not apply, and writing “not applicable, because…” is a completely valid, documented answer.

If you are weighing this against a lighter-touch scheme first, our guide to Cyber Essentials vs ISO 27001 explains where each one fits.

The documented information you must hold

You need a modest set of records, not a filing cabinet: a scope, a policy, your risk method, the SoA, and evidence that the system is running.

The word “documentation” scares people, so let us be concrete about the sorts of documented information ISO 27001 expects you to keep:

For a small business, several of these can be short. A policy can be a couple of pages. A risk treatment plan can be a simple table. What matters is that the documents are real, current, and match what you actually do, not that they are long. Auditors are far happier with a lean set of honest records than a thick binder nobody follows.

Myth-busting: what ISO 27001 does not require

A lot of the fear around ISO 27001 comes from requirements it never actually imposes.

Let us clear a few of these away.

A reassuring frame

ISO 27001 rewards businesses that are honest about their risks and steady about managing them. It does not reward the biggest budget or the longest documents.

How much realistically applies to a small business

The standard is deliberately scalable, so a small firm meets the same clauses as a large one but with proportionate effort and far fewer controls in scope.

This is the part that tends to relieve people most. Nothing in ISO 27001 says a ten-person company must do as much as a ten-thousand-person company. The clauses are written to flex. Your scope is smaller, your risk assessment is simpler, your documents are shorter, and your Statement of Applicability legitimately excludes controls that do not touch your business.

A very small team might run its whole management review as a focused meeting a couple of times a year, keep a single risk register, and hold a compact set of policies. That can be entirely compliant. The effort is real, but it is front-loaded and then maintained, which is why so much of the value comes from doing the groundwork once and keeping it fresh.

When you are ready to certify, the certificate itself is issued by a certification body. In the UK, a certificate from a UKAS-accredited body carries the most weight, particularly if larger customers or public-sector procurement are in your future. For a broader picture of the journey and what it costs, our overviews of ISO 27001 for SMEs and the ISO 27001 certification cost are good next stops. And if you are earlier in your security journey, the Cyber Essentials checklist is a sensible, lower-cost first step that builds many of the same habits.

The requirements of ISO 27001 are not a wall. They are a well-worn path, and it scales to fit a business your size.


SecurSentry is launching soon to help UK SMEs turn the ISO 27001 requirements into a clear, maintainable set of steps, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.

This article is for general information only and does not constitute legal or compliance advice. ISO 27001 requirements vary by organisation and scope; where in doubt, consult a qualified professional or an accredited certification body.

Frequently asked questions

What are the mandatory requirements of ISO 27001?

The mandatory requirements are the 'shall' statements in clauses 4 to 10 of ISO/IEC 27001:2022: understanding your context and scope, leadership and an information security policy, planning around risk, providing resources and competence, running your operations, evaluating performance through internal audit and management review, and improving over time. These clauses apply to every organisation. Annex A controls are selected, not mandated.

Do I have to implement all 93 Annex A controls?

No. Annex A is a reference set of 93 controls grouped into four themes. You assess your risks, decide which controls are relevant, and record each inclusion or exclusion with a reason in your Statement of Applicability. A small business often finds a meaningful number of controls simply do not apply, and that is a legitimate, documented decision.

How much documentation does ISO 27001 actually require?

Less than most people fear. You need a defined scope, an information security policy, a risk assessment and treatment method, the Statement of Applicability, and records that show your ISMS is working, such as internal audit results and management review notes. For a small firm this can be a modest set of documents, not a filing cabinet.

Is ISO 27001 realistic for a small UK business?

Yes. The standard is deliberately scalable, so the requirements flex to your size and risk profile. A small team meets the same clauses as a large enterprise but with proportionate effort, lighter records, and fewer controls in scope. The work is real, but it is the kind you do once and then maintain.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.