Free kit
ISO 27001:2022 Compliance Checklist
Check that your ISMS documents, clauses 4–10 and Annex A controls are audit-ready before certification.
An eight-page readiness checklist for ISO/IEC 27001:2022. Use it before a certification or surveillance audit to confirm that every required document, clause requirement and selected control is in place — and to see exactly where the gaps are.
What is inside
Part 1 — Mandatory documents and records: the documented information the standard explicitly requires, from the ISMS scope (4.3) to the nonconformity and corrective action log (10.2), each with its clause and purpose.
Part 2 — Recommended supporting documents: the policies and records auditors routinely ask for, mapped to the related Annex A controls.
Part 3 — Clause-by-clause compliance review: assessment questions for clauses 4 to 10.
Part 4 — Statement of Applicability review: a check that the Annex A controls you selected are implemented and working.
Who it is for
Information security managers, ISMS implementers, internal auditors and consultants preparing an organisation for ISO/IEC 27001:2022 certification or transition.
How to use it
Work through it alongside your risk assessment and your latest internal audit findings. Tick what exists, note what does not, and turn every gap into an action with an owner and a date. Print it, or complete it on screen and keep it as a record of your readiness review.
What is in the kit
- ISO/IEC 27001:2022 Compliance Checklist8 pages: mandatory documents, supporting documents, clauses 4–10 review and Statement of Applicability review.83 KB
A look inside
The first pages of ISO/IEC 27001:2022 Compliance Checklist. The full document downloads from the list above.
Next step
Learn to use it properly — with a certificate
The documents tell you what to check. These courses teach you how to audit and implement it, online and at your own pace.
Questions people ask
Is the ISO 27001:2022 Compliance Checklist really free?
Yes. There is no payment and no trial. Tell us your name, work email and company once, and every document in the Free Zone is yours to download.
What format are the documents in?
This kit has 1 document in PDF format.
Can I use it inside my company?
Yes. The licence covers one organisation with unlimited internal use — print it, share it with colleagues and adapt it. Please do not resell it or republish it as your own.
Does this make us compliant with ISO/IEC 27001?
No document can do that on its own. It is a practical working tool to help you prepare, check and improve. Conformity with ISO/IEC 27001 is decided by an audit of your actual system, and the standard itself remains the authoritative text.
Do you offer training on this topic?
Yes. Skedmia runs online courses with certificates on the standards and topics these kits cover — the matching courses are listed on this page.
More from the Free Zone
FreeNewEditableCyber Security Risk Mitigation Checklist
80 controls in 10 risk areas, each with the reason it matters — plus a 5 × 5 cyber risk register template.
FreeNewEditableAWS Security Checklist
90 checks to review an AWS account — root user, IAM, network, S3 and databases, encryption, logging, detection and recovery.
FreeNewEditableIT Security Audit Checklist
120 audit checks across 12 control areas, plus an audit plan and findings log — ready for your next internal IT audit.


