Skip to content
Information Security Management › ISO27001

ISO 27001 checklist: every requirement in clauses 4 to 10, point by point

An ISO 27001 checklist for the 2022 edition: each requirement in clauses 4 to 10, the Statement of Applicability, the risk treatment plan, management review and the documents an accredited auditor will ask for. Collected in one table you can copy, no PDF download form.

An ISO 27001 checklist on a clipboard, connected to a Statement of Applicability, a plan and a review

Table of Contents

    Most ISO 27001 checklists you can download are a list of ten sensible steps: get management on board, run a risk assessment, train your staff. None of that is wrong, but it is not what an auditor looks for. The auditor opens the standard, works through it clause by clause from 4.1 to 10.2 and asks for documented information against each requirement.

    This ISO 27001 checklist is built the same way. It follows ISO/IEC 27001:2022, covers every requirement in clauses 4 to 10, explains the three documents most often missing when organisations believe they are ready, and ends with a single table of mandatory documented information you can copy into your own working document. There is no gated PDF. Everything is on this page.

    The article is about the requirements, not the certification journey. What ISO 27001 is and what compliance means in practice is covered in our article on ISO 27001 compliance. The certification process itself, with Stage 1 and Stage 2 audits, costs and timelines, is covered in our guide to ISO 27001 certification.

    The short answer: what should an ISO 27001 checklist contain?

    A usable ISO 27001 checklist covers three layers. The first is the management system requirements in clauses 4 to 10. All of them are mandatory and none can be excluded. The second is the 93 reference controls in Annex A, which you compare your own controls against and decide on one by one in the Statement of Applicability (SoA). The third is the documented information the standard explicitly requires: scope, policy, risk process, SoA, risk treatment plan, objectives, evidence of competence, monitoring results, audit programme, management review and nonconformities.

    If one of the three layers is missing, the checklist is not complete. The three items most often skipped are the Statement of Applicability, the risk treatment plan and management review. Each has its own section further down.

    Standard, checklist, SoA and certificate: four things that get mixed up

    Searches for "ISO 27001 checklist" and "ISO 27001 requirements checklist" typically blend four things that belong to different categories. It is worth separating them before you start ticking boxes.

    Term What it is Who produces it
    ISO/IEC 27001:2022 The standard itself, with the requirements in clauses 4 to 10 and Annex A. Copyrighted and sold by ISO and national standards bodies such as BSI, DIN or Dansk Standard. ISO/IEC JTC 1/SC 27. National editions by the national standards body.
    ISO 27001 checklist A working tool that translates the requirements into items you can tick off. Not part of the standard and not something the auditor approves. You, a consultant or a platform.
    Statement of Applicability (SoA) Mandatory document under clause 6.1.3 d). Lists the necessary controls, justifies inclusions and exclusions and states implementation status. The organisation. The auditor uses it to steer the audit.
    ISO 27001 certificate Evidence issued after a two-stage audit. Valid for three years with an annual surveillance audit. A certification body, accredited by a national accreditation body such as UKAS in the UK.

    The point is simple. The checklist is yours, the SoA is mandatory, the standard has to be bought, and the certificate comes from a third party. A completed checklist proves nothing to an auditor on its own. It shows you where the evidence is missing.

    How ISO 27001:2022 is structured

    The current edition is ISO/IEC 27001:2022, published in October 2022. The transition period from the 2013 edition closed on 31 October 2025, so every valid certificate today is issued against the 2022 edition. In February 2024, Amendment 1 added climate change as an issue the organisation must consider under clause 4.1 and as a possible expectation of interested parties under 4.2. Annex A was not changed. ISO/IEC 27000, the vocabulary standard for the whole 27000 family, appeared in a new edition on 3 July 2026, but that does not alter the requirements in 27001. As of 24 September 2026, no new edition of ISO/IEC 27001 has been published.

    The standard has two parts, and the checklist needs to cover both:

    Clause Topic What the auditor typically asks for
    4 Context of the organisation Analysis of internal and external issues, list of interested parties, documented scope
    5 Leadership Approved information security policy, role descriptions, minutes showing top management involvement
    6 Planning Risk assessment process, risk treatment process, SoA, risk treatment plan, measurable objectives, planning of changes
    7 Support Resources, evidence of competence, awareness activities, communication plan, document control
    8 Operation Process descriptions, control of outsourced processes, completed risk assessments and risk treatment results
    9 Performance evaluation Monitoring results, internal audit programme and reports, management review minutes
    10 Improvement Nonconformity log, corrective actions with effectiveness review
    Annex A 93 reference controls in 4 themes SoA with a justification per control and evidence for the ones marked implemented
    ISO 27001:2022 structure: clauses 4 to 10 as a ring around the Annex A themes with 37, 8, 14 and 34 controls

    ISO 27001 checklist: clauses 4 to 10, point by point

    Here is the checklist. Each item refers to the clause the requirement sits in, so you can look it up in the standard and use the same numbering in your SoA and audit preparation. Change ☐ to ✓ when you have both the document and evidence that it is used.

    Clause 4: Context of the organisation

    Clause 4 decides what the ISMS protects and who has requirements of it. Everything else builds on that.

    ☐ 4.1: Internal and external issues relevant to information security are identified and documented, including whether climate change is a relevant issue (requirement added by Amendment 1:2024).
    ☐ 4.2: Interested parties and their requirements are mapped, and it is recorded which of those requirements the ISMS will address (item c) is new in the 2022 edition). Legal requirements such as GDPR Article 32, and for in-scope entities the national NIS2 legislation, belong here.
    ☐ 4.3: The scope of the ISMS is determined, including interfaces and dependencies with other organisations, and is available as documented information.
    ☐ 4.4: The ISMS is established with the processes needed and their interactions.

    Clause 5: Leadership

    The auditor will want to speak with top management, not only with the information security lead. Clause 5 is about what management itself must be able to show.

    ☐ 5.1: Top management can demonstrate its commitment: policy and objectives are established, resources are allocated, the ISMS is integrated into business processes, and management follows up on results.
    ☐ 5.2: An information security policy is approved, communicated internally, available to relevant interested parties and held as documented information.
    ☐ 5.3: Roles, responsibilities and authorities are assigned and communicated, including who reports on ISMS performance to top management.

    Clause 6: Planning

    Clause 6 is the heart of the standard and the place where most gap analyses find the biggest gaps.

    ☐ 6.1.1: Risks and opportunities for the ISMS as a whole are identified and actions planned.
    ☐ 6.1.2: A risk assessment process is documented with criteria for accepting risk and for performing assessments, and the process produces consistent, valid and comparable results. Risks are identified with risk owners, analysed for consequence and likelihood, and prioritised.
    ☐ 6.1.3: A risk treatment process is documented. Necessary controls are determined, compared with Annex A, recorded in a Statement of Applicability and built into a risk treatment plan approved by the risk owners together with acceptance of residual risks.
    ☐ 6.2: Information security objectives are established at relevant functions and levels. They are consistent with the policy, measurable where practicable, monitored, communicated and held as documented information. There is a plan for what will be done, with what resources, by whom, by when and how results are evaluated.
    ☐ 6.3: Changes to the ISMS are carried out in a planned manner (new clause in the 2022 edition).

    Clause 7: Support

    ☐ 7.1: The resources needed to establish, operate and improve the ISMS are determined and provided.
    ☐ 7.2: Necessary competence is determined for people whose work affects information security, and evidence of competence exists, such as training certificates and evaluations.
    ☐ 7.3: Staff are aware of the policy, their own contribution and the implications of not conforming. This is where your awareness training lands.
    ☐ 7.4: It is determined what is communicated about information security, when, with whom and how.
    ☐ 7.5: Documented information is created with identification, format and approval (7.5.2) and controlled for access, versioning, retention and disposal (7.5.3). This covers both the documents the standard requires and those you have judged necessary yourselves.

    Clause 8: Operation

    ☐ 8.1: Processes needed to meet the requirements and carry out the actions from clause 6 are planned with criteria and controlled against them. Externally provided processes, products and services are identified and controlled. This is where supplier management becomes an ISMS requirement and not only an Annex A control.
    ☐ 8.2: Risk assessments are performed at planned intervals and when significant changes occur, and the results are retained as documented information.
    ☐ 8.3: The risk treatment plan is implemented, and the results of risk treatment are retained as documented information.

    Clause 9: Performance evaluation

    ☐ 9.1: It is determined what is monitored and measured, by which methods, when, by whom and when the results are analysed. Results are documented.
    ☐ 9.2: There is an internal audit programme covering frequency, methods, responsibilities, planning requirements and reporting. Audit criteria and scope are defined for each audit, auditors are objective and impartial, and results are reported to relevant management. Programme and results are documented.
    ☐ 9.3: Top management reviews the ISMS at planned intervals using the inputs listed in clause 9.3.2, and the results, including decisions on improvements and changes, are documented.

    Clause 10: Improvement

    ☐ 10.1: The suitability, adequacy and effectiveness of the ISMS are continually improved.
    ☐ 10.2: When nonconformities occur, the organisation reacts, investigates causes, takes corrective action, reviews its effectiveness and documents both the nonconformity and the action.

    Loop from risk assessment (6.1.2) via treatment and SoA, treatment plan, implementation, audit and review to corrective action (10.2)

    The three items most often missing: SoA, risk treatment plan and management review

    When we look at ISO 27001 checklists organisations have used ahead of a first audit meeting, the same three items are missing or incomplete. All three are mandatory, and they depend on each other.

    The Statement of Applicability, clause 6.1.3 d)

    The Statement of Applicability is the document the auditor uses to steer the whole Stage 2 audit. For each control it must contain four things: the necessary controls, the justification for including them, whether they are implemented or not, and the justification for excluding any Annex A control that is not included. An SoA that simply repeats the 93 Annex A titles with a tick does not meet the requirement. Each justification must point back to the risk assessment, to a legal requirement or to a contractual requirement.

    Two points matter here. The Annex A controls are not mandatory in themselves, but you must take a position on every one of them. And you may include controls that are not in Annex A, for example from ISO/IEC 27017 for cloud services or from the NIS2 risk management measures in Article 21(2) of Directive (EU) 2022/2555. They then need to appear in the SoA as well.

    The risk treatment plan, clauses 6.1.3 e) and 8.3

    The risk treatment plan is the action plan for the risks above your acceptance criteria. For each risk it should show the treatment option chosen (modify, retain, avoid or share), which controls are used, who owns the action, when it is due, and that the risk owner has approved the plan and accepted the residual risk. Clause 8.3 requires the plan to be implemented and the results documented. A plan with no status and no dates is one of the most common audit findings.

    Management review, clause 9.3

    Management review is top management's own examination of whether the ISMS works. The standard says "at planned intervals". In practice, certification bodies expect it at least once a year, so that a full cycle of internal audit and management review is complete before the Stage 2 audit and before each surveillance audit. Clause 9.3.2 lists what the review must cover as a minimum:

    Input (9.3.2) What you bring to the table
    a) Status of actions from previous reviews Follow-up list from the last set of minutes
    b) Changes in external and internal issues Updated 4.1 analysis, for example new legislation, new systems, organisational changes
    c) Changes in needs and expectations of interested parties (new in 2022) Updated 4.2 list, for example new customer or regulator requirements
    d) Feedback on information security performance Nonconformities and corrective actions, monitoring results from 9.1, audit results from 9.2, fulfilment of objectives from 6.2
    e) Feedback from interested parties Customer audits, supplier incidents, complaints
    f) Results of risk assessment and status of the risk treatment plan Risk register and plan with status per action
    g) Opportunities for continual improvement Suggestions from audits, staff and incident analyses

    The outputs under 9.3.3 are decisions on continual improvement opportunities and on any need for changes to the ISMS. Minutes that only say "ISMS reviewed, no comments" are not enough. They must show that all seven inputs were considered and what management decided.

    Management review agenda: the seven inputs a) to g) from clause 9.3.2 as a ticked checklist, leading to the two outputs from 9.3.3

    Annex A: 93 controls in four themes

    Annex A in the 2022 edition contains 93 reference controls, down from 114 in the 2013 edition. They are grouped in four themes instead of 14 domains, and 11 controls are new. The full text of the controls and implementation guidance sits in ISO/IEC 27002:2022, which also gives each control five attributes (control type, information security properties, cybersecurity concepts, operational capabilities and security domains) that make them easier to sort in the SoA.

    Theme Count Examples New controls in 2022
    A.5 Organisational 37 Policies (5.1), roles (5.2), supplier relationships (5.19 to 5.23), incident management (5.24 to 5.28), legal requirements (5.31) 5.7 Threat intelligence, 5.23 Information security for use of cloud services, 5.30 ICT readiness for business continuity
    A.6 People 8 Screening (6.1), terms of employment (6.2), awareness and training (6.3), remote working (6.7) None
    A.7 Physical 14 Physical perimeters (7.1), entry (7.2), clear desk and clear screen (7.7), secure disposal (7.14) 7.4 Physical security monitoring
    A.8 Technological 34 Privileged access rights (8.2), malware protection (8.7), backup (8.13), logging (8.15), cryptography (8.24), secure development (8.25 to 8.31) 8.9 Configuration management, 8.10 Information deletion, 8.11 Data masking, 8.12 Data leakage prevention, 8.16 Monitoring activities, 8.23 Web filtering, 8.28 Secure coding

    The checklist item for Annex A is therefore not "have we implemented all 93". It is: have we taken a position on all 93 in the SoA, can we justify each inclusion and exclusion by reference to the risk assessment or a requirement, and can we show evidence for the controls we have marked as implemented.

    Mandatory documented information: the whole ISO 27001 requirements checklist in one table

    This table collects the documents and records ISO 27001:2022 explicitly requires as documented information. Copy it into your own working document, add a column for owner and status, and you have an ISO 27001 checklist template you can take straight into the Stage 1 audit. Documents that follow from the Annex A controls you select, such as an inventory of information assets (A.5.9) or acceptable use rules (A.5.10), come on top.

    Clause Mandatory documented information Type Typical audit evidence
    4.3Scope of the ISMSDocumentScope statement with locations, systems, interfaces and exclusions
    5.2Information security policyDocumentApproved and dated policy, evidence of communication
    6.1.2Risk assessment processDocumentMethodology with acceptance criteria, scales and frequency
    6.1.3Risk treatment processDocumentDescription of treatment options and approval flow
    6.1.3 d)Statement of Applicability (SoA)DocumentAll 93 Annex A controls plus your own, with justification and status
    6.1.3 e)Risk treatment planDocumentPlan with owner, deadline, status and risk owner approval
    6.2Information security objectivesDocumentMeasurable objectives with owner, deadline and measurement method
    7.2Evidence of competenceRecordTraining certificates, CVs, training log
    7.5Documented information the organisation determines necessaryDocument/recordProcedures and templates under version control
    8.1Documentation to the extent needed for confidence in the processesRecordProcess descriptions, supplier register, operational logs
    8.2Results of risk assessmentsRecordDated risk register with risk owners
    8.3Results of risk treatmentRecordCompleted actions and accepted residual risks
    9.1Results of monitoring and measurementRecordKPI reports, for example patch time, completed awareness training, incidents
    9.2Audit programme and audit resultsRecordThree-year programme, audit plans, reports, evidence of auditor independence
    9.3Results of management reviewRecordMinutes covering all inputs in 9.3.2 and decisions under 9.3.3
    10.2Nonconformities, actions and results of corrective actionRecordNonconformity log with root cause analysis and effectiveness review

    One clarification, because the error appears in many guides: a record of processing activities is a requirement under GDPR Article 30, not under ISO 27001. It belongs in your GDPR documentation and can be a useful input to the asset inventory, but it is not on the ISO 27001 checklist.

    The 16 mandatory documents and records in ISO 27001:2022 grouped by clauses 4 to 10, each marked as a document or a record

    Worked example: Harbourline Software runs the checklist

    Harbourline Software Ltd and Priya Shah are fictional. We invented them for this article, and they are neither customers nor a case study.

    Harbourline is a software supplier with 120 employees that hosts case management systems for local authorities in the UK and the Netherlands. Two customers have written ISO 27001 into their next contract renewal, and Priya Shah, the head of IT, has been made responsible for reaching the Stage 1 audit within eight months. She starts with the checklist above rather than with Annex A.

    Working through clauses 4 to 10 gives 41 items. 24 are in place, 10 are partly in place and 7 are missing entirely. The 7 missing items are: documented scope (4.3), measurable objectives (6.2), planning of changes (6.3), a monitoring programme (9.1), an internal audit programme (9.2), management review (9.3) and a nonconformity log (10.2). That is a typical picture for an organisation that has taken security seriously but never run a management system. The controls exist, the cycle does not.

    The risk assessment under 6.1.2 identifies 38 risks. 9 sit above the acceptance criterion and go into the risk treatment plan, each with an owner and a deadline. In the Statement of Applicability, Priya works through all 93 controls. 89 are judged necessary and 4 are excluded with a justification, for example A.8.30 on outsourced development, because all development is in-house. Of the 89, 71 are implemented and 18 sit as actions in the plan: the 9 from the risk assessment and 9 that follow from customer and legal requirements captured under 4.2.

    The sequence to Stage 1 then becomes: scope and policy approved by the board in month 1, risk assessment and SoA complete in month 3, plan actions delivered in months 3 to 6, internal audit in month 6 by an external auditor because nobody in-house is independent of the ISMS, and management review in month 7 with all seven inputs. Stage 1 is booked for month 8. The numbers are invented, but the logic is what the checklist should force: the cycle must have run once before the auditor arrives.

    What the ISO 27001 checklist does not do

    A checklist gives you an overview. It cannot give you four things, and they are worth saying out loud.

    It does not replace the standard. ISO/IEC 27001:2022 is copyrighted and has to be bought from ISO or from your national standards body, such as BSI in the UK. The auditor expects you to know the full wording, not a summary. Phrases such as "consistent, valid and comparable results" in 6.1.2 have a precise meaning.

    It does not make you certified. The certificate is issued by a certification body accredited by a national accreditation body, in the UK by UKAS, against ISO/IEC 17021-1 and ISO/IEC 27006-1:2024. Be aware that "approved", "registered" or "authorised" is not the same as accredited. A certificate from a non-accredited body has limited value in tenders and supplier assessments. According to the ISO Survey 2024, there were 96,709 valid ISO 27001 certificates worldwide, 4,455 of them in the UK, and buyers increasingly check the accreditation mark on the certificate before they accept it.

    It does not make you GDPR or NIS2 compliant. ISO 27001 supports security of processing under GDPR Article 32, but GDPR contains requirements on lawful basis, transparency, records of processing and data subject rights that the standard does not cover at all. The NIS2 Directive (EU) 2022/2555 requires registration, incident reporting within 24 hours, 72 hours and one month under Article 23, and management body accountability under Article 20, none of which sit inside ISO 27001. The ENISA technical implementation guidance from June 2025 maps the Article 21(2) measures to ISO 27001 and other standards and is a good starting point. In the UK, the NIS Regulations 2018 apply, and the Cyber Security and Resilience Bill was at report stage in the House of Lords on 16 September 2026 and has not yet received Royal Assent. See our comparison of NIS2 vs ISO 27001 for the full mapping.

    It does not choose your method. The standard requires a risk assessment process that produces consistent and comparable results, but it does not say which. A simple risk matrix has known weaknesses, and for organisations facing several regimes a single shared method may be better. Our article on information security risk management across GDPR, NIS2, DORA and ISO 27001 walks through the options.

    How .legal supports your ISO 27001 checklist

    The problem with a checklist in a spreadsheet is that it is true on the day it is filled in. Three months later the risk register has changed, three actions are overdue and the SoA still says "implemented". Our information security management module is built to keep the three documents this article is about connected: the risk assessment with risk owners, the risk treatment plan with owners and deadlines, and the Statement of Applicability with a justification and status per control, so it moves when an action is closed.

    Internal audits, management review and the annual policy reviews go into compliance task management, so clauses 9 and 10 become recurring tasks with an owner and evidence rather than a scramble before the surveillance audit. If you are working on NIS2 or GDPR at the same time, the Frameworks module lets you map one control to several regimes, so the supplier review or the awareness training is documented once.

    The platform does not do the work for you, and it does not give you the certificate. It makes sure the checklist still holds when the auditor arrives. Book a demo if you want to see how the SoA, the risk treatment plan and the task calendar fit together in practice.

    FAQ: ISO 27001 Compliance & Certification

    Is there a free ISO 27001 checklist PDF, and do I need one?

    Plenty of vendors offer an ISO 27001 checklist PDF in exchange for an email address. Most are implementation roadmaps of 10 to 14 steps rather than a clause-by-clause requirements checklist. The table of mandatory documented information on this page is ungated and covers clauses 4 to 10. Copy it into your own document, add owner and status columns, and you have a working ISO 27001 checklist template. A PDF adds nothing an editable table does not.

    What is the difference between an ISO 27001 checklist and a Statement of Applicability?

    The checklist is your own working tool and has no formal status. The Statement of Applicability (SoA) is a mandatory document under clause 6.1.3 d) that the auditor uses to steer the Stage 2 audit. For each control it must state whether the control is necessary, why, whether it is implemented, and why any Annex A control has been excluded. The checklist helps you arrive at a correct SoA, but it cannot replace it.

    Are all 93 Annex A controls mandatory?

    No. Annex A is a reference list you compare your own chosen controls against, so that no necessary control is overlooked. What is mandatory is taking a position on each of the 93 controls in the Statement of Applicability and justifying inclusions and exclusions by reference to the risk assessment, a legal requirement or a contractual requirement. You may also add controls from other sources, such as ISO/IEC 27017 or the NIS2 Article 21(2) measures.

    Which documents does ISO 27001:2022 require as a minimum?

    The standard explicitly requires documented information on the ISMS scope (4.3), the information security policy (5.2), the risk assessment and risk treatment processes (6.1.2 and 6.1.3), the Statement of Applicability and risk treatment plan (6.1.3), objectives (6.2), evidence of competence (7.2), results of risk assessment and risk treatment (8.2 and 8.3), monitoring results (9.1), the audit programme and results (9.2), management review (9.3) and nonconformities and corrective actions (10.2). Documents that follow from the controls you select come on top.

    How often must internal audit and management review take place?

    Clauses 9.2 and 9.3 both say 'at planned intervals' and set no fixed period. In practice, certification bodies expect the whole ISMS to be covered by internal audit within the three-year certificate cycle and management review to take place at least once a year, so both are complete before the Stage 2 audit and before each surveillance audit. The frequency must be stated in your audit programme.

    What changed in ISO 27001:2022 compared with the 2013 edition?

    Annex A went from 114 controls in 14 domains to 93 controls in four themes, and 11 controls are new, including threat intelligence, cloud security and secure coding. In clauses 4 to 10, requirements were added to state which interested party requirements the ISMS addresses (4.2 c), to plan changes (6.3), to monitor and document objectives (6.2) and to consider changed interested party needs in management review (9.3.2 c). The transition closed on 31 October 2025.

    What does Amendment 1:2024 on climate change mean for the checklist?

    The February 2024 amendment adds one sentence to clause 4.1: the organisation shall determine whether climate change is a relevant issue. Clause 4.2 gains a note that interested parties can have climate-related requirements. For the checklist, this means your analysis of internal and external issues must show the question was considered, for example data centre location or power supply resilience. Annex A was not changed and no new controls were added.

    Does a record of processing activities belong on an ISO 27001 checklist?

    No. The record of processing activities is a requirement under GDPR Article 30 and falls on the controller and the processor, not on the ISMS. ISO 27001 does not require it, although control A.5.9 on the inventory of information assets and A.5.34 on privacy and protection of PII make it natural to reuse the information. Keep the two documents separate, so you can show the ISO requirement to the auditor and the GDPR requirement to your supervisory authority.

    Who is allowed to carry out the internal audit under clause 9.2?

    Clause 9.2.2 requires auditors to be selected so that objectivity and impartiality are ensured. An auditor must therefore not audit their own work. In a small organisation where the security lead has built the whole ISMS, many choose an external auditor or a colleague from another function with audit competence. ISO 19011 gives guidance on audit programmes and auditor competence, and evidence of independence must be available at the certification audit.

    Does a completed ISO 27001 checklist also cover NIS2 and accreditation requirements?

    Partly. The checklist covers the standard's requirements, and ISO 27001 is a solid foundation for the NIS2 risk management measures in Article 21(2), but the directive has its own requirements on registration, three-stage incident reporting under Article 23 and management accountability under Article 20 that must be added. Accreditation places requirements on the certification body, not on you: it must be accredited against ISO/IEC 17021-1 and ISO/IEC 27006-1, in the UK by UKAS. Check the body you choose is listed by its national accreditation body.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform

    Achieve ISO 27001 Compliance with .legal

    Simplify your ISO 27001 compliance journey with the .legal platform. Track requirements, manage documentation, and prepare for certification audits systematically.
    • Track ISO 27001 requirements and controls
    • Manage Statement of Applicability
    • Document policies and procedures
    • Prepare for certification audits
    • Monitor continuous compliance
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell