Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Analyst wearing a headset in front of a wall of monitoring screens in a darkened room

ISO 27001 checklist: what your supplier delivers, and what stays with you

Most checklists online are written by parties who want to certify you. This one is written from the other side: which controls come out of your IT, who delivers them, and what evidence an auditor will ask for later.

7 min read Written by the ITproposal team
Short answer

Annex A of ISO 27001:2022 lists 93 controls across four themes. Part of that is technology and therefore sits with whoever runs your IT; the rest is policy and stays with you.

A supplier cannot certify you and cannot tick the standard off on your behalf. What a supplier can do: deliver the technical controls and the evidence you use to demonstrate them.

Start with the evidence, not with the control. A control that works but records nothing does not exist as far as an auditor is concerned.

What this checklist is and is not

ISO/IEC 27001 is a standard, and a standard can be assessed. That assessment is done by an accredited certification body and by nobody else. We are not one and will not become one, so what follows is not a certification path but a work list.

Here is why we know what an auditor looks for: this company is itself ISO 27001, ISO 9001 and ISO 14001 certified. That says something about how we work and nothing about how you meet the standard, a certificate is not something you can inherit from us.

Annex A of the 2022 version lists 93 controls across four themes: organisational, people, physical and technological. That last group is where your IT supplier sits. This piece is about that group, and about the line around it.

The controls that sit with your IT supplier

Access and identity. Who may reach what, and how someone loses that again. This is not one control but a chain: creating an account, the rights attached to it, elevated rights handled separately, and revocation on departure. That last step is the one most often missed, a leaver whose account is still alive is a finding you cannot repair on the day of the audit.

Strong authentication. MFA on everything reachable from outside, and conditional access for the rest. A password policy without a second factor no longer meets the standard.

Logging and monitoring. Record what happens, keep it long enough, and act on it. This is where most organisations come unstuck: logging happens, but nobody can show afterwards what was logged and how long it was kept.

Backup that survives an attack. Not merely that a copy exists, but that the copy cannot be altered by whoever gets into the environment, and that a restore has been demonstrably tested.

Encryption and key management. Encrypting is the easy part. The question an auditor asks is about the keys: who manages them, where they live, and what happens when that person is away.

Vulnerabilities and patching. Knowing what you have, knowing what is wrong with it, and being able to show the pace at which it gets fixed.

Segmentation. That a guest, a workstation and a payment terminal join the same network and end up in different corners of it.

The controls that stay with you

This part cannot be outsourced, and that is the design of the standard rather than reluctance on anyone’s part. An auditor puts these questions to the board, not to the supplier.

The scope. What falls inside your management system and what does not. This is the first question of every audit and the only one you have to defend yourself, because it determines what your whole certificate is worth.

The risk assessment and the statement of applicability. Which of the 93 controls you apply, which you do not, and why not. A supplier can bring in what is technically at play; the judgement stays yours.

Policy, management review and internal audit. The standard asks that leadership looks at this with some regularity and records that it did. That is an hour a quarter, almost always skipped and almost always a finding.

People. Awareness, terms on joining, what happens on leaving. Technology does not cover this.

Supplier management. We are a supplier to you as well. Assessing us and recording that belongs in your system; we help by answering the questionnaire, but the judgement is yours.

What we do here, and what we do not

What we do. Set up and run the technical controls above, and produce the evidence you use to demonstrate them: which rights exist, what is logged and for how long, when a restore was last tested, how quickly patching happens. That evidence is half the work of an audit and it is precisely the part nobody can invent afterwards.

What we do not do. We certify nobody and we are not auditors. We do not set your scope, we do not approve your statement of applicability and we do not issue a declaration that you meet the standard. That is the work of an accredited certification body, and it belongs there: a party that builds your environment and then assesses itself is exactly what the standard exists to prevent.

Frequently asked

Questions we get about this

The four that come back most often.

Can you certify us for ISO 27001?

No. Certification is done by an accredited certification body and by nobody else; we are not one. We set up the technical controls and deliver the evidence you use to demonstrate them. We are ISO 27001, ISO 9001 and ISO 14001 certified ourselves, but a certificate is not something you can inherit from us.

Is this checklist enough to pass the audit?

No, and deliberately so. It covers the technological controls from Annex A, the side that comes out of your IT. The scope, the risk assessment, the statement of applicability, the policy and the internal audit stay with you, and that is where an auditor starts.

Our client asks whether we have ISO 27001. What do we send?

If you do not have it, do not send what you do not have. What does work is showing which controls are in place and what evidence goes with them. In most questionnaires that is enough, because the question is rarely really about the certificate and almost always about the controls behind it.

We are twenty people. Is this feasible?

The standard scales with the scope, not with headcount. What does not scale is the paperwork around it, and that is where small organisations get stuck. Start from the evidence your IT already produces; that helps more than a template.

Related services

Further reading

The controls from this checklist, each worked out separately.

Shall we look at what you already have?

Tell us which standard is in play or which questionnaire came in. We walk through the technical side, say what you can already demonstrate today and what is missing.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. See our privacy policy.

Request a quote Call