Join our Newsletter — 33% off our NHI Course

How should organisations prepare for ISO 27001 certification when they are starting from scratch?

Start by mapping your information assets, understanding the risks they face, and deciding which controls already exist versus which gaps must be closed. Then secure management buy-in, because leadership support, budget, and clear scope are essential before an auditor ever reviews evidence. Build the ISMS as an operating programme, not a paper exercise, so documentation, ownership, and remediation work stay aligned.

Start with scope, assets, and risk before you write policies

iso 27001 readiness starts with knowing what the ISMS will actually cover. If the organisation cannot name its critical information assets, owners, and major risk themes, it will struggle to define controls, produce evidence, or explain scope to an auditor. The first milestone is a defensible boundary, not a document set.

For teams building from zero, the practical sequence is: identify the business services and data that matter most, map the main risks to confidentiality, integrity, and availability, then compare those risks with the controls already in place. That gap view becomes the backbone for the Statement of Applicability and the implementation plan.

Well-run certification projects also treat documentation as a decision record, not a paperwork burden. Procedures, policies, and registers should show who owns each control, how it is operated, and what evidence will prove it works in practice.

Turn leadership support into a funded programme

Most first-time certification efforts fail when they are framed as a compliance task owned by security alone. ISO 27001 requires cross-functional cooperation, so management support must translate into scope approval, budget, named owners, and authority to remediate gaps across IT, operations, HR, legal, and procurement.

ISO/IEC 27001:2022 Information Security Management is built around an information security management system, which means the organisation needs repeatable governance, not just control deployment. In practice, that means assigning accountability for risk treatment, internal audit, and management review before the certification clock starts.

Use the programme structure to prevent last-minute surprises. A realistic plan separates policy drafting, control implementation, evidence collection, internal audit, and remediation, because auditors will look for consistency between what the organisation says, what it does, and what it can prove.

Build evidence, operations, and remediation together

Starting from scratch, the main mistake is to create policies first and hope operations will catch up later. Certification readiness is strongest when controls are embedded into daily work: joiner-mover-leaver handling, access reviews, incident handling, supplier oversight, logging, change management, and security awareness all need operating owners and measurable outputs.

That is where implementation guidance matters. ISO/IEC 27002:2022 Information Security Controls helps teams translate the ISMS into concrete control choices and operating practices, while the right internal references help teams sustain lifecycle discipline and visibility. NHIMG’s Ultimate Guide to NHIs is especially useful where organisations need to understand identity governance, rotation, offboarding, and visibility for machine accounts, service accounts, and API keys.

If you want one useful operational test, ask whether every major control has a named owner, a current procedure, and an artefact that would survive an auditor interview. If the answer is no, the gap is not theoretical, it is a readiness issue.

Risk and Threat Considerations

Certification programmes that start without scope discipline or operational ownership often fail in a predictable way: evidence exists in fragments, controls are only partly implemented, and remediation work arrives too late to be credible. The risk is not just missing the certificate, but building an ISMS that cannot sustain itself after the audit cycle.

Failure mechanism: Teams document controls after the fact, leave ownership unclear, or underestimate the time needed to close gaps, which creates inconsistent evidence and weak control operation across departments.

Impact: Auditors will challenge scope, control design, and operating effectiveness, and the organisation may need to rework the programme under time pressure, with increased cost and delayed certification.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, and ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 42001:2023 AI management system governance Organisational governance discipline is central to building a repeatable management system.
Recommendation — Establish governance, accountability, and review cadence before expanding control implementation.
NIST CSF 2.0 GV.RM — Risk Management Strategy Preparing for certification starts with risk-based scope and treatment decisions.
GV.OV — Oversight Leadership buy-in and programme oversight are essential to ISMS execution.
Recommendation — Define a risk-based scope and treatment approach before implementing controls. Assign executive oversight and clear control ownership for the certification programme.
CIS Controls v8 CIS 4 — Secure Configuration of Enterprise Assets and Software From-scratch readiness depends on operationalising baseline controls and evidence.
CIS 6 — Access Control Management Access governance is a common control area auditors examine in an ISMS.
Recommendation — Baseline and evidence your control state before the audit window opens. Review and document access governance as part of your core control set.
NIST SP 800-63 IAL — Identity Assurance Level Certification programmes often depend on trustworthy identity and access processes.
AAL — Authenticator Assurance Level Authentication controls must be defined and evidenced in operating procedures.
FAL — Federation Assurance Level Federated access and trust relationships can materially affect audit scope and evidence.
Recommendation — Verify identity processes are documented and consistently operated where access controls depend on them. Document authentication requirements and operating evidence for systems in scope. Map federated access paths and retain evidence for trust and assurance decisions.
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Management ISMS readiness often depends on governing machine credentials and secret handling.
NHI-02 — Identity Lifecycle and Offboarding Lifecycle governance is critical to proving access removal and account ownership.
Recommendation — Inventory and control secret handling where machine and application access is in scope. Define offboarding and rotation processes for non-human identities in scope.

Practitioner Guidance

What to prioritise: Lock scope, risk method, and executive ownership before expanding control detail. If those three are unstable, every later workstream will drift and the audit trail will be harder to defend.

What to verify: Confirm that each control in the Statement of Applicability has a real owner, a current operating process, and an evidence source that is produced routinely rather than assembled ad hoc for the audit.

Practitioner takeaway: The fastest path to ISO 27001 readiness is not more documentation, it is a governed operating model where risk, ownership, and evidence are aligned from the beginning.