Getting Started with ISO 27001
ISO 27001 is the international standard for Information Security Management Systems (ISMS). Certification demonstrates to customers, partners, and regulators that your organization manages information security systematically. Matproof pre-loads 93 controls based on ISO 27001:2022 Annex A, mapped to your ISMS policies, risk register, and evidence library. This guide walks you through implementation in the recommended order to reach audit-readiness.To activate ISO 27001, go to Settings → Frameworks → ISO 27001 and click Activate. Your Annex A control set will be pre-populated immediately.
What ISO 27001 Requires at a Glance
Am I in Scope?
ISO 27001 is voluntary but effectively mandatory if:- You sell to enterprise customers who require it in their vendor assessments
- You process personal data or sensitive customer information
- You operate in industries with regulatory overlap (finance, healthcare, critical infrastructure)
- You need a recognized security credential to enter new markets
The 4 Annex A Themes in Matproof
Organisational Controls
37 controls — Policies, roles, asset management, supplier relationshipsStart here. These establish the governance foundation all other controls depend on.
People Controls
8 controls — Hiring, training, offboarding, disciplinary processManaged in the People module. Link employment records and training completions as evidence.
Physical Controls
14 controls — Physical security, clear desk, secure areasUpload site assessments and physical security documentation as evidence.
Technological Controls
34 controls — Access control, cryptography, logging, malware protectionAutomate evidence collection by connecting your cloud and SaaS integrations.
Recommended 12-Week Implementation Plan
ISO 27001 certification requires a Stage 1 (documentation review) and Stage 2 (implementation audit) audit. This plan prepares you for certification over approximately 16-20 weeks, with Stage 1 readiness by week 12.The Three Things Teams Get Wrong
1. Scope creep
Starting with “the whole company” creates a compliance project that never ends. Pick the narrowest defensible scope — a product, a team, a data type — certify that, then expand.2. The SOA is an afterthought
The Statement of Applicability is a primary deliverable, not an export at the end. Build it as you work through controls. Auditors read it before they look at anything else.3. No internal audit before the external one
Stage 2 auditors will raise nonconformities for gaps they find. If you walk in with zero corrective actions documented, they conclude you haven’t been running your ISMS — because every ISMS finds issues. Run a real internal audit and close the findings.Certification Timeline Reference
What Good Looks Like
Before submitting to your certification body:- ISMS scope statement documented and approved
- Risk assessment complete with all risks above threshold assigned a treatment plan
- All 5 foundational policies published, owned, and acknowledged
- SOA complete with justifications for all Not Applicable controls
- At least one internal audit completed with findings documented
- All corrective actions from the internal audit closed with evidence
- Management review documented since ISMS establishment
Next Steps
- Risk Management — ISO 27001-aligned risk assessment and treatment workflow
- Policy Management — generating, customizing, and distributing your policy library
- Audit Programs — running internal audits and producing the management review report
- Corrective Actions — Clause 10.2 compliance through tracked remediation