ISO 27001:2022 Mandatory Documents for Certification

Here are the mandatory documents  required by ISO/IEC 27001:2022 (the 2022 revision) for implementing and certifying an ISMS. This is a summary; depending on your organization’s context, some items may or may not apply (especially Annex A controls are only mandatory if relevant).


Mandatory Documents / Documented Information (Core Requirements)

These are explicitly required by clauses in ISO 27001:2022

Document / InformationISO 27001:2022 ClausePurpose / Why It’s Required
ISMS Scope Statement4.3To define the boundaries and applicability of the ISMS.
Information Security Policy5.2Top management commitment; sets direction and principles for ISMS.
Risk Assessment Methodology6.1.2How risks are identified, assessed; scales etc.
Risk Treatment Process / Methodology6.1.3To define how identified risks will be treated.
Statement of Applicability (SoA)6.1.3(d)Lists which Annex A controls are applicable / not, and why.
Information Security Objectives6.2Specific measurable objectives aligned to policy.
Evidence of Competence7.2Records of skills, experience, qualifications of persons who influence ISMS.
Operational Planning and Control8.1Documented information to ensure operations are planned, and controlled.
Risk Assessment & Risk Treatment Reports / Results8.2 & 8.3Show outcomes of risk assessments and treatments.
Monitoring and Measurement Results9.1Metrics, measurements to show performance.
Internal Audit Program & Results9.2Schedule, reports of internal audits.
Management Review Results9.3Records from top management reviewing the ISMS.
Records of Nonconformities and Corrective Actions10.1Showing that issues are identified, corrective actions taken.)

This website uses cookies. By continuing to use this site, you accept our use of cookies.  Learn more