
By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · August 2026 · 10 min read
Your buyer's security questionnaire came back with one line highlighted. Provide your ISO 27001 certificate, or your timeline to get one. So you search for an ISO 27001 checklist, and the first page of results hands you a grid of controls to tick off.
That grid is the wrong place to start. It is also the single most common reason a first attempt stalls six months in, with a folder full of policies and nothing an auditor can test.
Here is the part people get wrong. ISO 27001 is not a control checklist. It is a management system standard. ISO describes it on its own catalogue page as defining the requirements an information security management system must meet, and as guidance for establishing, implementing, maintaining and continually improving that system. The controls come later, and which ones apply to you is an output of your own risk work, not an input you copy from somebody else's spreadsheet.
This post gives you the checklist in the order the standard actually works. Management system first, controls second, evidence throughout.
Check this before anything else. The current edition is ISO/IEC 27001:2022, published in October 2022 as the third edition. ISO's catalogue entry lists the 2013 edition and its two corrigenda with the status Withdrawn, and the foreword of the 2022 text states that the third edition cancels and replaces the second edition, ISO/IEC 27001:2013, which has been technically revised.
Two practical consequences for a Canadian company starting now.
If you inherited a policy pack, a template set, or a consultant's workbook built for the 2013 structure, it is aligned to a withdrawn edition. The foreword says the main change is that the text has been aligned with the harmonized structure for management system standards and with ISO/IEC 27002:2022. A 2013 era control mapping will not line up cleanly.
Second, there is an amendment most checklists still do not mention. ISO's catalogue page for the standard lists ISO/IEC 27001:2022/Amd 1:2024, titled Climate action changes. It is a published amendment to the current edition. If your documentation set was assembled before you knew that existed, it is worth a look now rather than during a certification audit.
Worth setting expectations early, because this catches teams out. ISO publishes the informative sections of its standards for free on its Online Browsing Platform. Open the ISO/IEC 27001:2022 entry there and you can read the foreword, the introduction, the scope, the normative references, and the terms and definitions. Then the platform says plainly that only informative sections are publicly available, and that viewing the full content requires purchasing the standard.
So the normative clauses and Annex A itself are behind a purchase. Any free checklist you find online, including this one, is someone's reading of the standard rather than the standard. Budget for the document. A certification body will expect you to be working from the real text.
This is the part the control grids skip, and it is the part that decides whether the rest holds together. The clause titles below are as published in ISO's own contents listing for ISO/IEC 27001:2022.
Clause 4, context of the organization. Four things to produce. Understanding the organization and its context. Understanding the needs and expectations of interested parties. Determining the scope of the information security management system. And the information security management system itself.
Scope is where most Canadian SMBs get into trouble, in one of two directions. Draw it too wide and you have committed to evidencing every system you own. Draw it too narrow and your buyer reads the certificate, sees that the product they are buying sits outside the scope statement, and asks why. Write the scope for the thing the customer is actually buying.
Clause 5, leadership. Leadership and commitment. Policy. Organizational roles, responsibilities and authorities. Auditors test this by talking to people. If your CEO cannot describe the information security policy in their own words, that is a finding, and no document fixes it.
Clause 6, planning. Actions to address risks and opportunities. Information security objectives and planning to achieve them. This is the engine of the whole standard. A real risk assessment, done on your actual systems, with decisions recorded and owned. A good auditor pushes hard here, because a rubber stamped risk assessment falls apart in the room and everything downstream of it inherits the weakness.
Clause 7, support. Resources. Competence. Awareness. Communication. Documented information. Competence and awareness are separate requirements and they are evidenced differently. Competence is about the people running the system being capable of running it. Awareness is about everyone else knowing what is expected of them.
Clause 8, operation. Operational planning and control. The system has to actually run, on a schedule, with records that show it ran.
Read that list again and notice what is not on it. There is no control grid. Five clauses in, and you have not yet chosen a single technical control.
Now the controls. ISO/IEC 27002:2022 is the companion standard that describes them, and its contents listing shows a clause 4.2 titled Themes and attributes, then the control clauses themselves. The first control clause is clause 5, organizational controls.
Here are the organizational controls as ISO titles them, from 5.1 through 5.15: policies for information security, information security roles and responsibilities, segregation of duties, management responsibilities, contact with authorities, contact with special interest groups, threat intelligence, information security in project management, inventory of information and other associated assets, acceptable use of information and other associated assets, return of assets, classification of information, labelling of information, information transfer, and access control.
Run your eye down that list and mark each one honestly as in place, partly in place, or absent. Not whether you have a policy about it. Whether you could show a stranger the evidence this week.
That distinction is the whole game. Contact with authorities is not a paragraph in a policy, it is knowing who you call and being able to show you know. Inventory of information and other associated assets is not a spreadsheet somebody made once, it is a list that matches what is actually running.
The remaining control clauses cover people, physical and technological topics, and they sit behind the same purchase wall described above. Work from the real text for those rather than a summary.
ISO 27001 is an international standard and it says nothing about Canadian law. That does not make Canadian law optional, and this is where an imported template set leaves you exposed.
The Personal Information Protection and Electronic Documents Act applies, in the Office of the Privacy Commissioner's own words, to private sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. The OPC sets out ten fair information principles, and two of them map directly onto work you are already doing for ISO 27001. Accountability is the first principle. Safeguards is the seventh.
Practically, that means the risk assessment you build for clause 6 should already be reasoning about personal information, not just about systems and uptime. If your ISO scope covers a product that handles customer personal information, your safeguards evidence is doing double duty. Build it once and point both ways.
There is a second Canadian reference worth having open. The Canadian Centre for Cyber Security publishes Baseline Cyber Security Controls for Small and Medium Organizations, written for Canadian organizations that want recommendations to improve resiliency, and built to apply what the Centre calls the 80/20 rule. It names thirteen control areas, including incident response planning, automatic patching, security software, secure device configuration, strong user authentication, employee awareness training, backup and data encryption, and access control and authorization. The Centre's own guidance points organizations that want something more comprehensive toward ISO/IEC 27001.
That gives you a sensible sequence. If you are early, work the Cyber Centre baseline first. It is free, it is Canadian, and most of what you build there becomes evidence you reuse later.
After enough of these, the pattern is consistent, and it is almost never the standard itself being too hard to understand.
The gap is evidence. Teams can describe their controls perfectly well in conversation. What they cannot do is produce, on demand, the record showing the control ran last quarter, who reviewed it, and what happened when it failed. Access reviews that everyone agrees happen, with no artifact. A risk assessment updated once, eighteen months ago. Onboarding checklists completed in a chat thread nobody can search.
An audit is not a test of whether you are secure. It is a test of whether you can prove what you claim, repeatedly, from records that existed before anyone asked. That is a different muscle, and it is the one worth building first.
The same evidence carries further than most teams expect. Much of what satisfies ISO 27001 also supports a SOC 2 report, which is why running one system beats running two projects. If you are weighing the two, we wrote a plain English comparison of the SOC report types and a walkthrough of what ISO 27001 involves for a Canadian company. If your product has anything AI facing in it, the governance questions arriving in procurement questionnaires now are covered on our sister brand at SecuritAI.
We are not an auditor and we do not issue certificates. A certification body does that, and it should stay that way. Any vendor blurring that line is telling you something about how they work.
What we build is the software that gets your evidence in order long before anyone shows up to test it. Scope, risk register, control ownership, and the records that prove the system ran. Our ISO 27001 readiness tooling is built around Canadian requirements rather than translated from a US template, and the resource library has the checklists and templates free to use whether or not you ever talk to us.
If you want to see it against your own environment rather than a demo dataset, book a walkthrough with our team.
Is there an official ISO 27001 checklist?
No. ISO publishes the standard, not a checklist. Any checklist, this one included, is somebody's reading of the requirements. ISO makes the informative sections free on its Online Browsing Platform and states that the full content requires purchase, so treat a free checklist as a map and the purchased standard as the territory.
Which edition should we be working to in 2026?
ISO/IEC 27001:2022, the third edition, published October 2022. ISO's catalogue lists the 2013 edition as withdrawn. Also check ISO/IEC 27001:2022/Amd 1:2024, the climate action changes amendment, which is listed on the same catalogue page.
Do we need ISO 27001 or SOC 2 for Canadian buyers?
It usually follows the buyer. European and UK buyers ask for the ISO certificate more often. North American buyers ask for a SOC 2 report more often. The underlying evidence overlaps heavily, so the sequence matters more than the choice. Build one system and produce whichever artifact the deal requires.
Does ISO 27001 make us PIPEDA compliant?
No. They are different instruments and one does not substitute for the other. PIPEDA applies to private sector organizations collecting, using or disclosing personal information in the course of commercial activity, and it sets out ten fair information principles including accountability and safeguards. ISO 27001 gives you a management system that produces much of the evidence those principles require, which is a considerable help, but the legal obligation is its own thing.
How do we know if we are ready to call a certification body?
One test. Pick three controls at random and ask someone to produce the evidence that each ran in the last quarter, without preparing first. If that takes more than a few minutes per control, you are not ready, and the fix is record keeping rather than more policy writing.
SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.
Start Free →