ISO 27001 pre-audit checklist: 2 weeks before Stage 2
Stage 2 is two weeks away. This 22-point checklist covers everything auditors typically ask for — if even one box is missing, fix it now.
Two weeks before Stage 2. This is no longer the time to build anything substantial — it's time to make sure everything is in order. Work through these 22 points.
\n\nDocumentation
\n- \n
- Security policy is up to date, an owner is named, and an annual review date is scheduled. \n
- Statement of Applicability is current (all Annex A controls: implemented / N/A + reason). \n
- All 8–12 policies are on the correct version number, with a visible changelog. \n
- Risk register review date falls within the last quarter. \n
- Asset inventory is current (including the SaaS inventory). \n
Operational evidence
\n- \n
- Most recent access review completed, with a PDF report including decisions and sign-offs. \n
- Privileged access inventory is current, with the latest review within the past 3 months. \n
- Last 2 offboardings fully documented. \n
- Onboarding process for at least 1 recent hire complete. \n
- Backup test performed, with evidence of a successful restore. \n
- Incident register for the last quarter present (even "nothing happened" must be logged). \n
Governance
\n- \n
- Most recent management review within the last 12 months, with minutes available. \n
- Internal audit completed, report available, and findings closed or included in an action plan. \n
- Training log: everyone has completed security awareness training this year. \n
- Roles and responsibilities document in place (CISO role filled, even if that's the director themselves). \n
Technical controls
\n- \n
- MFA enforced on critical systems (M365 admin, accounting, cloud infrastructure). \n
- Password policy enforced (at minimum: length requirements + common password blocking). \n
- Patches: last quarter's OS/browser patches applied to > 95% of devices. \n
- Anti-malware installed on all endpoints. \n
- Disk encryption enabled on all company laptops. \n
Contracts
\n- \n
- Data processing agreements in place with key suppliers (see processor register). \n
- Confidentiality and security clauses included in employment contracts. \n
Everything ticked off → you're ready for Stage 2.
Volledige gids: ISO 27001 para pymes sin gastar €50k en consultores
Dit artikel is onderdeel van onze uitgebreide Compliance-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →