BG Beter Geregeld ICT
Compliance · 2 min leestijd · 19 October 2025

ISO 27001 pre-audit checklist: 2 weeks before Stage 2

Stage 2 is two weeks away. This 22-point checklist covers everything auditors typically ask for — if even one box is missing, fix it now.

Two weeks before Stage 2. This is no longer the time to build anything substantial — it's time to make sure everything is in order. Work through these 22 points.

\n\n

Documentation

\n
    \n
  1. Security policy is up to date, an owner is named, and an annual review date is scheduled.
  2. \n
  3. Statement of Applicability is current (all Annex A controls: implemented / N/A + reason).
  4. \n
  5. All 8–12 policies are on the correct version number, with a visible changelog.
  6. \n
  7. Risk register review date falls within the last quarter.
  8. \n
  9. Asset inventory is current (including the SaaS inventory).
  10. \n
\n\n

Operational evidence

\n
    \n
  1. Most recent access review completed, with a PDF report including decisions and sign-offs.
  2. \n
  3. Privileged access inventory is current, with the latest review within the past 3 months.
  4. \n
  5. Last 2 offboardings fully documented.
  6. \n
  7. Onboarding process for at least 1 recent hire complete.
  8. \n
  9. Backup test performed, with evidence of a successful restore.
  10. \n
  11. Incident register for the last quarter present (even "nothing happened" must be logged).
  12. \n
\n\n

Governance

\n
    \n
  1. Most recent management review within the last 12 months, with minutes available.
  2. \n
  3. Internal audit completed, report available, and findings closed or included in an action plan.
  4. \n
  5. Training log: everyone has completed security awareness training this year.
  6. \n
  7. Roles and responsibilities document in place (CISO role filled, even if that's the director themselves).
  8. \n
\n\n

Technical controls

\n
    \n
  1. MFA enforced on critical systems (M365 admin, accounting, cloud infrastructure).
  2. \n
  3. Password policy enforced (at minimum: length requirements + common password blocking).
  4. \n
  5. Patches: last quarter's OS/browser patches applied to > 95% of devices.
  6. \n
  7. Anti-malware installed on all endpoints.
  8. \n
  9. Disk encryption enabled on all company laptops.
  10. \n
\n\n

Contracts

\n
    \n
  1. Data processing agreements in place with key suppliers (see processor register).
  2. \n
  3. Confidentiality and security clauses included in employment contracts.
  4. \n
\n\n

Everything ticked off → you're ready for Stage 2.

Onderwerpen

#checklist #audit #iso-27001

Volledige gids: ISO 27001 para pymes sin gastar €50k en consultores

Dit artikel is onderdeel van onze uitgebreide Compliance-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →