Anacruses Associates Ltd

Free Resource

ISO 27001 Certification Checklist for UK SMEs

Everything your business needs to verify before the Stage 2 certification audit — written by a CQI/IRCA certified Lead Auditor with 20+ years of ISO 27001 experience.

What the checklist covers

Scope and context

Confirm your ISMS scope is documented correctly and matches operational reality — including remote workers, cloud systems, and outsourced functions.

Risk assessment and Statement of Applicability

The two areas most commonly responsible for Stage 2 failures. Every required element is listed so nothing is missed.

All 93 Annex A controls

Organisational, People, Physical, and Technological controls — including the 11 new controls added in ISO 27001:2022.

Internal audit requirements

What a rigorous internal audit looks like and what certification auditors check in your audit records.

The five most common Stage 2 failure reasons

From 20+ years of conducting and supporting ISO 27001 audits — the specific gaps that cause businesses to fail or receive major nonconformities.

Already read our ISO 27001 guide? This checklist is the practical companion — use it to verify your readiness at each stage. Read the complete guide →

Get the free checklist

Enter your details below. The PDF will be emailed to you immediately.

By submitting you agree to receive emails from Anacruses Associates Ltd. Your data is held securely and never shared with third parties. You can unsubscribe at any time.

Rob Pragnell

Rob Pragnell

CQI/IRCA Lead Auditor · 20+ years

CQI & TRECCERT certified Lead Auditor across ISO 9001, 14001, 27001, 45001 & 42001. Every Anacruses client works directly with Rob — not a junior consultant.

Full biography →