Project plan for an ISO 27001 certification
ISO 27001 certification is not an IT project but a management system: scope, risk assessment, Annex A controls, internal audit and management review have to fit together. This plan shows the path to the certification audit.
No sign-up · opens instantly · 34 Weeks · 10 Phases · 67 Tasks · Budget approx. €216,350
This is how the plan looks in PathHub — click through the tabs or tick off tasks.
ISO/IEC 27001:2022 ISMS Implementation and Certification
This project will establish and operationalize an organization-wide Information Security Management System for a 120-person software company. It will define the ISMS scope, governance, risk treatment, documentation, and operational controls needed to meet ISO/IEC 27001:2022 requirements. The work also includes training, evidence collection, internal audit, management review, and support through certification audits. The goal is to achieve certification readiness within the nine-month delivery window while embedding sustainable business-as-usual ownership.
Phases
Phase 1: Mobilization and Certification Planning
Establish executive sponsorship, project governance, certification assumptions, and delivery capacity. This phase creates the decision-making structure needed to meet the nine-month certification deadline.
Phase 2: ISMS Scope, Context and Governance
Define the formal ISMS context, scope, governance model, and policy direction. The outputs establish the boundaries and accountability model that will be assessed during certification.
Phase 3: Asset, Information and Dependency Inventory
Build a validated inventory of information, assets, services, applications, infrastructure, suppliers, and dependencies within the approved ISMS scope. Each critical asset and process will have an accountable owner and classification.
Phase 4: Gap Assessment and Remediation Roadmap
Compare current practices and available evidence with ISO/IEC 27001:2022 requirements and relevant Annex A controls. The resulting prioritized roadmap will align remediation work, budget, owners, and deadlines with the certification plan.
Phase 5: Risk Assessment, Treatment Plan and Statement of Applicability
Establish the formal information-security risk register, select risk treatments, and document the applicability of Annex A controls. This phase provides the evidence-based foundation for the ISMS and certification audit.
Phase 6: ISMS Documentation and Process Design
Convert the approved risk treatments and control decisions into an operational ISMS documentation set. Processes will define who performs each control, how often it operates, what records are retained, and how exceptions are handled.
Phase 7: Technical and Operational Control Implementation
Implement and test the priority technical and operational controls identified in the remediation roadmap. The work focuses on cloud security, identity, software development, monitoring, resilience, suppliers, and independent security validation.
Phase 8: Training, Awareness and Evidence Operation
Operate the ISMS controls long enough to produce reliable evidence and establish consistent employee behavior. Control owners will demonstrate repeatable execution, while gaps are corrected before the internal audit.
Phase 9: Internal Audit and Management Review
Independently test ISMS conformity and control effectiveness before certification. Management will review audit results, performance data, risks, and resources before authorizing progression to the certification audit.
Phase 10: Certification Audit, Corrective Actions and Handover
Support the certification body through Stage 1 and Stage 2, respond to findings, and transition the operating ISMS to permanent ownership. The phase concludes with submitted corrective-action evidence and a business-as-usual improvement plan.
Timeline
Budget
| Item | Qty | Unit price | Total |
|---|---|---|---|
| External ISO 27001 implementation consultant | 32 Person days | €1,200 | €38,400 |
| Independent internal audit specialist | 10 Person days | €1,000 | €10,000 |
| ISO 27001 certification body Stage 1 and Stage 2 audits | 1 Flat rate | €22,000 | €22,000 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Cloud and identity security remediation engineer | 25 Person days | €900 | €22,500 |
| DevSecOps and secure-development remediation engineer | 20 Person days | €850 | €17,000 |
| Backup, logging and secure-configuration implementation | 1 Flat rate | €8,000 | €8,000 |
| External penetration test of applications and cloud infrastructure | 1 Flat rate | €12,000 | €12,000 |
| Penetration-test remediation validation and retesting | 1 Flat rate | €4,000 | €4,000 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| GRC and evidence-management platform | 9 Person days | €1,200 | €10,800 |
| Security awareness and training platform | 9 Person days | €500 | €4,500 |
| Vulnerability scanning and dependency-monitoring subscription | 6 Person days | €900 | €5,400 |
| Cloud logging and SIEM service uplift | 9 Person days | €700 | €6,300 |
| Access governance and access-review tooling | 9 Person days | €350 | €3,150 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Organization-wide security awareness workshops | 16 Person days | €250 | €4,000 |
| Control-owner and evidence-operation workshops | 12 Person days | €250 | €3,000 |
| GDPR, privacy and contractual alignment review | 8 Person days | €1,100 | €8,800 |
| Supplier security assessment and contractual assurance support | 10 Person days | €850 | €8,500 |
| Training materials, communications and completion tracking setup | 1 Flat rate | €3,000 | €3,000 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Internal ISMS Manager / CISO allocation | 20 Person days | €700 | €14,000 |
| Control owners and business process leads backfill | 20 Person days | €550 | €11,000 |
Risks
Insufficient Executive Sponsorship and Control-Owner Capacity
If the CEO, CTO, and functional leaders have not approved the ISMS RACI, allocated named control owners, and reserved engineering, IT, HR, legal, and operations capacity by the end of Week 2, critical decisions and remediation work may be delayed throughout Phases 2–8.
Uncontrolled Expansion of the Certification Scope
If products, cloud environments, customer services, regions, or suppliers are added after the scope is approved in Week 5, the company may need to repeat inventory, risk assessment, control design, and evidence work, threatening the nine-month certification deadline.
Incomplete Asset, Information, and Dependency Inventory
If critical systems, repositories, SaaS platforms, data stores, shadow IT, cloud accounts, or information owners remain unidentified by the end of Week 8, material risks may be omitted from the risk assessment and exposed during the certification audit.
Delayed Risk Assessment or Statement of Applicability
If the risk register, treatment plan, residual-risk acceptances, or Statement of Applicability are not approved by Week 15, documentation and technical implementation may proceed without an agreed control basis, causing rework and audit objections.
Cloud, Identity, and Secure-Development Control Gaps
If critical findings involving excessive cloud privileges, weak joiner-mover-leaver controls, unmanaged secrets, insufficient logging, vulnerable dependencies, insecure CI/CD pipelines, or inadequate backup protection remain open at the end of Week 23, certification-critical controls may not be demonstrably effective.
Controls Documented but Not Operating Consistently
If access reviews, vulnerability remediation, incident records, backup tests, supplier reviews, change approvals, or security monitoring activities have not operated for sufficient cycles by Week 27, the company may be unable to demonstrate control effectiveness even where procedures exist.
Certification-Body Availability or Significant Audit Findings
If a certification body is not provisionally booked by Week 2, Stage 1 identifies major scope or documentation deficiencies, or Stage 2 findings remain open after Week 32, there may be insufficient time to achieve certification within the nine-month deadline.
Supplier, Customer-Contract, and Privacy Gaps
If critical cloud, SaaS, hosting, development, or support suppliers have not been assessed or lack appropriate security commitments by Week 19, or if customer data-processing and breach obligations conflict with ISMS procedures, legal and audit findings may remain unresolved.
Employee Adoption and Personnel-Control Failures
If mandatory security training completion is below the agreed threshold, onboarding/offboarding evidence is incomplete, or employees do not report incidents during the tabletop exercise by Week 27, personnel and incident-management controls may fail during audit testing.
Remediation Budget and Internal-Resource Overrun
If technical remediation, tooling, penetration testing, or backfill forecasts exceed the approved budget by more than 10% by Week 19, the company may defer certification-critical controls or reduce evidence and testing quality.
Stakeholders
Executive Sponsor / CEO
Provides funding, resolves cross-functional conflicts, and approves risk acceptance and ISMS direction
ISMS Manager or CISO
Owns implementation, risk methodology, control coordination, evidence model, and certification interface
CTO
Decides on technology priorities, engineering capacity, architecture changes, and acceptance of technical risks
IT, Cloud and Platform Operations Lead
Owns infrastructure, identity and access management, logging, backup, vulnerability management, and operational evidence
Software Engineering and DevSecOps Lead
Implements secure development, code review, dependency management, release, and vulnerability remediation controls
Data Protection Officer / Legal Counsel
Aligns the ISMS with GDPR, contracts, data-processing obligations, retention, and breach requirements
HR / People Operations Lead
Owns onboarding, offboarding, role changes, security responsibilities, training records, and personnel controls
Procurement and Vendor Management Lead
Establishes supplier due diligence, security clauses, monitoring, and third-party risk records
Product, Customer Operations and Business Process Owners
Identify critical services and information, validate business risks, and own control execution within their areas
Internal Audit or Quality Lead
Provides independence for the internal audit, tests control effectiveness, and verifies corrective actions
External ISO 27001 Consultant
Supplies methodology, implementation guidance, readiness reviews, and remediation support without replacing internal control ownership
Certification Body and Lead Auditor
Confirms audit requirements, performs Stage 1 and Stage 2 assessments, and determines certification readiness
Compliance
Establish and maintain the ISO/IEC 27001:2022 ISMS, including organizational context, interested parties, defined scope, leadership responsibilities, security objectives, documented information, and continual improvement under Clauses 4–10
Perform a documented information-security risk assessment, create and maintain a risk treatment plan, obtain residual-risk approvals, and approve the Statement of Applicability
Implement and operate the controls selected in the Statement of Applicability, including access control, cloud security, secure software development, vulnerability management, logging, backup, incident management, physical/endpoint protection, and supplier security
Maintain reliable evidence of control operation, including access reviews, training, vulnerability remediation, changes, incidents, backup tests, supplier assessments, risk decisions, and corrective actions
Conduct an independent internal audit, address nonconformities, complete management review, and verify corrective actions before certification
Fulfil binding customer, supplier, data-processing, confidentiality, security, breach-notification, audit-right, and data-location obligations relevant to the ISMS scope
Maintain an approved security policy framework, role-based awareness and competence program, incident-response exercises, business-continuity and backup testing, and periodic control-performance reviews
Milestones
- Week 2
Approved ISMS charter, named workstream owners, committed internal capacity, and provisionally booked certification audit dates
Depends on: Executive sponsorship and project governance established - Week 5
Approved ISMS scope statement, context and interested-party register, security objectives, governance RACI, and obligations register
Depends on: Scope and governance definition completed - Week 8
Signed-off information and asset inventory with owners, classifications, criticality ratings, dependencies, and identified inventory gaps
Depends on: Asset and dependency discovery completed - Week 11
Approved gap assessment and funded remediation roadmap with named owners and deadlines for all certification-critical gaps
Depends on: Current-state assessment completed - Week 15
Approved risk register, risk treatment plan, residual-risk acceptances, and Statement of Applicability
Depends on: Risk assessment and control selection completed - Week 19
Approved ISMS policy and procedure set with control owners, operating frequencies, evidence requirements, and exception workflows
Depends on: Documentation and process design completed - Week 23
Priority control implementations completed, high-risk technical findings remediated or formally accepted, and control test evidence available
Depends on: Technical and operational implementation completed - Week 27
Required personnel training completed, priority controls operated with evidence, tabletop exercise completed, and evidence gaps closed or tracked
Depends on: Training and evidence operation completed - Week 30
Completed independent internal-audit report, corrective-action plan, signed management-review minutes, and formal certification-readiness decision
Depends on: Internal audit and management review completed - Week 34
Stage 1 and Stage 2 audits completed, certification findings addressed with submitted evidence, and ongoing ISMS ownership and improvement activities formally handed over
Depends on: Certification audit and corrective actions completed
How this plan was created
This plan was created by PathHub AI from a single description: “Prepare a 120-person software company for ISO 27001 certification within 9 months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.
Obligations with lead time: what many think of too late
These obligations are typically triggered by an ISO 27001 certification (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.
Rule & evidence
Why: Accredited certification bodies are often booked months ahead; stage 1 checks readiness, stage 2 effectiveness.
- Information security management system (ISMS) defined
- Risk assessment and treatment documented
- Statement of Applicability (SoA) with Annex A controls
- Internal audit and management review annually
If breached: Voluntary standard but de facto mandatory for enterprise/government clients. Loss terminates business relationships.
Rule & evidence
Why: Without a documented internal audit and management review the system is not ready for certification; findings need time to be corrected.
- Information security management system (ISMS) defined
- Risk assessment and treatment documented
- Statement of Applicability (SoA) with Annex A controls
- Internal audit and management review annually
If breached: Voluntary standard but de facto mandatory for enterprise/government clients. Loss terminates business relationships.
Frequently asked questions
More project plan examples
Adapt this plan to your company
Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.
Open plan →