CloudSignLab

Help centerYour security program

Prepare for ISO 27001 certification

Use the certification kit: readiness per clause, the management system, objectives, management reviews and the audit pack for the auditor.

Updated September 30, 2026

In this section: Your security program

The ISO 27001 certification kit brings together everything a certification auditor asks for. Open Frameworks and click Open the kit.

Readiness

The Readiness tab checks your own records, clause by clause, and marks each step Done, To do or Needs attention. For example: is the information security policy published, does every open risk have a treatment plan, was there an internal audit and a management review in the last 12 months? Click Open next to a step to go where you fix it. The percentage at the top is the share of steps done. The certification body decides in the end; the list shows what auditors usually ask to see.

Management system

The Management system tab holds what the standard asks you to write down:

  • 4.3 Scope: what the management system covers and anything you leave out, with the reason.
  • 4.1 Context: internal and external issues that affect your security.
  • 4.2 Interested parties: who expects what, and how you handle it. Click Add party for each one.
  • 5.3 Roles and responsibilities.
  • 6.1.2 / 6.1.3 Risk assessment and treatment method. Use our example fills in a method that matches the risk register; adjust it to your company.
  • Certification path: your certification body and the planned audit dates.

Click Save when you are done.

Objectives and management reviews

Under Objectives, set a few measurable security objectives, each with how it is measured, a target, the latest result and an owner. Under Management reviews, record at least once a year what management looked at (earlier actions, changes, performance, feedback, risks, improvements) and what it decided. Set the status to Completed when the review is done.

Corrective actions

In Internal audits, each finding now also has a Root cause and an Effectiveness check. For a nonconformity, fill in why it happened, the corrective action and, once closed, how you checked that the fix works.

The audit pack

Download audit pack creates one ZIP file for the auditor: the readiness checklist, the management system (Word), the Statement of Applicability, the risk register, objectives, management reviews (Word), internal audits and findings, training records and, when your package includes Word export, the published policies. Downloads are recorded in the activity log.

The way to the certificate

The Certification path tab explains the steps: run the management system for a few months, do an internal audit and a management review, choose an accredited certification body, then the stage 1 audit (documents) and the stage 2 audit (does it work in practice). The certificate is valid for three years, with a surveillance audit every year.

Who can change the kit: members who may change controls. Everyone who may read controls can see it and download the pack.

See also