Every document ISO 27001:2022 actually requires
ISO 27001 certification fails on documents more often than on technology. The standard requires two distinct layers: a policy layer that addresses the 93 Annex A controls and the clause-level requirements (Cl. 5.2), and an ISMS operating layer — the records and registers that prove the system runs. Here is the complete list, and who can realistically produce each piece.
Layer 1 — the policy set for 93 Annex A controls
Across the 93 controls of Annex A: 78 are covered by a well-built core set of 18 policies (governance, risk, access, crypto, logging, incident response, continuity, vendors and the other always-tested domains). 11 controls need two extension policies — the nine physical controls (A.7.1–A.7.6, A.7.8, A.7.11–A.7.12) require a Physical & Environmental Security Policy, and A.8.21 (security of network services) and A.8.26 (application security requirements) are covered by a Network Security Policy. The remaining 4 secure-development controls (A.8.25, A.8.27, A.8.28, A.8.30) live in a Secure Software Development Policy — excludable from your Statement of Applicability only if you genuinely develop no software.
Layer 2 — the ISMS operating documents
| Artifact | Required by | Who produces it |
|---|---|---|
| ISMS scope statement | Cl. 4.3 | Template-able one page: boundaries and interfaces |
| Statement of Applicability | Cl. 6.1.3 d) | Template-able — best pre-populated from per-policy annex mappings |
| Risk assessment methodology | Cl. 6.1.2 | Policy-level — method, criteria, scoring, appetite in the risk policy |
| Risk register & treatment plan | Cl. 6.1.3 / 8.2–8.3 | Template-able workbook; Your data populates it |
| Security objectives (current set) | Cl. 6.2 | Template-able framework; the year's objectives are yours |
| Internal audit programme | Cl. 9.2 | Template-able programme + procedure |
| Management review minutes | Cl. 9.3 | Template-able minutes structure; Your record |
| Nonconformity & corrective-action log | Cl. 10.2 | Template-able log; tracking is yours |
| Incident-response plan & runbooks | A.5.24–A.5.26 | Template-able scenario runbooks; contact rosters are yours |
| Access provisioning procedure | A.5.16/A.5.18 | Template-able lifecycle; step-level work instructions are yours |
| Backup/restoration procedure + test records | A.8.13 | Template-able procedure; Test evidence is yours |
| Asset inventory & vendor registers | A.5.9 / A.5.19 | Template-able registers with mandatory fields; Your data |
| Training & competence records | Cl. 7.2 | Template-able register; completions are yours |
| Operating runbooks (per platform) | A.5.37 | Yours — no template pack can know your stack |
The trap to avoid
Certifiers routinely reject document sets whose policies mandate registers that don't exist. If your access-control policy says "a provisioning register is maintained," the register — even empty-but-structured — must exist at stage 1. Buy or build the policy layer and the operating layer together, or your gap analysis will just move the gap.
Shortcut: MeerLock Professional (22 policies, 89/93 controls; 93/93 with the Engineering add-on) + the 24-artifact ISMS Toolkit covers both layers, with a pre-populated Statement of Applicability lifted from each policy's annex table. The PCI Bundle and Complete ship 27 — the three payment-card workbooks on top. See what's inside →
Both layers, one doctrine
Professional: €1,390 one-time, ISMS Toolkit included — or get a free sample policy first.
Get a sample policy →