Every document ISO 27001:2022 actually requires

ISO 27001 certification fails on documents more often than on technology. The standard requires two distinct layers: a policy layer that addresses the 93 Annex A controls and the clause-level requirements (Cl. 5.2), and an ISMS operating layer — the records and registers that prove the system runs. Here is the complete list, and who can realistically produce each piece.

Layer 1 — the policy set for 93 Annex A controls

Across the 93 controls of Annex A: 78 are covered by a well-built core set of 18 policies (governance, risk, access, crypto, logging, incident response, continuity, vendors and the other always-tested domains). 11 controls need two extension policies — the nine physical controls (A.7.1–A.7.6, A.7.8, A.7.11–A.7.12) require a Physical & Environmental Security Policy, and A.8.21 (security of network services) and A.8.26 (application security requirements) are covered by a Network Security Policy. The remaining 4 secure-development controls (A.8.25, A.8.27, A.8.28, A.8.30) live in a Secure Software Development Policy — excludable from your Statement of Applicability only if you genuinely develop no software.

Layer 2 — the ISMS operating documents

ArtifactRequired byWho produces it
ISMS scope statementCl. 4.3Template-able one page: boundaries and interfaces
Statement of ApplicabilityCl. 6.1.3 d)Template-able — best pre-populated from per-policy annex mappings
Risk assessment methodologyCl. 6.1.2Policy-level — method, criteria, scoring, appetite in the risk policy
Risk register & treatment planCl. 6.1.3 / 8.2–8.3Template-able workbook; Your data populates it
Security objectives (current set)Cl. 6.2Template-able framework; the year's objectives are yours
Internal audit programmeCl. 9.2Template-able programme + procedure
Management review minutesCl. 9.3Template-able minutes structure; Your record
Nonconformity & corrective-action logCl. 10.2Template-able log; tracking is yours
Incident-response plan & runbooksA.5.24–A.5.26Template-able scenario runbooks; contact rosters are yours
Access provisioning procedureA.5.16/A.5.18Template-able lifecycle; step-level work instructions are yours
Backup/restoration procedure + test recordsA.8.13Template-able procedure; Test evidence is yours
Asset inventory & vendor registersA.5.9 / A.5.19Template-able registers with mandatory fields; Your data
Training & competence recordsCl. 7.2Template-able register; completions are yours
Operating runbooks (per platform)A.5.37Yours — no template pack can know your stack

The trap to avoid

Certifiers routinely reject document sets whose policies mandate registers that don't exist. If your access-control policy says "a provisioning register is maintained," the register — even empty-but-structured — must exist at stage 1. Buy or build the policy layer and the operating layer together, or your gap analysis will just move the gap.

Shortcut: MeerLock Professional (22 policies, 89/93 controls; 93/93 with the Engineering add-on) + the 24-artifact ISMS Toolkit covers both layers, with a pre-populated Statement of Applicability lifted from each policy's annex table. The PCI Bundle and Complete ship 27 — the three payment-card workbooks on top. See what's inside →

Both layers, one doctrine

Professional: €1,390 one-time, ISMS Toolkit included — or get a free sample policy first.

Get a sample policy →