Get Demo
↑

ISO 27001 Mandatory Documents and Records: The Complete List

ISO/IEC...

Published: September 2026 Compliance · ISO 27001 10–14 min read

ISO/IEC 27001:2022 requires specific documented information. Below is the locked core list used for this site’s P1 programme — clause references, not a vendor “100 policies” pack.

List lock: Treat this as the mandatory floor. Your SoA and Clause 7.5/8.1 needs may add procedures and records for effectiveness.

Mandatory Documented Information (Core)

Clause
Documented information
4.3
Scope of the ISMS
5.2
Information security policy
6.1.2
Information security risk assessment process
6.1.3
Risk treatment process and Statement of Applicability
6.2
Information security objectives
7.2
Evidence of competence
8.1
Documented information necessary for operational processes
8.2
Results of information security risk assessments
8.3
Results of information security risk treatment
9.1
Evidence of monitoring and measurement results
9.2.2
Evidence of the audit programme(s) and audit results
9.3.3
Results of management reviews
10.2
Evidence of nonconformities, actions, and corrective-action results

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

Is every procedure mandatory?

No. The standard explicitly requires documented information in specific clauses. Additional procedures are often necessary for effectiveness (7.5.1 / 8.1) but are not an infinite fixed checklist.

Where is the SoA required?

Clause 6.1.3 d).

Which clause covers corrective action records?

Clause 10.2 — evidence of the nature of nonconformities and subsequent actions, and of the results of corrective action.

ISO 27001 hub · 93 controls · SoA · CSA · Policy templates

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!