Many organisations now pursue ISO 27001 not only for governance maturity, but because enterprise customers, procurement teams, insurers, and regulators increasingly expect independently verifiable security governance.
ISO 27001 has moved from a nice-to-have to a contractual expectation for many South African organisations — particularly those serving enterprise customers, processing personal information at scale, or operating in regulated sectors. The standard is well documented; what is less obvious is the sequence that gets an organisation from its current state to a certifiable Information Security Management System (ISMS) without wasted motion. This guide walks through the path that Lead Auditors actually run.
The short answer
Achieving ISO 27001 compliance in South Africa follows seven sequential steps: define scope, conduct a gap analysis, build the Statement of Applicability and complete risk treatment, implement Annex A controls, run an internal audit and management review, engage an accredited certification body and then maintain the certification. Most medium enterprises reach certification readiness in nine to eighteen months.
Step 1 — Define ISMS scope and the drivers behind certification
Scope is the most undervalued decision in an ISO 27001 implementation. Define which entities, services, locations, and information assets the ISMS covers — and which it explicitly excludes — before writing a single policy. The driver behind certification matters too: a customer contract has a different urgency than a multi-year strategic posture build. Both are valid; they sequence differently.
Step 2 — Run a gap analysis against the standard
A structured gap analysis compares the current state to ISO 27001 Clause 4–10 and Annex A controls. The output is a prioritised list of what exists, what is partially in place, and what is missing — with effort estimates for each gap. This is the document that anchors the implementation roadmap and the conversation with the executive sponsor about cost, time, and risk.
Step 3 — Build the Statement of Applicability and risk treatment plan
The Statement of Applicability (SoA) declares which Annex A controls apply, which do not, and why. The risk treatment plan documents how identified risks are addressed — accepted, transferred, avoided, or mitigated. These two documents are the spine of the ISMS and the first things a certifying auditor will ask to see.
Step 4 — Implement controls across people, process, and technology
Annex A 2022 has 93 controls across four themes: organisational, people, physical, and technological. Implementation is risk-prioritised, not a checkbox march. The highest-impact controls (access management, change control, supplier security, logging and monitoring, incident management) are typically tackled first because they produce the evidence the rest of the system depends on.
Step 5 — Run internal audit, management review, and the PDCA cycle
Before any external certification audit, the ISMS must demonstrate that it is operating, not just documented. Internal audit produces evidence that controls work in practice. Management review brings findings to the executive for decision. The Plan-Do-Check-Act (PDCA) cycle keeps the system improving after certification, which is what surveillance auditors look for year on year.
Step 6 — Engage an accredited certification body
Certification is performed by an accredited body, independent of the team that implemented the ISMS. ISO 17021 prohibits the implementer from also certifying. Plan for a Stage 1 readiness review, followed by Stage 2 certification, with surveillance audits typically held annually and full recertification every 3 years. Choosing the certification body early smooths Stage 1 timelines.
Step 7 — Maintain certification through continuous improvement
ISO 27001 certification is not a once-off project. Surveillance audits assess whether the ISMS continues operating effectively over time. Ongoing risk assessment, corrective actions, supplier reviews, policy updates, and management review activities keep the PDCA cycle active and the certification healthy between audit cycles.
In South Africa, ISO 27001 certification is increasingly a procurement and supplier assurance requirement across financial services, healthcare, mining, and enterprise outsourcing environments.
Common ISO 27001 implementation mistakes
- Defining scope too broadly
- Writing policies before risk assessment
- Treating Annex A as a checklist
- Ignoring supplier risk
- Failing to operationalise the PDCA cycle
- Pursuing certification without executive ownership
Key Takeaways
- Scope is the most undervalued decision in ISO 27001 implementation — define it before drafting any policy.
- The Statement of Applicability and risk treatment plan are the spine of the ISMS and the first documents an auditor inspects.
- Annex A 2022 has 93 controls across four themes; implement in risk-priority order, not in numerical order.
- Internal audit and management review must demonstrate that the ISMS is operating before a Stage 2 certification audit.
- ISO 17021 prohibits the implementer from also being the certifier — choose the certifying body separately.
- Most medium South African enterprises reach certification readiness in nine to eighteen months when the work is sequenced properly.
How Cyber Resilience Can Help
Cyber Resilience helps organisations design, implement, and operationalise ISO 27001-aligned ISMS programmes that withstand certification scrutiny and continue to improve long after certification is achieved.
Speak to our team to arrange a scoping discussion.
