← Document packs ISO 27001:2022

ISO 27001 for SMEs: an ISMS documentation guide

ISO 27001 is the international standard for information security management. It is the framework most South African SMEs turn to when a customer, tender, or regulator asks them to prove they take information security seriously.

This guide explains what the standard requires, which documents you need to build, and how a small business can work towards certification without a full-time compliance team.

What ISO 27001 is and why it exists

ISO 27001 sets out the requirements for an Information Security Management System (ISMS) - a structured way of protecting your organisation information and demonstrating that you manage risk deliberately. The 2022 revision organises 93 controls across four themes: Organisational, People, Physical, and Technological.

Certification is awarded by accredited certification bodies after an independent audit and is valid for three years, with annual surveillance audits. For most SMEs the value is practical: it gives clients and partners a recognisable, audited signal that their data is safe with you.

Why SMEs pursue ISO 27001

The most common trigger is procurement. Enterprises and government departments increasingly require suppliers to hold ISO 27001 certification or at least demonstrate an ISMS. Tenders regularly ask for it as a condition of entry.

The other drivers are regulatory and commercial: a clear security framework helps you meet protection-of-personal-information obligations, reduces the impact of incidents, and is a genuine differentiator against competitors who cannot show a structured programme.

The documents you need for certification

Certification is built on a documentation foundation. The core set for an SME is smaller than people expect.

You need a scope and context document defining what your ISMS covers, your stakeholders, and their requirements; a set of policies such as the Information Security Policy, Acceptable Use, Access Control, Incident Response, Asset Management, and Business Continuity policies; an Annex A controls register used as your Statement of Applicability showing which of the 93 controls apply and why; and a risk register aligned to clauses 6.1 and 6.2 recording your risks, scores, and treatment decisions.

Our ISO 27001 document packs are ready-to-use templates for exactly these four documents. They are pre-structured with placeholder fields for your company details so you tailor rather than start from a blank page.

A realistic roadmap for a small business

A typical certification journey for an SME runs six to twelve months. Start with a gap analysis against the standard, build your documentation foundation, implement the controls in scope, and run an internal audit before inviting a certification body to assess you.

Choose an accredited certification body early, because their requirements will shape your implementation. Keep the momentum going - the documentation is a living part of the business, not a one-off filing exercise.

Common mistakes to avoid

The most expensive mistakes are also the most common: buying generic document packs without tailoring them to your business, defining an ISMS scope that is vague or unrealistically wide, treating certification as a one-time project rather than an ongoing system, and attempting it without visible management commitment.

Also remember that not all 93 Annex A controls will apply to you. The applicability assessment - your Statement of Applicability - is there to justify what you include and what you exclude.

ISO 27001:2022 document packs

Ready-to-use ISO 27001:2022 templates, pre-structured with placeholder fields for your company details. Instant download after payment - no subscription.

ISO 27001:2022 FAQ

How much does ISO 27001 certification cost for an SME?

The audit fees charged by accredited certification bodies vary by company size and scope and typically run to tens of thousands of rands. Our document templates cover the documentation foundation for a small fraction of that, but certification itself always requires a formal audit.

How long does it take to get certified?

Most SMEs plan for six to twelve months from gap analysis to certification. The exact time depends on how much of the work is already in place and how quickly the business implements the controls in scope.

Will document templates get me certified?

No. Certification requires an accredited audit of your actual implementation. The documentation foundation is a significant part of the work - and what our templates provide - but you still need to implement the controls and undergo the audit.

Do I need all 93 Annex A controls?

No. The Statement of Applicability lets you justify which controls are relevant to your ISMS scope. Many controls will not apply to a small business, and that is expected.

Questions?

If you have questions about which kit is right for your business, or need a custom document set for a specific framework or industry, contact us at [email protected].