
Toolkit overview
Image 1 of 6: Toolkit overviewISO 27001 Policy Pack — Core
16 editable ISO/IEC 27001:2022 policies plus the full 93-control Statement of Applicability — everything a small business needs to start its ISMS.
The ISO 27001 Policy Pack — Core is a set of 16 editable ISO/IEC 27001:2022 document templates (including 1 Excel workbook) in Microsoft Word (.docx) and Excel (.xlsx), written for Small businesses & startups. It is a one-time purchase with instant download and a single-organization license; you replace the amber [placeholders] with your organization's details. The toolkit gives you the documentation — certification or attestation, where it applies, still comes from an independent audit.
- What it is
- 16 editable ISO/IEC 27001:2022 document templates, including 1 Excel workbook
- Formats
- Microsoft Word (.docx) + Excel (.xlsx)
- Best for
- Small businesses & startups
- Price
- $29.50 (50% off $59) — one-time purchase, single-organization license
- Delivery
- Instant download after checkout
New to ISO/IEC 27001:2022? Read our ISO/IEC 27001:2022 guide →
Overview
The ISO 27001 Policy Pack — Core gives small businesses and startups a ready foundation for an information security management system, or ISMS. It is made for lean teams that have little or no security documentation yet. You need a credible starting point, and you need it fast. The pack delivers 16 editable ISO/IEC 27001:2022 documents plus the full 93-control Statement of Applicability. Every file is Microsoft Word or Excel, so you edit, rename, and brand it as your own. Download is instant. The license covers a single organization.
Most buyers arrive here under real pressure. A large customer sends a security questionnaire and expects written policies in return. A prospect asks for proof of your security program before they will sign. An investor or partner wants to see governance on paper, not just promises. A missed questionnaire can stall a deal you have spent months earning. Suddenly you need an information security policy, an access control policy, and an incident response procedure that did not exist last week. Drafting all of that from scratch is slow and stressful. A blank page is the hardest place to begin, and the deadline rarely moves.
This pack maps directly to how ISO/IEC 27001:2022 expects you to work. The Information Security Policy sets the top-level mandate and records leadership commitment. The Information Security Roles and Responsibilities policy assigns clear ownership. The Risk Assessment and Treatment Procedure drives a risk-based approach rather than a checkbox one. Focused policies then cover the areas auditors probe most. These include the Access Control Policy and the Asset Management and Information Classification Policy. You also get the Human Resources Security Policy and the Supplier and Cloud Services Security Policy.
The set adds a Logging and Monitoring Policy, a Backup and Recovery Policy, and a Remote Working and Mobile Device Policy. Operational documents round out the pack. There is an Information Security Incident Response Procedure, a Business Continuity and ICT Readiness Plan, and a Security Awareness and Training Procedure. An AI Acceptable Use Policy covers the new tools your team has already started using.
The Statement of Applicability ties the whole pack to the standard. This Excel workbook lists all 93 Annex A controls across the four themes. For each control, you record whether it applies, how you meet it, and the reason behind your decision. Auditors expect this document early, and it anchors the rest of your evidence. The policies in the pack give you concrete language to point to as you complete it. Together they show a reviewer that your program is deliberate, not improvised.
Tailoring a structured set beats drafting from nothing. The documents read consistently and reference each other clearly. Terms, roles, and cross-references line up across the whole pack. Bracketed placeholders show exactly what to fill in. You add your company name, your owners, and your review cadence. You shape the language to your real operations instead of inventing structure from an empty page. That turns weeks of policy writing into focused, confident editing. You can have a complete first draft in days, then refine it as your controls mature. The result is a coherent paper trail you can put in front of a customer, a partner, or an auditor.
Be clear about what these documents do and do not do. They form the readiness layer of your security program. They do not make you certified or compliant on their own. ISO 27001 certification comes only from an accredited certification body. It follows a Stage 1 and Stage 2 audit of a working ISMS, not a folder of templates. You still operate the controls, keep the records, and improve the system over time. What this pack does is remove the hardest first step. It helps you document a complete program quickly and start that work on solid ground.
What's inside — 16 documents + 1 workbook
- Information Security Policy (.docx)
- Information Security Roles and Responsibilities (.docx)
- Risk Assessment and Treatment Procedure (.docx)
- Acceptable Use Policy (.docx)
- Access Control Policy (.docx)
- Asset Management and Information Classification Policy (.docx)
- Physical and Environmental Security Policy (.docx)
- Human Resources Security Policy (.docx)
- Remote Working and Mobile Device Policy (.docx)
- Supplier and Cloud Services Security Policy (.docx)
- Information Security Incident Response Procedure (.docx)
- Business Continuity and ICT Readiness Plan (.docx)
- Backup and Recovery Policy (.docx)
- Logging and Monitoring Policy (.docx)
- Security Awareness and Training Procedure (.docx)
- AI Acceptable Use Policy (.docx)
Excel workbooks
- Statement of Applicability — all 93 Annex A controls (Excel)
See the real content before you buy
We publish genuine excerpts — not marketing mockups. Read the opening sections of the Information Security Policy exactly as you'll receive it:
Read the free previewWhat customers say
“Great toolkit has helped me tremendously with cutting down the time needed to write each part. Would highly recommend.”
Frequently asked questions
- Does this ISO 27001 toolkit include the Statement of Applicability?
- Yes. Every ISO 27001 toolkit includes an editable Excel Statement of Applicability covering all 93 Annex A controls of ISO/IEC 27001:2022, alongside the Word policies and, where listed, a risk register.
- Will these templates make my company ISO 27001 certified?
- No document set alone grants certification. An accredited certification body issues ISO 27001 certification after a Stage 1 and Stage 2 audit of a working ISMS. This toolkit gives you the complete, professionally structured documentation auditors expect — the longest part to prepare.
- Is it aligned to ISO 27001:2022 or the older 2013 version?
- It is written to ISO/IEC 27001:2022, including the restructured Annex A of 93 controls across four themes. When the standard changes materially we update the documents and offer affected customers a free re-download.
- What format are the files and how are they delivered?
- Editable Microsoft Word (.docx) and Excel (.xlsx) files, delivered as an instant download immediately after checkout. Organization-specific values are amber [bracketed placeholders] you replace with find-and-replace.
- What licence do I get?
- A single-organization licence. If you are a consultant or MSP intending to reuse the documents across multiple clients, contact us first for a fair multi-client arrangement.
- What if a file is defective or is not what the page described?
- Because delivery is instant, sales are final — but if a file is defective or materially does not do what this site describes, email support@compliancedocshq.com within 14 days of purchase and we will repair, replace or refund it. The choice of remedy is ours, but we will make a genuine defect right. Purchases made through a marketplace such as Etsy follow that marketplace's policies.
- What happens after I pay, and what if I lose the download link?
- You are taken to a receipt page with your download, and a delivery email is sent to the address you enter at checkout. No account is required. Download links expire for security — if yours has lapsed, reload your receipt page or email support@compliancedocshq.com for a fresh link.
