ISO 27001 Checklist for Manufacturing IT Teams (2026)

Last updated: 10/06/2026
Compliance
ISO 27001 Checklist for Manufacturing IT Teams (2026)

An ISO 27001 checklist for manufacturing covers clauses 4-10, a Statement of Applicability for the 93 Annex A controls, and 3 plant decisions: whether OT is in scope, how vendors reach production systems, and what happens to equipment you can't patch.

Built for manufacturers rather than software companies, the checklist below runs in 4 phases. Scope and context come first, before anyone writes a policy. Then risk and the Statement of Applicability, then the 6 controls that read differently on a shop floor, then audit and certification. Each phase has items you can tick off and the evidence an auditor will ask to see.

The request usually arrives sideways. A customer's supplier questionnaire asks for your ISO 27001 certificate number, purchasing forwards it to IT, and IT downloads a generic checklist written for a software company with 40 laptops and no factory. That checklist will get you a policy binder. It won't tell you what to do about the PLC that runs Windows 7, the integrator who dials in every Thursday, or the HMI terminal 3 shifts share under one login.

If you need the basics first, start with our plain-English guide to what ISO 27001 is. This post assumes you know the standard and need to apply it to a plant. It's written for the IT lead who owns the project and the operations leader who has to live with it.

A certificate proves you run a management system. It doesn't prove the plant is secure. Manufacturing was again the most targeted industry in IBM's 2026 X-Force Threat Intelligence Index, and a Black Kite study reported by Infosecurity Magazine put manufacturers at 22% of all ransomware victims from April 2025 to March 2026. Certified companies are in those numbers too. Build the ISMS so it actually changes how the plant runs. Then the certificate is a side effect.

A factory robotic arm and conveyor beside a clipboard checklist with green check marks and a security shield, representing an ISO 27001 checklist for a manufacturing plant

What Does an ISO 27001 Checklist Need to Cover in a Manufacturing Plant?

It needs to cover the mandatory clauses 4 through 10, a risk assessment, a Statement of Applicability that rules each of the 93 Annex A controls in or out with a reason, and evidence that the controls actually run. In a plant, that includes production systems, not just the office.

The ISMS (information security management system) is the set of policies, risk decisions, and routines you use to run security. The Statement of Applicability, or SoA, is the document that lists every Annex A control and says whether you use it and why. Annex A is the catalog of 93 controls in ISO/IEC 27001:2022, grouped into 4 themes: organizational, people, physical, and technological.

Two dates matter in 2026. The 2013 edition is gone. Under the accreditation rule IAF MD 26, every 2013 certificate was withdrawn on October 31, 2025, whatever date was printed on it, as RSM Certification's IAF MD 26 summary lays out. And a 2024 amendment added a line to clauses 4.1 and 4.2 requiring you to decide whether climate change is a relevant issue for your ISMS. For an office tenant, that's usually a sentence. For a plant on a flood plain or a line that shuts down above a certain ambient temperature, it's a real risk entry.

ISO 27001 sits alongside the rest of your compliance program, not on top of it. If you already carry CMMC, ITAR, or customer security clauses, the checklist should reuse that work instead of starting a parallel binder.

Phase 1 Checklist: Scope and Context

Scope is where manufacturing projects quietly go wrong, so it comes before policy writing. Get this phase signed off by leadership before anyone opens a template.

An office building and a factory connected by network cables that pass through a green firewall shield, representing the decision on whether plant systems are in ISO 27001 scope

  • List every site, building, and line the ISMS covers, plus anything you're deliberately leaving out and why.
  • Make the OT decision in writing. Are PLCs, HMIs, SCADA, and the MES in scope?
  • Map where information actually lives: ERP, MES, quality system, CAD and CAM file shares, engineering laptops, USB drives at the machines.
  • Name your interested parties (clause 4.2). For a manufacturer that's OEM customers, defense primes, insurers, regulators, and key suppliers, each with their own security asks.
  • Record the climate change determination for each site.
  • Write down the internal and external issues (clause 4.1), like a planned ERP migration or a customer requirement landing next year.
  • Get the scope statement (clause 4.3) signed by someone who can actually stop a production line.

The OT question deserves more than a checkbox. Auditors generally expect production systems in scope when they hold or move information that matters, and in a modern plant almost everything does. Recipes, part programs, process parameters, and quality records are information. So are the files on the test stations. A CNC program for a customer's part is that customer's IP.

So is excluding OT ever reasonable? Sometimes. A purely mechanical line with no network connection and no stored data can sit outside. What doesn't work is excluding the floor because it's hard. The SoA has to justify the exclusion, and "the plant team didn't want to deal with it" isn't a justification an auditor accepts. Our guide to ISO 27001 for electronics manufacturers covers how this plays out in a high-mix electronics shop.

Phase 2 Checklist: Risk Assessment and the Statement of Applicability

This phase produces the 3 documents an auditor reads first: the risk assessment, the risk treatment plan, and the SoA. All 3 are mandatory under clause 6.1.

  • Build an asset inventory that includes the floor: PLCs, HMIs, engineering workstations, historians, test stations, label printers, and the vendor laptops that visit.
  • Pick a risk method and write it down (clause 6.1.2). Likelihood times impact on a 1-5 scale is fine. Consistency matters more than sophistication.
  • Score impact in production terms. An hour of line downtime, a scrapped lot, a missed ship date, a customer's drawings leaking.
  • Name a risk owner for every risk. On the floor that's usually a plant or operations manager, not IT.
  • Write the risk treatment plan (clause 6.1.3): treat, transfer, accept, or avoid, with a date and an owner.
  • Complete the SoA with a reason for every included and excluded control.
  • Set information security objectives you can measure (clause 6.2).

Scoring impact in production terms changes the results. A file server outage scored on generic IT criteria looks medium. The same outage scored as "the shop can't pull work instructions, 2 lines stop, and Friday's shipment misses" looks like what it is. Nothing about the server changed. Risk owners on the plant side will also defend the budget for fixing it, which IT owners rarely manage alone.

Phase 3 Checklist: The Annex A Controls That Look Different on a Shop Floor

Every Annex A control applies to a plant the same way on paper. In practice, 6 areas need a plant-specific answer.

ISO 27001 Annex A controls on the shop floor: identity, supplier security, vulnerabilities, network segregation, classification, and backup, with the generic reading and the plant reading for each

Shared logins on HMIs and kiosks

An HMI (the touchscreen operators use to run a machine) with one shared account across 3 shifts fails control 5.16 as written. Forcing a 12-character password and MFA on a press operator in gloves fails the line. Both are real failures. The workable answer is usually badge or PIN login on shared terminals, shared accounts limited to view-and-run functions, and unique accounts for anything that changes a setpoint or a program.

  • Inventory every shared account on the floor and what it can change.
  • Separate "operate" rights from "modify" rights.
  • Log program and setpoint changes to a named person.

Vendor and integrator remote access

A machine builder installs remote access software or a cellular modem during commissioning so they can support the equipment. Three years later nobody remembers it's there, and it bypasses every firewall rule you wrote. Nobody approved it, and nothing logs it.

CISA and the FBI addressed this directly in a September 2026 fact sheet on third-party ICS integrators. They recommend access through routes you can monitor, on-demand access that someone at the plant has to switch on, least privilege, and contracts that spell out remote access, patching, and who on the integrator's side is authorized. CISA's joint guide to securing remote access software covers the tools themselves.

  • List every vendor with remote access to production, how they connect, and who approves each session.
  • Walk the floor for modems and unmanaged remote access tools. Check the panels, not just the network diagram.
  • Route all vendor sessions through one gateway with MFA and logging.
  • Add security terms to machine purchase and service contracts (control 5.20).

Equipment you can't patch

Control 8.8 asks you to manage technical vulnerabilities. It doesn't demand a patch on a fixed calendar, and that distinction saves plant projects. A coordinate measuring machine running Windows 7 often can't be updated without voiding the OEM's support. NIST SP 800-82 Rev. 3, the federal guide to OT security, says when patching an older OT component isn't an option, add controls that protect it from exploitation.

In ISO terms, that's a documented risk acceptance with compensating controls. Isolate the machine on its own network segment, block internet access, disable USB ports, allow-list the software it runs, and record the decision in the risk register with an owner and a review date. Auditors accept unpatched equipment. They don't accept unpatched equipment nobody wrote down.

Segmenting office and floor networks

Plants that grew over 20 years often have office PCs, the ERP server, and the PLCs on one flat network. Ransomware that lands on a front-office laptop then reaches the line. Controls 8.20 and 8.22 want networks segmented by trust level. The usual target is a firewall between office and floor, with a small buffer zone (often called a DMZ) for the systems that need to talk to both, like the MES or a historian.

Don't try to do it in one weekend. Map the traffic first. Lines have stopped because someone blocked a port a label printer quietly depended on.

Customer drawings and process IP

Controls 5.12 and 5.13 cover classifying and labeling information. In a plant, the most sensitive data often belongs to someone else: customer drawings, specs under NDA, and in defense work, controlled technical data. Classify those by customer obligation, not just internal sensitivity, and check where copies live. Engineering laptops and the USB stick taped to the CNC control are common answers. Check both.

Backup and continuity for production systems

IT backs up servers. Who backs up the PLC logic and HMI projects? Often it's the integrator, on their laptop, from 2022. That's the whole plan. Control 8.13 covers backups and 5.30 covers ICT readiness for business continuity. For a plant, that means current copies of controller programs and recipes, stored where ransomware can't reach them, and a tested answer to how long it takes to bring a line back.

  • Pull current PLC and HMI project files into managed, versioned storage.
  • Run one restore test on a real controller or a spare, not just a file check.
  • Write recovery time targets per line, agreed with operations.

Phase 4 Checklist: Internal Audit, Management Review, and Certification

The last phase proves the system runs. Certification bodies look for records over time, so start collecting evidence the day controls go live.

  • Run a full internal audit (clause 9.2) by someone independent of the work they're auditing.
  • Hold a management review (clause 9.3) with minutes, decisions, and action owners.
  • Log nonconformities and corrective actions (clause 10.2).
  • Keep 2-3 months of operating evidence: access reviews, vendor session logs, backup tests, training records.
  • Book the Stage 1 audit (a documentation review) and the Stage 2 audit (on-site testing of whether controls work).
  • Plan for surveillance audits in years 1 and 2 and recertification in year 3.

ISO 27001 certification timeline for a manufacturer: ISMS build, Stage 1 audit, Stage 2 audit, surveillance audits, and recertification, with typical timing and what the auditor checks

Stage 2 auditors do walk the floor in manufacturing audits. Expect them to stop at an HMI and ask who's logged in. Budget and timing ranges for each step are in our breakdown of ISO 27001 certification cost and timeline.

Does ISO 27001 Cover CMMC or IEC 62443?

No. ISO 27001 doesn't satisfy CMMC, and it isn't a substitute for IEC 62443. But the overlap is large enough that a manufacturer holding more than one of them should build a single control set and map it to each framework.

CMMC is required by contract for defense suppliers handling Federal Contract Information or Controlled Unclassified Information, under the DoD's rule at 32 CFR Part 170. The rule names CMMC, not ISO, so an ISO certificate earns no CMMC credit. The underlying work still overlaps heavily, especially access control, incident response, and audit logging. If you're a defense supplier, sequence it with your CMMC compliance program rather than running 2 projects that interview the same people twice.

IEC 62443 is the industrial control system security series. It goes deeper than ISO on zones, conduits, and security levels for the equipment itself. Plants with heavy automation often use ISO 27001 as the management system and IEC 62443 as the engineering standard for the floor. Our guide to IEC 62443 in electronics manufacturing covers that split.

ISO 27001 vs CMMC vs IEC 62443 compared by what each covers, who asks for it, how certification works, and how they reuse each other

Where Manufacturing ISO 27001 Projects Stall

IT owns it alone. The ISMS needs risk owners from operations, quality, and engineering. When IT writes every policy and owns every risk, the plant treats the project as paperwork, and Stage 2 finds the gap between the binder and the floor.

Scope gets set by convenience. Too narrow, and the certificate covers the front office while the customer's drawings sit on a shop floor share that's out of scope. Customers can read the scope statement, and the careful ones do. Too broad, and a 3-site manufacturer with a thin IT team never finishes.

Then there's the binder problem. A company can pass Stage 2 with good documents and weak habits, and the first surveillance audit catches it. Access reviews that happened once. A vendor list nobody updated after the new packaging line went in. Compliance isn't security, and the auditor's sample will find where they diverge.

And the plant's own schedule gets ignored. Internal audits booked during peak season, segmentation changes scheduled during a launch. Plan the ISMS calendar around production, the same way you'd plan a shutdown.

If you'd rather have someone walk the floor with you before the auditor does, Speak to a Compliance Expert. Consilien helps manufacturers prepare for ISO 27001 certification through its ISO 27001 services and manufacturing compliance services, as a standalone engagement. If you have an in-house security team that has already certified a plant, you probably don't need us for this one.

Get Ready Before the Auditor Walks the Floor

Stage 2 auditors stop at the HMI and ask who's logged in.

We'll go through your ISO 27001 scope with you, including the OT decision, vendor remote access, the equipment you can't patch, and the evidence an auditor will ask to see.

Questions Manufacturers Ask About ISO 27001

How long does ISO 27001 take for a manufacturer?
Plan on roughly 9-18 months from a cold start to certificate, with the ISMS build taking the largest share. Stage 1 and Stage 2 audits then need to fall within 6 months of each other. A plant that already runs CMMC or strong customer security controls can move faster, because much of the evidence exists.
Do PLCs and other OT systems have to be in scope?
Usually, yes. If production systems store or move information that matters, like recipes, part programs, quality records, or customer IP, auditors expect them in scope. You can exclude OT, but the Statement of Applicability has to justify it, and difficulty isn't a justification.
Does ISO 27001 replace CMMC for defense suppliers?
No. CMMC is a contract requirement under 32 CFR Part 170, and an ISO certificate earns no credit toward it. The control work overlaps, though, so build once and map to both.
Is ISO 27001:2013 still accepted?
October 31, 2025 ended it. Every 2013 certificate was withdrawn that day, so all 2026 audits use the 2022 edition with its 93 Annex A controls.
Which documents are mandatory?
Six sit at the core: the ISMS scope (4.3), the information security policy (5.2), the risk assessment process (6.1.2), the risk treatment process and plan (6.1.3), the Statement of Applicability (6.1.3), and security objectives (6.2). You'll also need records of internal audits, management reviews, and corrective actions. The Annex A controls you select add their own documented procedures on top, so a plant with OT in scope typically ends up with remote access, change management, and backup procedures written specifically for the floor.
Can a small manufacturer certify without a security team?
Yes, with outside help and an honest scope. Single-site manufacturers do certify with one IT generalist, an executive sponsor who shows up to management reviews, and a consultant or vCISO for the risk work and the internal audit. The part that can't be outsourced is the plant's participation.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.