# ISO 27001:2022 on AWS — Stage Checklist (July 2026)

## Before Stage 1

- [ ] ISMS scope (accounts / products) written
- [ ] Risk assessment + treatment plan
- [ ] Statement of Applicability (93 Annex A — justify exclusions)
- [ ] Mandatory docs: IS policy, roles, IR, BCP/DR, access, crypto, supplier

## Stage 2 evidence (examples)

- [ ] Org CloudTrail / Config / Security Hub samples
- [ ] Access reviews; change tickets; training logs
- [ ] Backup restore test; IR tabletop notes
- [ ] Shared-responsibility map vs AWS Artifact reports

## Counter-case

Tooling without management reviews / internal audit fails certification.
