By Jackson Godwin | Cybersecurity Analyst & Penetration Tester. Email info@jacksontechnology.com.ng
ISO 27001 certification has moved from a nice-to-have to a hard commercial requirement for Nigerian businesses operating in banking, fintech, telecoms, oil and gas, and the public sector. The Central Bank of Nigeria (CBN) CSOR Framework, the Nigeria Data Protection Act 2023 (NDPA), and the Nigerian Communications Commission (NCC) Information Security Directives all reference internationally recognised security management standards — and ISO 27001 is the gold standard.
Yet many Nigerian organisations approach the ISO 27001 audit cycle unprepared. Gap assessments reveal missing documentation, untested controls, incomplete risk registers, and incident response plans that have never been exercised. The result: failed stage audits, costly remediation cycles, and delayed certification.
This guide provides a practical, step-by-step preparation roadmap for Nigerian businesses pursuing ISO 27001:2022 certification — from initial gap assessment through to audit day readiness. Whether you are a first-time applicant or preparing for a surveillance audit, this framework applies.
📌 Standard in Focus: This guide references ISO/IEC 27001:2022 — the current edition, which replaced the 2013 version and introduced a restructured Annex A with 93 controls across four themes. Organisations certified under ISO 27001:2013 must migrate to the 2022 standard by October 2025.
Step 1: Understand What ISO 27001 Actually Requires
Before scheduling any audit, leadership and the security team must have a clear, accurate understanding of what ISO 27001 certification means. It is not a one-time technical assessment. It is a demonstration that your organisation operates a documented, risk-driven, continuously improving Information Security Management System (ISMS).
The standard has two primary components:
- The main clauses (Clauses 4–10): These define the management system requirements — context of the organisation, leadership commitment, planning, support, operation, performance evaluation, and improvement. Every requirement in these clauses is mandatory.
- Annex A (ISO/IEC 27002:2022): A reference set of 93 information security controls grouped into four themes — Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). Organisations select applicable controls and justify exclusions in a Statement of Applicability (SoA).
💡 Nigeria Tip: Many Nigerian SMEs attempt to implement Annex A controls without first establishing the management system (Clauses 4–10). Auditors will fail an organisation that cannot demonstrate leadership buy-in, a formal risk assessment process, and a documented ISMS scope — regardless of how many technical controls are in place.
Step 2: Define and Document Your ISMS Scope
The ISMS scope is the formal boundary of what your certification covers. It must be documented, defensible, and appropriate to your organisation’s risk profile. Auditors scrutinise scope definitions carefully — an overly narrow scope that excludes critical systems or processes will be challenged.
Your scope document should clearly define:
- Which business units, locations, and functions are within scope
- Which information assets are covered (systems, databases, physical records, third-party hosted data)
- Which interfaces and dependencies exist with out-of-scope entities (parent companies, cloud providers, third-party processors)
- Any exclusions and the justification for each exclusion
For Nigerian organisations with operations across multiple states or with offshore data processing arrangements — common in banking, insurance, and oil and gas — the scope must explicitly address cross-border data flows and whether offshore locations or processors fall within or outside the certified boundary.
💡 Nigeria Tip: If your organisation processes data subject to CBN, NDPA, or PENCOM regulations, ensure your ISMS scope explicitly covers the systems and processes that handle regulated data. Auditors increasingly reference sector-specific regulatory requirements during clause 4.1 (Understanding the Organisation and Its Context) review.
Step 3: Conduct a Formal Gap Assessment
A gap assessment maps your current security posture against ISO 27001:2022 requirements. This is not an audit — it is a structured self-assessment that identifies what is already in place, what is partially implemented, and what is missing entirely.
The gap assessment should evaluate:
| Clause 4 | Context, interested parties, internal/external issues, regulatory obligations (NDPA, CBN, NCC, FRCN, SEC) |
| Clause 5 | Leadership commitment, ISMS policy, defined information security roles and responsibilities |
| Clause 6 | Risk assessment methodology, risk register, risk treatment plan, Statement of Applicability (SoA) |
| Clause 7 | Competence, awareness training records, documented information management procedures |
| Clause 8 | Operational planning, supplier management, change management, incident response |
| Clause 9 | Internal audit programme, management review records, performance metrics and KPIs |
| Clause 10 | Nonconformity tracking, corrective action records, continual improvement documentation |
| Annex A | All 93 controls assessed for applicability, implementation status, and evidence availability |
Gap findings should be scored by severity (Critical, High, Medium, Low) and mapped to a remediation timeline with named owners. This gap assessment output becomes your project plan for audit preparation.
💡 Nigeria Tip: Engage an experienced ISO 27001 consultant or internal GRC team to conduct the gap assessment. Self-assessment by the team responsible for implementation introduces bias and often misses documentation gaps that auditors will immediately identify.
Step 4: Build Your Risk Assessment and Treatment Framework
Risk assessment is the engine of ISO 27001. Everything flows from it — control selection, the SoA, the risk treatment plan, and ongoing management review. The risk assessment methodology must be documented, consistently applied, and repeated at defined intervals or when significant changes occur.
4.1 Risk Assessment Methodology
Your methodology document must define:
- The risk criteria: what constitutes acceptable risk for your organisation
- The likelihood and impact scoring scales and how scores translate to risk ratings
- The asset-threat-vulnerability model you use to identify risks
- Who is responsible for risk identification, assessment, and sign-off
4.2 The Risk Register
Every identified risk must be recorded in a risk register with: asset, threat, vulnerability, inherent likelihood, inherent impact, inherent risk rating, selected treatment (Accept / Mitigate / Transfer / Avoid), applicable Annex A controls, residual risk rating, and risk owner. For Nigerian organisations, risk registers should include risks specific to the local operating environment:
- Power infrastructure unreliability and generator dependency affecting availability controls
- Insider threat risks compounded by limited background check infrastructure
- Third-party risk from local cloud hosting providers and managed service providers with varying security maturity
- Physical security risks specific to Nigerian office environments and data centre facilities
- Regulatory compliance risk from evolving CBN, NDPA, and NCC requirements
4.3 Statement of Applicability (SoA)
The SoA is one of the most scrutinised documents in any ISO 27001 audit. It lists all 93 Annex A controls, states whether each is applicable, references the justification for inclusion or exclusion, and provides implementation status and evidence reference. The SoA must be signed by management and version-controlled.
💡 Nigeria Tip: Auditors frequently cross-reference the SoA against the risk register and the actual technical environment. If you have marked a control as ‘implemented’ but cannot produce evidence, or if your risk register identifies a risk for which no corresponding control is selected in the SoA, expect a nonconformity.
Step 5: Implement and Evidence the Required Controls
Documentation alone does not pass an ISO 27001 audit. Auditors require evidence that controls are operational, consistently applied, and effective. For each Annex A control marked as applicable in your SoA, you must be able to produce evidence of implementation.
Priority evidence areas that Nigerian organisations commonly struggle to produce:
- Access control reviews: Quarterly or semi-annual documented reviews of user access rights, with sign-off by data owners. Screenshots of user lists without evidence of review will not suffice.
- Asset inventory: A complete, current inventory of information assets within scope — hardware, software, data, and services — with ownership, classification, and location recorded.
- Supplier agreements: Written information security clauses in contracts with all key suppliers, including cloud providers (AWS, Azure, Google Cloud), local ISPs, managed service providers, and third-party processors.
- Incident response records: A log of information security events and incidents, including those resolved without escalation. Auditors look for evidence the process is used, not just documented.
- Vulnerability management: Evidence of regular vulnerability scanning, patch management processes, and remediation tracking — particularly critical for Nigerian fintech and banking environments subject to CBN cybersecurity framework requirements.
- Physical security: Visitor logs, CCTV coverage documentation, clean desk policy compliance evidence, and secure disposal records for decommissioned hardware.
- Business continuity and DR testing: Documented, completed business continuity and disaster recovery tests — not just plans. Include test dates, participants, results, and lessons learned.
💡 Nigeria Tip: The NCC and CBN both reference vulnerability assessment and penetration testing (VAPT) as a required security activity. Including a recent VAPT report from a qualified penetration testing firm as evidence of control A.8.8 (Management of Technical Vulnerabilities) strengthens your audit position significantly.
Step 6: Run Your Internal Audit Programme
ISO 27001 Clause 9.2 requires that organisations conduct internal audits at planned intervals to determine whether the ISMS conforms to the standard’s requirements and the organisation’s own ISMS requirements, and whether it is effectively implemented and maintained.
Before your certification audit, you must have completed at least one full internal audit cycle covering all clauses and all applicable Annex A controls. The internal audit programme must include:
- A documented audit plan covering scope, criteria, methods, and schedule
- Auditors who are independent of the areas being audited (internal or external)
- Documented audit findings, including both conformities and nonconformities
- A formal audit report presented to management
- A corrective action register for all identified nonconformities, with target dates and owners
All nonconformities identified during internal audit must have documented corrective actions — and those corrective actions must be at least in progress, if not completed, before your Stage 2 certification audit. Unresolved internal audit nonconformities with no corrective action plan will be escalated to major nonconformities by certification body auditors.
Step 7: Conduct a Management Review
Clause 9.3 requires top management to review the ISMS at planned intervals. This is not a status update meeting — it is a formal, minuted review that must cover:
- The status of actions from previous management reviews
- Changes in external and internal issues relevant to the ISMS
- Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives
- Feedback from interested parties including regulatory bodies (CBN, NDPC, NCC)
- Results of risk assessment and the status of the risk treatment plan
- Opportunities for continual improvement
Management review minutes must be formally documented and retained as evidence. The review must result in documented decisions and actions — resource allocation, policy changes, ISMS improvements. A management review that produces no actions will be questioned by auditors.
💡 Nigeria Tip: Nigerian CEOs and board members sometimes view management review as an administrative formality. Prepare a concise management review pack that translates ISMS performance metrics into business language — data breach risk, regulatory fine exposure, client trust, and competitive positioning. Engagement improves significantly when executives see the business case alongside the compliance requirement.
Step 8: Select and Engage Your Certification Body
ISO 27001 certification must be issued by an accredited certification body (CB). In Nigeria, organisations may use locally present CBs or international CBs conducting remote or on-site audits. When selecting a certification body, consider:
- Accreditation: The CB must be accredited by a recognised national accreditation body (such as UKAS in the UK, DAkkS in Germany, or ANAB in the US). Certificates issued by non-accredited CBs are not internationally recognised.
- Sector experience: Choose a CB with auditors experienced in your sector. Financial services, oil and gas, and telecoms have sector-specific risk contexts that sector-experienced auditors understand.
- Nigerian regulatory familiarity: CBs whose auditors understand local regulations (NDPA, CBN CSOR Framework, NCC Cybersecurity Regulations) will conduct more relevant and productive audits.
- Stage 1 (Documentation Review) and Stage 2 (On-site Audit): Understand the two-stage certification audit process and agree timelines with the CB well in advance.
Step 9: Stage 1 Audit — Documentation Review
The Stage 1 audit is a review of your ISMS documentation. The certification body auditor assesses whether your documentation demonstrates readiness for the Stage 2 on-site audit. The auditor is not verifying implementation — they are verifying that the management system is designed to meet the standard’s requirements.
Ensure the following documents are complete, current, and available for Stage 1 review:
| ✓ | Stage 1 Documentation Readiness Checklist |
| ☐ | ISMS Scope document (signed, version-controlled) |
| ☐ | Information Security Policy (approved by top management, communicated to all staff) |
| ☐ | Risk Assessment Methodology document |
| ☐ | Risk Register (current, with residual risk ratings and owner sign-offs) |
| ☐ | Risk Treatment Plan (with implementation timeline and status) |
| ☐ | Statement of Applicability — all 93 Annex A controls addressed |
| ☐ | Information Security Objectives with measurable targets |
| ☐ | Competence and awareness training records for all in-scope staff |
| ☐ | Documented information management procedure (document control) |
| ☐ | Internal Audit Programme and completed audit reports |
| ☐ | Internal audit corrective action register with evidence of remediation |
| ☐ | Management Review minutes (formal, minuted, with decisions and actions) |
| ☐ | Incident response procedure and incident log |
| ☐ | Business continuity and disaster recovery plans with test records |
| ☐ | Supplier and third-party management policy and contractual clauses |
| ☐ | Asset inventory (information assets within ISMS scope) |
| ☐ | Access control policy and evidence of access reviews |
| ☐ | HR security procedures (pre-employment screening, termination process) |
| ☐ | Change management procedure |
| ☐ | Vulnerability management and patch management records |
Stage 1 findings are communicated as major nonconformities (must be resolved before Stage 2 can proceed), minor nonconformities (must have corrective action plans), or observations (improvement recommendations). Address all Stage 1 findings before confirming your Stage 2 date.
Step 10: Stage 2 Audit — On-Site Certification Audit
The Stage 2 audit verifies that the ISMS is not only documented but actively implemented, consistently applied, and effective. Auditors will interview staff, observe processes, test controls, and request evidence across the full scope of your ISMS.
Preparing Your Team
Staff interviews are the most revealing part of Stage 2. Auditors will approach employees at all levels — from executives to IT helpdesk staff — and ask questions about their security responsibilities, how they handle incidents, what training they have received, and how they access and protect sensitive information. Ensure:
- All in-scope staff have completed information security awareness training and can articulate the key policies
- IT and security staff can demonstrate technical controls (access management, logging, patching) without advance preparation
- Management can speak to the ISMS strategy, risk appetite, and recent management review outcomes
- Receptionists, facilities staff, and non-technical employees understand physical security and clean desk policies
Evidence Presentation
Prepare a structured evidence folder (physical or electronic) organised by Annex A control reference. When an auditor asks for evidence of a specific control, you should be able to produce it within seconds — not minutes. Evidence retrieval delays create a poor audit impression and prompt auditors to probe further.
💡 Nigeria Tip: Conduct an internal mock audit — sometimes called a ‘pre-audit’ — two to four weeks before your Stage 2 date. Have an internal team member or external consultant play the role of the certification auditor, asking interview questions and requesting evidence. Gaps identified in the mock audit can still be addressed before the real thing.
Common Reasons Nigerian Businesses Fail ISO 27001 Audits
Based on recurring patterns in Nigerian compliance engagements, the following are the most frequent causes of audit failure or significant nonconformity findings:
- 1. Incomplete Statement of Applicability — controls marked ‘implemented’ with no supporting evidence, or justified exclusions that the auditor considers indefensible given the organisation’s risk profile.
- 2. Untested business continuity and disaster recovery plans — documented plans that have never been exercised and cannot demonstrate recovery capability.
- 3. Access control reviews never conducted — user access lists that have never been formally reviewed, containing inactive accounts, over-privileged users, and former employees.
- 4. No supplier information security clauses — contracts with cloud providers, ISPs, and managed service providers that contain no information security requirements.
- 5. Incident response plan never activated — no incident log, no evidence the process has been used, no post-incident review records.
- 6. Management review documentation missing — no formal minutes, no evidence of management-level engagement with ISMS performance.
- 7. Risk register not maintained — a risk register produced for the audit but clearly not regularly updated, with risks that do not reflect the current threat landscape.
- 8. Staff unaware of security policies — employees unable to describe basic security responsibilities during auditor interviews.
Conclusion: Certification as a Business Enabler
ISO 27001 certification is not simply a compliance checkbox. For Nigerian businesses, it is a market differentiator that signals information security maturity to enterprise clients, international partners, and regulators alike. CBN-regulated institutions, oil majors, international NGOs, and government procurement frameworks increasingly mandate ISO 27001 certification as a baseline supplier qualification.
The preparation journey is demanding — typically six to eighteen months for organisations starting from a low baseline. But organisations that invest in building a genuine, operational ISMS find that the benefits extend well beyond the certificate: reduced incident frequency, faster breach detection, cleaner supplier relationships, and a security-aware workforce.
The Nigerian cybersecurity landscape is maturing rapidly. The NDPA 2023, the CBN CSOR Framework, and the NCC Cybersecurity Regulations all point in the same direction: evidence-based, risk-managed, continuously improved information security. ISO 27001 provides the internationally recognised framework to get there.
🚀 Ready to begin your ISO 27001 journey? Jackson Technology provides ISO 27001 gap assessments, ISMS implementation support, internal audit services, and penetration testing for Nigerian and African organisations. Contact us at info@jacksontechnology.com.ng to schedule a consultation.
About the Author
Jackson Godwin is a Cybersecurity Analyst and Penetration Tester with over four years of hands-on experience in VAPT, cloud security, GRC compliance, and ISO 27001 advisory. He leads cybersecurity initiatives at TechTrain Academy and provides enterprise security consulting through Jackson Technology, serving Nigerian and African organisations across banking, fintech, oil and gas, and the public sector.
Email: info@jacksontechnology.com.ng





