Back to Guides
Guide16 September 2026

What Is ISO 37301 and How Do You Implement a Certified Compliance Management System?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is ISO 37301 and why does it matter?
  3. How is ISO 37301 structured?
  4. What are the core requirement areas?
  5. How does ISO 37301 differ from ISO 19600?
  6. What steps should an organisation follow to implement ISO 37301?
  7. How to achieve certification?
  8. How does ISO 37301 integrate with other ISO standards?
  9. What are the benefits of ISO 37301 certification?
  10. Where can I find more detailed guidance?
  11. How often is ISO 37301 reviewed?
  12. Quick checklist for ISO 37301 readiness
  13. Conclusion

Key takeaways


What is ISO 37301 and why does it matter?

ISO 37301:2021 is the internationally recognised, certifiable standard for compliance management systems. It provides mandatory requirements (not just guidance) that help organisations systematically identify, assess, and treat compliance risks while demonstrating accountability to stakeholders.

The standard applies to all types of organisations - public, private, non - profit - regardless of size, sector, or activity. Adoption can improve governance, boost stakeholder trust, and align compliance with broader quality, risk, and anti - bribery initiatives.


How is ISO 37301 structured?

ISO 37301 follows the Annex SL high - level structure with ten clauses; clauses 4 - 10 contain the mandatory requirements. The clauses cover leadership, planning, support, operation, performance evaluation, and improvement. This uniform structure enables easy integration with other ISO management - system standards that use the same framework.


What are the core requirement areas?

ISO 37301 requires organisations to address eight key areas:

  1. Leadership & commitment - top - management must demonstrate responsibility for compliance.
  2. Compliance culture & governance - establish a culture that supports ethical behaviour.
  3. Compliance policy & objectives - document a policy and measurable objectives.
  4. Identification of compliance obligations & risk assessment - catalogue legal and other obligations and assess associated risks.
  5. Planning, resources, competence & communication - allocate resources, ensure staff competence, and communicate requirements.
  6. Operational controls, monitoring, incident handling - implement controls, monitor activities, and manage incidents.
  7. Performance measurement, internal audit, management review - measure performance, conduct audits, and review the CMS at management level.
  8. Continual improvement (PDCA cycle) - use the Plan - Do - Check - Act model to drive ongoing enhancement.

How does ISO 37301 differ from ISO 19600?

ISO 19600:2014 was a guidance - only document. ISO 37301 replaces it with a type - A requirements standard that uses “shall” language and allows organisations to obtain third - party certification from an accredited body.


What steps should an organisation follow to implement ISO 37301?

Implementation follows the PDCA cycle:

  1. Plan - Define the CMS scope, write a compliance policy, identify obligations, perform a risk assessment, and set objectives.
  2. Do - Establish processes, assign responsibilities, provide training, and deploy operational controls.
  3. Check - Monitor compliance performance, conduct internal audits, and review incidents and corrective actions.
  4. Act - Perform management review, implement corrective actions, and drive continual improvement.

Each step should produce documented evidence (policy statements, risk registers, audit reports) that auditors will review during certification.


How to achieve certification?

  1. Select an accredited certification body - examples include ANAB - accredited registrars such as TÜV NORD or other IAF - recognised bodies.
  2. Conduct a pre - assessment - internal or third - party gap analysis against ISO 37301 requirements.
  3. Address gaps - implement missing controls, update documentation, and train staff.
  4. Schedule the certification audit - the auditor will review the CMS documentation, interview staff, and observe processes.
  5. Obtain the certificate - upon successful audit, the body issues a certificate valid for three years, with surveillance audits annually.

How does ISO 37301 integrate with other ISO standards?

Because ISO 37301 uses the Annex SL framework, it aligns naturally with:

Integrating these systems reduces duplication, streamlines audits, and presents a unified governance, risk, and compliance (GRC) structure.


What are the benefits of ISO 37301 certification?


Where can I find more detailed guidance?


How often is ISO 37301 reviewed?

ISO 37301 is confirmed as the current version with no scheduled revision until the systematic review around 2029, unless an amendment is issued earlier.


Quick checklist for ISO 37301 readiness

AreaAction
Scope & policyDefine CMS scope, write a compliance policy, set objectives
Obligations & riskList legal/contractual obligations, perform risk assessment
LeadershipDocument top - management commitment and roles
Resources & competenceAllocate budget, train staff, assign responsibilities
Operational controlsImplement procedures, monitoring, incident handling
Performance & auditSet KPIs, schedule internal audits, conduct management review
ImprovementRecord corrective actions, plan continual improvement
CertificationChoose accredited body, complete pre - assessment, schedule audit

Conclusion

ISO 37301:2021 (with the 2024 amendment) offers a robust, certifiable framework for building a compliance management system that works for any organisation. By following the PDCA cycle, integrating with existing ISO systems, and engaging an accredited certification body, you can achieve certification that demonstrates systematic compliance, reduces risk, and strengthens stakeholder confidence.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary