Free resource
If you already run PCI DSS, most evidence carries over. Map each PCI area to ISO 27001 Annex A, mark what is reusable, and focus on the genuine ISO-specific gaps.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A crosswalk for teams who already run PCI DSS. Most PCI evidence carries straight over to ISO 27001 - this shows what is reusable and isolates the genuinely ISO-only work so you do not rebuild evidence twice. |
| How to read 'Reusable?' | Yes = the PCI artifact works for ISO with, at most, a scope widening. Partial = it covers the cardholder environment but ISO needs the whole ISMS scope. No = PCI has no equivalent; this is net-new ISO work. |
| The #1 mistake | Assuming PCI equals ISO. The three management-system clauses (risk-based SoA, internal audit, management review) have no PCI equivalent, and are where PCI-strong teams still fail Stage 2. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: PCI to ISO
Map each PCI area to ISO 27001, mark what is reusable, and focus effort on the genuine ISO-specific gaps at the bottom. The last column tells you what still needs doing even where evidence carries over.
| PCI DSS area | Existing PCI evidence | Maps to ISO 27001 (Annex A / clause) | Reusable? (Yes/Partial/No) | ISO-specific gap / what still needs work |
|---|---|---|---|---|
| Access control (Req 7-8) | Access reviews, least privilege | A.5.15-A.5.18 access control | Yes | Reuse as-is; widen scope beyond the cardholder environment to the whole ISMS |
| Change management (Req 6) | Change records, approvals | A.8.32 change management | Yes | Reusable; make sure non-payment systems in ISMS scope are covered too |
| Key management (Req 3) | Key lifecycle, rotation | A.8.24 use of cryptography | Yes | Reusable; add a documented cryptographic policy if PCI only gave you procedures |
| Logging (Req 10) | Log retention, review | A.8.15-A.8.16 logging and monitoring | Yes | Reusable; ISO wants evidence the logs are reviewed, not just retained |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources