Skip to main content
ISO27001

What is the PDCA Cycle? The Complete Guide for ISO 27001 & BSI IT-Grundschutz

The PDCA cycle forms the methodological foundation for continuous improvement in ISO 27001 and BSI IT-Grundschutz. Learn how this iterative four-step approach systematically optimizes your information security and creates a culture of continuous development.

Srdan Manasijevic

Srdan Manasijevic

CEO

What is the PDCA Cycle? The Complete Guide for ISO 27001 & BSI IT-Grundschutz

Introduction

At the core of ISO 27001 and BSI IT-Grundschutz lies a simple but powerful approach to continuous improvement: the Plan–Do–Check–Act (PDCA) cycle. Also known as the Deming cycle, it is a systematic four-step model for problem solving and process improvement.

The PDCA cycle starts with the Plan phase, where a problem or opportunity for improvement is identified and a plan is created. In the Do phase, this plan is implemented. During the Check phase, results are evaluated and compared to the original objectives. In the Act phase, corrective actions and improvements are derived and standardised. The cycle then starts again – enabling continuous improvement.

PDCA is a key element in:

  • ISO 27001 – the international standard for information security management systems (ISMS)

  • BSI IT-Grundschutz – the German baseline security standard

By applying PDCA, organisations can systematically improve their information security and stay aligned with ISO 27001 and BSI IT-Grundschutz.


Key Takeaways

  • Structured improvement model: PDCA provides a clear framework for continuous improvement of processes and systems.

  • Core method in ISO 27001 & BSI IT-Grundschutz: It forms the methodological backbone of information security management in both international and national standards.

  • Iterative cycle: The four phases – Plan, Do, Check and Act – drive ongoing adjustment and optimisation based on measurable results.

  • Engagement & quality assurance: The model promotes staff involvement, improves quality and reduces errors and inefficiencies.


What Is the PDCA Cycle?

The PDCA cycle (Deming cycle) is an iterative management model for continuous improvement. It consists of four phases:

  1. Plan

  2. Do

  3. Check

  4. Act

Organisations use the model to continuously monitor, analyse and improve their processes, aiming to increase quality, efficiency and customer satisfaction.


Phase 1: Plan

The Plan phase lays the foundation for the entire cycle.

Typical activities:

  • Identify issues, risks or improvement opportunities

  • Analyse the current situation (audits, KPIs, interviews, process data)

  • Define clear objectives and target values

  • Analyse causes and derive hypotheses

  • Develop a concrete action plan (who, what, by when, with which resources?)

  • Define KPIs and benchmarks to measure success

A solid Plan phase ensures that everyone understands the goals, roles and responsibilities and that the next steps are based on valid assumptions.


Phase 2: Do

The Do phase is where the plan is implemented.

Typical activities:

  • Implement planned measures (controls, process changes, new tools)

  • Run pilots or tests (proof of concept)

  • Train staff involved in the process

  • Document execution and deviations

  • Collect data for evaluation in the Check phase

Do is not just “doing things” – it is controlled implementation with documentation, so that later analysis is meaningful.


Phase 3: Check

In the Check phase, the effectiveness of the measures is evaluated.

Typical activities:

  • Compare actual vs. target values

  • Analyse performance indicators and reports

  • Conduct quality checks and effectiveness reviews

  • Gather feedback from employees, stakeholders or customers

  • Identify deviations, causes and lessons learned

If results do not meet expectations, root causes must be analysed. If objectives are achieved, success factors become visible and can be used in the Act phase.


Phase 4: Act

The Act phase translates insights from Check into decisions and adjustments.

Typical activities:

  • Standardise effective measures (policies, processes, SOPs)

  • Correct or replace ineffective measures

  • Document lessons learned

  • Set new or refined objectives for the next PDCA cycle

This creates a learning organisation: every cycle improves maturity and resilience.


PDCA in ISO 27001

ISO 27001 uses PDCA as the underlying model for the information security management system.

  • Plan: Context analysis, risk assessment, definition of information security objectives and controls (Statement of Applicability, ISMS plan).

  • Do: Implementation of controls, processes, responsibilities and security policies.

  • Check: Internal audits, monitoring, metrics, management reviews, non-conformity analysis.

  • Act: Corrective and improvement actions, updates to risk treatment and documentation.

Through repeated PDCA cycles, the ISMS is continuously adapted to new threats and changes in the organisation.


PDCA in BSI IT-Grundschutz

BSI IT-Grundschutz also relies on PDCA, focusing on a structured security process.

  • Plan: Define security objectives, scope, perform structure analysis and protection needs assessment, select BSI modules and measures.

  • Do: Implement the selected measures, establish processes and responsibilities, document the security concept.

  • Check: Perform Grundschutz checks, monitor effectiveness, analyse gaps and deviations.

  • Act: Adjust measures, update the security concept and documentation, close identified gaps.

PDCA ensures that information security is not a one-time project but a continuous management discipline.


Benefits of the PDCA Cycle

  • Clear structure for continuous improvement and problem solving

  • Increased process efficiency and quality

  • Reduced errors and waste

  • Stronger culture of responsibility and learning

  • Better auditability and compliance capability


Challenges in Practice

Common obstacles:

  • Lack of management commitment

  • Insufficient understanding of PDCA

  • Poor or incomplete data

  • Resistance to change

Mitigation approaches:

  • Training & awareness

  • Transparent communication of goals and benefits

  • Proper tools for data collection and analysis

  • Active involvement of staff in all phases


Step-by-Step to a Certifiable ISMS (with fuentis)

With the fuentis ISMS tool, PDCA becomes operational:

  • Multi-compliance ISMS A full ISMS solution guiding you to ISO 27001 certification while also covering BSI IT-Grundschutz, TISAX® or NIS2.

  • Automated processes Guided and automated workflows that lead you step by step through implementation and certification – even without prior ISMS expertise.

  • Review questionnaires Simple, customisable questionnaires to determine protection needs and assess risks quickly and transparently.

  • Personal support Experienced consultants support you from the first gap analysis all the way to audit preparation.


Conclusion

The PDCA cycle is an essential instrument for continuous improvement in information security. Its use in ISO 27001 and BSI IT-Grundschutz demonstrates its effectiveness and flexibility.

By applying PDCA consistently, organisations can:

  • systematically plan and control security measures

  • continuously improve their ISMS

  • adapt to evolving risks and threats

  • foster a culture of ongoing improvement

Srdan Manasijevic

Srdan Manasijevic

CEO

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.