Skip to main content
Informationssicherheit / NIS2

PDCA cycle

The PDCA cycle (Plan-Do-Check-Act) is the four-stage feedback loop used to plan, implement, review and continually improve an information security management system.

The PDCA cycle traces back to the statistician Walter A. Shewhart and was popularised by W. Edwards Deming as a model of continual improvement. It describes a control loop with four stages: "Plan" establishes the organisational context, interested parties, scope, risks and objectives and derives controls from them; "Do" introduces and operates the planned controls, policies and processes; "Check" uses metrics, internal audits and the management review to verify whether the controls are effective and the objectives are being met; "Act" corrects deviations, removes root causes and feeds improvements back into the next iteration. For an ISMS this loop is the actual engine. Without it, information security remains a one-off project; with it, it becomes a permanently managed process.

The cycle is deeply embedded in the standards, even though ISO/IEC 27001:2022 no longer prescribes the term PDCA explicitly. The harmonised structure shared by management system standards still follows it clearly: clauses 4 to 6 (context of the organisation, leadership, planning including risk assessment and risk treatment) form the Plan stage, clauses 7 and 8 (support, operation) the Do stage, clause 9 (performance evaluation with monitoring, measurement, internal audit and management review) the Check stage, and clause 10 (improvement, covering nonconformity and corrective action as well as continual improvement) the Act stage. The German BSI Standard 200-1 likewise describes the security process as a lifecycle of planning, implementation, effectiveness review and optimisation. Crucially, the cycle does not only run at the level of the ISMS as a whole: smaller loops apply per control, per security incident and per risk.

Supervisory law thinks in control loops too. Article 21 of the NIS2 Directive (EU) 2022/2555 requires an all-hazards, risk-based approach and, in paragraph 2(f), explicitly names policies and procedures to assess the effectiveness of cybersecurity risk-management measures — precisely the Check stage. The German transposition in the BSIG (NIS2UmsuCG) obliges the management body to approve the measures and to supervise their implementation; in practice the timetables for individual registration and evidence duties are still moving, so specific deadlines should always be checked against the current legal status. In day-to-day work the PDCA cycle rarely fails at Plan and Do, but at weak Check and Act stages: audits are carried out, yet findings are never closed out with a root-cause analysis and dated corrective actions. A robust cycle therefore needs named owners, a fixed cadence, measurable ISMS metrics and a documented feedback path into the next planning round.

Legal Basis

ISO/IEC 27001:2022, clauses 4–10, in particular 9.1–9.3 and 10.1–10.2; ISO/IEC 27002:2022; BSI Standard 200-1; Art. 21(2)(f) NIS2 Directive (EU) 2022/2555; Sections 30 and 38 BSIG (German NIS2 Implementation Act)

Practical Example

A mechanical engineering company with 600 employees qualifies as an important entity under NIS2 and runs an ISMS certified to ISO/IEC 27001. The information security officer paces the cycle annually. In the Plan stage she updates the risk assessment after a new remote maintenance access for production machinery is introduced and derives two objectives: multi-factor authentication for all external access, and a 95 percent patch rate for critical vulnerabilities within 14 days. In the Do stage the controls are implemented, supplier contracts are amended and staff are trained. In the Check stage the internal audit and the metrics show that MFA is in place, but the patch rate reaches only 78 percent because machine PCs on the production network can only be updated during maintenance windows. In the Act stage the root cause is documented, an additional quarterly maintenance window is approved and network segmentation is strengthened as a compensating control; the management review releases the resources, and the objective moves into the next iteration with an adjusted measurement method.

FAQ

The 2022 edition of ISO/IEC 27001 no longer names PDCA as a prescribed model. All elements of the loop remain mandatory, however: planning and risk treatment, operation, monitoring and measurement, internal audit, management review, corrective action and continual improvement. Anyone meeting those requirements is effectively running a PDCA cycle, whatever they choose to call it.
The standard sets no fixed period; it requires internal audits and management reviews at planned intervals. In practice an annual full cycle has become the norm, matching the certification logic with yearly surveillance audits. For highly critical areas, after serious security incidents or after major changes, additional shorter loops are advisable.
Usually in the Act stage: audit findings and metrics exist, but they are never translated into root-cause analyses, dated actions and clear ownership. The cycle then degenerates into reporting without any steering effect. A central action register with deadlines and owners, tracked consistently through the management review, is the standard remedy.

How preeco supports you

Learn how our software supports you with this topic.

Learn more