Skip to content

ISO/IEC 27001 Readiness Assessment

Evaluate your information-security management system, control environment and evidence before accredited certification activities.

What we review

  • Organizational context
  • Leadership and accountability
  • Information-security objectives
  • Risk assessment and treatment
  • Policies
  • Asset management
  • Access control
  • Supplier security
  • Incident management
  • Business continuity
  • Technical security controls
  • Internal governance
  • Monitoring
  • Evidence and documentation

Deliverables

  • Readiness summary
  • Gap register
  • Prioritized remediation plan
  • Evidence-readiness checklist
  • Management briefing

Frequently asked questions

Can you certify us to ISO/IEC 27001?

No. Readiness and consulting services do not constitute accredited ISO/IEC 27001 certification. Certification is performed by an appropriately accredited certification body.

What do we receive?

A readiness summary, a gap register, a prioritized remediation plan, an evidence-readiness checklist and a management briefing.

Do you review the ISMS as well as technical controls?

Yes. The review covers organizational context, leadership, objectives, risk assessment and treatment, policies and governance alongside technical security controls.

We answer customer security questionnaires. Does this help?

Readiness work organizes control ownership, evidence and documentation, which is the same material customer assurance and enterprise sales reviews depend on.

Discuss the scope of your assessment

Tell us what you need to assess, your target timeline and the environment involved. We will review the scope and identify the appropriate next step.

Page last reviewed 6 September 2026