Let's talk
ISO-27001 Readiness Assessment

Know where you stand before taking on ISO 27001.

A customer has asked about ISO 27001, or you are considering certification. We review your existing security practices and evidence, then explain the main gaps and practical next steps.

Best fit

When it helps

When you need a clear starting point for ISO 27001 preparation, without losing sight of the business you are running.

  • A customer has asked about ISO 27001.

    The request creates work before you know exactly what is expected. You need to understand the requirement and what it means for your business.

    • Review the customer's request and the reason behind the assessment.
    • Clarify whether they require certification or another form of security assurance.
    • Define the preparation goal and record any requirements still to confirm.
  • You have good practices, but no clear view of readiness

    Your team may have sound security practices, useful records and capable people. It is harder to see how that work fits together and what preparation is still missing.

    • Review the practices, documents and evidence already available.
    • Identify useful work to retain and areas needing more attention.
    • Separate missing practices from missing evidence and unanswered questions.
  • There is no spare time to work through it.

    Product work, customers and daily operations keep taking priority. Even when your team knows the subject, bringing the current position together takes time you do not have.

    • Prepare the review and coordinate focused input from the relevant people.
    • Build on existing plans and previous findings.
    • Bring the findings into one summary with a clear order of priorities.
  • You need to judge the work before taking it on.

    Certification may support your plans, but preparation has to fit around the business. You need to see the main work involved and the decisions that would shape it.

    • Outline the main gaps, dependencies and preparation tasks.
    • Identify decisions about scope, people and specialist input.
    • Set out practical next steps and where a deeper assessment would add value.
Scope & deliverables

A clear starting point for preparation.

We agree your goal and the areas to review, then assess your existing practices and available evidence. You receive the main findings, priorities and a practical route forward.

What's included

Review what is already in place.

  • Clarification of your preparation goal, customer requirements and assessment scope.
  • Review of selected security practices, working documents and available records.
  • Discussions with relevant people to understand how the business works.
  • Identification of the main gaps, dependencies and decisions still needed.
  • Prioritization of next steps and a walkthrough of the findings.
What you receive

Findings you can plan around.

  • A readiness summary showing the preparation goal and current position.
  • Main gaps and useful existing work, linked to the information reviewed.
  • Prioritized preparation actions, with dependencies and decisions explained.
  • A coverage summary recording assumptions, unanswered questions and areas needing deeper review.
Out of scope

Beyond assessing your starting position.

Any further work is optional and agreed separately.

  • A detailed requirement-by-requirement gap assessment, independent internal audit or certification audit.
  • Setting up the management system, writing policies or implementing security improvements.
  • Preparing an audit evidence pack, completing customer questionnaires or ongoing security management.
Process

How it works

We organize the assessment and bring the findings together. Your team contributes the business context, existing information and decisions that shape the next steps.

  1. Agree the goal and scope

    We clarify why you are preparing, the requirements you are working towards and what to review. We agree price, timing, relevant contacts and the information needed before starting.

  2. Review your existing work

    We examine the selected practices, documents and records, then speak with the people who know them. We build on useful work already completed and clarify any gaps in the available information.

  3. Bring the priorities into focus

    We bring together the main findings and order the preparation actions around your goal, the gaps and their dependencies. We make assumptions and decisions still needed visible.

  4. Walk through the way forward

    We explain the findings and recommended next steps with your team. You receive a clear record of what was reviewed, what remains uncertain and where further work may be useful.

Get in touch

Need a clearer starting point?

An informal 30-minute call to discuss what is prompting your ISO 27001 preparation and see whether a Readiness Assessment is the right fit.