An ISO 27001 readiness assessment is the honest audit you run on yourself before a certification body runs one on you. It answers one question: if a Stage 2 auditor walked in on Monday, what would they write up? Done properly it is not a questionnaire and not a sales exercise. It is a structured walk through Clauses 4 to 10 and the 93 Annex A controls, scoring each one against the evidence you can actually produce today.
Most organisations skip it, book the audit, and discover the answer the expensive way. The pattern is consistent: the technical controls are in reasonable shape, and the management system around them barely exists. There is no scope statement anyone agrees on, no Statement of Applicability, no internal audit, and no management review. Those are not technical gaps. They are the four findings that stop a certificate being issued.
This checklist is what a working ISO 27001 readiness assessment looks like. It covers the mandatory clause requirements, the four Annex A themes, the documented information an auditor will ask for by name, a scoring method that produces a remediation plan rather than a spreadsheet, and the seven gaps that turn up in almost every first assessment. It also sets out how long each gap realistically takes to close, because the output of a readiness assessment is a date, not a score.
If you are still deciding whether the standard is the right target at all, read our comparison of Cyber Essentials Plus and ISO 27001 first, and the breakdown of ISO 27001 certification cost for UK SMEs second. This guide assumes you have chosen the standard and want to know how far away you are.
Table of contents
- What an ISO 27001 Readiness Assessment Actually Is
- The ISO 27001 Readiness Assessment Checklist for Clauses 4 to 10
- Scoring the Annex A Controls in Your ISO 27001 Readiness Assessment
- How to Score an ISO 27001 Readiness Assessment Without Fooling Yourself
- The Documented Information an ISO 27001 Readiness Assessment Must Find
- Seven Gaps Every ISO 27001 Readiness Assessment Uncovers
- Turning an ISO 27001 Readiness Assessment Into a Certification Plan
- Running the ISO 27001 Readiness Assessment In-House or Buying It In
- What an ISO 27001 Readiness Assessment Will Not Tell You
- ISO 27001 Readiness Assessment Questions Answered
- References
What an ISO 27001 Readiness Assessment Actually Is
The definition that matters
A readiness assessment measures the distance between your current state and a certifiable information security management system. It produces three things: a scored position against every mandatory requirement, a prioritised remediation plan with owners and effort estimates, and a defensible target date for Stage 1. Anything that produces only the first of those three is a gap analysis wearing a better name.
Where it sits in the timeline
The assessment belongs at the very start, before you buy tooling, appoint a consultant or approach a certification body. Running it first is the single cheapest decision in the whole programme, because it converts an unknown budget into a scoped one. Run it last and you are paying a certification body day rate to tell you what a spreadsheet could have told you in week one.
Why it is not the same as Stage 1
Stage 1 is a formal audit performed by your certification body. It is chargeable, it is minuted, and its findings sit on your file. An ISO 27001 readiness assessment is internal, unminuted and free to fail. That difference is the entire point: you want the bad news somewhere it costs you nothing.
| Activity | Who runs it | Covers | Typical effort | Findings go on file |
|---|---|---|---|---|
| Readiness assessment | You or an adviser | Clauses 4–10 plus all 93 Annex A controls | 3–10 days | No |
| Gap analysis | You or an adviser | Usually Annex A controls only | 1–3 days | No |
| Internal audit (Clause 9.2) | Independent internal auditor | The ISMS as operated, against the standard | 3–8 days | Yes — auditors read it |
| Stage 1 audit | Certification body | Documentation and readiness for Stage 2 | 1–2 days | Yes — chargeable |
| Stage 2 audit | Certification body | Effectiveness of the whole ISMS | 2–6 days | Yes — decides the certificate |
What a good assessment output looks like
A useful ISO 27001 readiness assessment ends with a remediation register: every gap as a row, with a clause or control reference, an owner, an effort estimate in days, a dependency, and a target week. Colour-coded dashboards are fine as a summary, but the register is the deliverable. If the report you receive cannot be handed straight to a project manager, it has not finished the job.
The ISO 27001 Readiness Assessment Checklist for Clauses 4 to 10
Clauses 4 to 10 are the mandatory requirements. Annex A controls can be excluded with justification; these cannot. This is where most first-time programmes fail, so score them before you look at a single technical control.
Clause 4 — Context of the organisation
Confirm you have a documented scope statement naming the services, locations, people and information systems inside the ISMS, and — critically — what sits outside and why. List your interested parties and their information security requirements: customers, regulators, insurers, staff, shareholders. Auditors open here, and a vague scope contaminates everything downstream.
Clause 5 — Leadership
You need a signed information security policy, evidence that top management has assigned roles and responsibilities, and something that demonstrates active involvement rather than a signature block. Minutes showing security discussed at board or senior management level are the cheapest proof. Your ISO 27001 readiness assessment should record who owns the ISMS by name and job title.
Clause 6 — Planning
This is the heaviest clause. You need a documented risk assessment methodology, a completed risk assessment, a risk treatment plan, a Statement of Applicability covering all 93 Annex A controls with inclusion or exclusion justified, and measurable information security objectives. The 2022 revision also expects planned changes to the ISMS to be handled deliberately rather than ad hoc.
Clause 7 — Support
Score resources, competence, awareness, communication and documented information control. In practice: a training record showing who has been trained on what and when, a competence matrix for security roles, and version control on your policies. A policy set with no revision history is a finding waiting to happen.
Clause 8 — Operation
Demonstrate that risk assessments and treatment are actually performed on the planned schedule, not just designed. You also need control over outsourced processes, which is where most SMEs discover their supplier list is incomplete. An ISO 27001 readiness assessment that skips supplier records will understate your remediation effort badly.
Clause 9 — Performance evaluation
Three separate requirements: monitoring and measurement of the ISMS, a full internal audit programme with results, and a documented management review covering the specific inputs the standard lists. You need at least one complete internal audit and one management review before Stage 2. Both take calendar time you cannot compress.
Clause 10 — Improvement
You need a nonconformity and corrective action process, plus records showing it has been used. An empty corrective action log is not evidence of a perfect year; auditors read it as evidence the process is theoretical. Raise and close a few real nonconformities during the build phase deliberately.
Clauses 6 and 9 score worst almost every time, and they are also the two that take longest to fix. That combination is why a realistic ISO 27001 readiness assessment usually lands the certificate six to twelve months out rather than three.
Scoring the Annex A Controls in Your ISO 27001 Readiness Assessment
ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes, replacing the 114 controls in 14 domains that the 2013 version used. If you are working from an older checklist, it is measuring the wrong thing.
Organisational controls (37)
The largest theme and the one that carries the most documentation. It covers policies, roles, segregation of duties, supplier and cloud service security, threat intelligence, incident management planning, business continuity and legal compliance. Controls 5.7 (threat intelligence) and 5.23 (information security for use of cloud services) were new in 2022 and are routinely missed.
People controls (8)
Screening, terms of employment, awareness and training, disciplinary process, responsibilities after termination, confidentiality agreements, remote working and reporting of security events. Small, but heavy on evidence — every one of these needs a record per person, not a policy statement.
Physical controls (14)
Perimeters, entry controls, securing offices, monitoring, protection against environmental threats, clear desk and clear screen, equipment siting, off-site assets, storage media and secure disposal. Fully remote organisations still score this theme; the answer is home working and cloud data centre inheritance, documented, not an exclusion.
Technological controls (34)
Endpoints, privileged access, information deletion, data masking, data leakage prevention, backup, logging, monitoring activities, web filtering, secure coding, configuration management and secure development. This theme usually scores best on capability and worst on evidence — the control exists in the product, and nothing records that anyone checks it.
The eleven controls introduced in 2022
Threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Score these explicitly. An ISO 27001 readiness assessment built on a 2013 control set will look healthy and still fail Stage 2 on the eleven it never asked about.
How to Score an ISO 27001 Readiness Assessment Without Fooling Yourself
Use a maturity scale, not a yes/no
Binary scoring hides the difference between “we have a policy” and “we do this and can prove it”. A five-point scale works: 0 nothing exists, 1 informal or undocumented practice, 2 documented but not operating, 3 operating but not evidenced, 4 operating and evidenced, 5 measured and improved. Certification needs a consistent 4, not a scattering of 5s.
Score against evidence, not intention
The discipline that makes an ISO 27001 readiness assessment worth doing is refusing to score anything above 2 without seeing the artefact. Not a description of the artefact — the artefact. If nobody can produce the access review record inside ten minutes, it scores 2, however certain the team is that reviews happen.
Weight the mandatory clauses separately
Report clause conformity and Annex A conformity as two numbers. Averaging them produces a comfortable middle figure that conceals the fact that Clause 9 is at zero. A single blended percentage is the most common way an ISO 27001 readiness assessment misleads the people who commissioned it.
Convert every gap into days
Each row in the remediation register needs an effort estimate and a dependency. A missing risk assessment is not one gap; it blocks the Statement of Applicability, the risk treatment plan, and half of Clause 8. Sequencing matters more than volume, and only the register shows it.
| Score | Meaning | What the auditor sees | Certifiable |
|---|---|---|---|
| 0 | Nothing exists | Major nonconformity | No |
| 1 | Informal practice, undocumented | Major nonconformity | No |
| 2 | Documented, not operating | Minor or major, depending on clause | No |
| 3 | Operating, no records | Minor nonconformity | Usually not |
| 4 | Operating and evidenced | Conformity | Yes |
| 5 | Measured and improved | Conformity, often an observation of good practice | Yes |
The Documented Information an ISO 27001 Readiness Assessment Must Find
The standard names specific documented information. These are the items an auditor will ask for by name, and the fastest way to run this part of the checklist is to try to open each one.
The documents
Scope of the ISMS. Information security policy. Risk assessment process. Risk treatment process. Statement of Applicability. Risk treatment plan. Information security objectives. Any documented information you have determined is necessary for ISMS effectiveness.
The records
Evidence of competence. Results of the risk assessment. Results of risk treatment. Evidence of monitoring and measurement results. The internal audit programme and its results. Evidence of the management review. Evidence of nonconformities and subsequent corrective actions.
The one people forget
The Statement of Applicability is the document auditors use to navigate everything else, and it is the one most often missing at readiness stage. It must list all 93 Annex A controls, state whether each is applicable, justify inclusion and exclusion, and record implementation status. Producing it is a genuine week of work.
Operating records beat perfect documents
A frequent misread of an ISO 27001 readiness assessment result is that a high documentation score means you are close. You also need the ISMS to have been running long enough to have produced records — typically at least three months of logs, reviews, tickets and meeting minutes before Stage 2 is worth booking.
Seven Gaps Every ISO 27001 Readiness Assessment Uncovers
1. Scope that nobody has written down
Everyone assumes the scope is “the whole company” until you ask about the legacy subsidiary, the development environment or the acquisition. Write the boundary, then check it against your asset and supplier lists.
2. No Statement of Applicability
Common when a programme starts with tooling. Platforms produce control status dashboards, which look like a Statement of Applicability and are not one — the justification column is what the auditor reads.
3. Risk assessment without a method
A risk register exists; the documented methodology that says how risks are identified, analysed, evaluated and re-evaluated does not. Clause 6.1.2 requires the method, and a register with no method behind it is a major finding.
4. Supplier security that stops at the contract
Cloud and outsourced services are in scope under 5.19 to 5.23. You need a supplier list, security requirements per supplier, and evidence of monitoring. Our guidance on Cyber Essentials for suppliers covers the contract wording side of this.
5. Access reviews that happen informally
Privileged access is usually controlled and almost never reviewed on a documented schedule. The NCSC 10 Steps to Cyber Security identity and access guidance is a reasonable baseline for what the review should cover.
6. No internal audit and no management review
The two Clause 9 requirements that cannot be bought, borrowed or accelerated. They need an independent auditor, a schedule, and a meeting with the right inputs and attendees. Budget six to eight weeks.
7. Awareness training with no records
Training happened. The record of who attended, when, and what was covered does not exist. This is the cheapest gap on the list to fix and the one most often left until the week before Stage 2.
Turning an ISO 27001 Readiness Assessment Into a Certification Plan
Fix the blockers before the breadth
Scope, risk methodology and the Statement of Applicability gate almost everything else. Close them in weeks one to four regardless of how many Annex A controls are showing amber, because control remediation you do before the scope is settled is work you may repeat.
Start the Clause 9 clock early
Internal audit and management review cannot be done retrospectively with any credibility. Schedule both the moment the ISMS is documented, even if controls are still being implemented. This single sequencing decision typically pulls four to six weeks out of the programme.
Let the ISMS run before booking Stage 2
Certification bodies want to see the system operating, not just designed. Three months of live records is a sensible floor. Booking Stage 2 for the week after remediation finishes is the most common self-inflicted delay in the whole process.
Re-run the assessment before you book
A second ISO 27001 readiness assessment, run against evidence four to six weeks before Stage 1, is the cheapest insurance available. It costs a few days and it is the difference between a clean audit and a corrective action plan.
Running the ISO 27001 Readiness Assessment In-House or Buying It In
In-house
Cheapest in cash and most expensive in calendar time. It works when someone internal has audited against a management system standard before. It fails when the assessor is the same person who built the controls, because self-scoring against your own work is not an independent view.
Consultant-led
A specialist runs interviews and evidence sampling and produces the register. Faster and genuinely independent, and the report carries weight with a board that has been told everything is fine. The risk is a generic report that maps controls without touching your actual evidence.
Platform-led
Compliance platforms score continuously against connected systems. Excellent for technological controls and ongoing monitoring, weak on Clauses 4, 5 and 9, which are about governance rather than configuration. Treat the platform score as one input to the ISO 27001 readiness assessment, not the assessment itself.
| Route | Indicative cost | Elapsed time | Strongest on | Weakest on |
|---|---|---|---|---|
| In-house | Staff time only | 4–8 weeks | Context and business knowledge | Independence and standard fluency |
| Consultant-led | £3,000–£9,000 | 2–4 weeks | Clause conformity and audit realism | Cost, and generic templates |
| Platform-led | £4,000–£15,000 per year | Days to connect | Technological controls, monitoring | Clauses 4, 5 and 9 governance |
| Hybrid | £5,000–£12,000 plus platform | 3–5 weeks | Coverage across all four themes | Coordination overhead |
The pragmatic answer for most SMEs
Run a structured self-assessment first to establish rough position and build internal understanding, then buy two or three days of independent review to challenge the scores. That combination costs a fraction of a full consultant-led ISO 27001 readiness assessment and catches the optimism that self-scoring always introduces. Organisations already working with a managed IT services provider should check what evidence that provider can supply directly, because a good chunk of the technological theme may already be documented on your behalf.
What an ISO 27001 Readiness Assessment Will Not Tell You
Whether your auditor will agree
Auditors interpret. Two competent assessors can score the same control differently, particularly around scope exclusions and the sufficiency of evidence. A readiness assessment reduces surprise; it does not eliminate it.
Whether your controls actually work
Conformity and effectiveness are different questions. A documented, operating, evidenced backup process scores 4 and can still fail when restored. Penetration testing and restore testing sit alongside the assessment, not inside it. The NCSC risk management guidance is a better lens for that question than any conformity checklist.
Whether the scope is commercially right
Narrowing scope makes certification faster and cheaper, and can also produce a certificate your customers do not accept because it excludes the service they buy. That is a commercial judgement the assessment can inform but not make.
What the certificate will cost
A readiness assessment tells you the remediation effort. Certification body fees are driven by audit days, headcount and scope complexity, which is a separate calculation covered in our ISO 27001 certification cost guide. If artificial intelligence systems are in scope, ISO 42001 may be worth assessing at the same time.
ISO 27001 Readiness Assessment Questions Answered
How long does an ISO 27001 readiness assessment take?
Three to ten working days of assessor effort, spread across two to four weeks of calendar time to allow for interviews and evidence collection. A 20-person single-site organisation sits at the lower end; a multi-site business with several product lines at the upper.
Can we run one before we have any policies?
Yes, and it is often the right moment. An assessment against nothing produces a clean build plan rather than a remediation list, and it stops you buying a policy template pack you will have to rewrite.
What score means we are ready for Stage 2?
Full conformity on Clauses 4 to 10, no Annex A control below 3, and at least three months of operating records. A percentage figure is not a threshold — a single missing internal audit is enough to stop certification at 95%.
Does a Cyber Essentials certificate help?
It contributes evidence to parts of the technological theme and demonstrates baseline control, but it covers five control areas rather than a management system. The overlap is useful and small. Our guide to Cyber Essentials failure reasons explains where those controls typically break down.
Should the assessment cover the 2013 or 2022 control set?
2022, without exception. The transition period for ISO/IEC 27001:2013 certificates has closed, so any assessment mapping to the old 114 controls is measuring against a superseded structure.
Who should run it internally?
Someone independent of the controls being assessed, with authority to ask for evidence and record that it was not produced. In a small business that is often a finance or operations lead rather than the IT manager, precisely because they will not accept “we do that” as an answer.
Do we need a consultant for Stage 1 preparation?
Not necessarily. What you need is an honest ISO 27001 readiness assessment and the discipline to work the register. Consultants add most value on risk methodology and the Statement of Applicability, and least on tasks your own team can do faster.
How often should we repeat it?
Once before you build, once four to six weeks before Stage 1, and thereafter the internal audit programme takes over. Post-certification, Clause 9.2 supersedes the readiness assessment as your ongoing check.
What is the single biggest predictor of failing Stage 2?
No completed internal audit and management review. It is the most common cause of a delayed certificate, and it is entirely avoidable with eight weeks of notice. For a wider view of security posture beyond the standard, see our IT security services.