Are you ISO 27001 certification-ready?
Eight scored questions on the foundations a certification body checks at Stage 1. Answer honestly — it takes about two minutes.
1. Do you have written information-security policies that employees have acknowledged?
2. Have you defined your ISMS scope — which systems, sites, and teams are in scope?
3. Do you review who has access to production systems and customer data?
4. Do you have a risk assessment and a Statement of Applicability (SoA)?
5. Is there a tested backup and disaster-recovery plan for critical systems?
6. Do you have an incident-response plan and know who runs it?
7. Have you run an internal audit of your ISMS in the last 12 months?
8. Do you assess the security of vendors that touch customer data?
A low score isn't a verdict — it's a work list. See the realistic ISO 27001 timeline and the cost guide to plan what comes next.
Ready or not, talk to CBs
A gap assessment with a matched CB tells you exactly what's missing — free quotes, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.