ISO 27001 is the international standard for information security management systems, or ISMS. A readiness assessment helps CEOs, compliance leaders and security teams understand what already works, what evidence exists and what needs to close before certification.

This is not a substitute for an external audit or a promise of certification. It is a practical way to assess whether the ISMS is defined, operating and supported by evidence before inviting a certification body to review it.

At PrivaLex, we use readiness assessments to help teams turn ISO 27001 requirements into a realistic implementation plan. The aim is to identify material gaps early, assign ownership and avoid discovering missing evidence during the certification process.

Work through each area and rate every item as complete, partial or not started. For every complete item, name the evidence and the person responsible. If the team cannot identify the policy, record, system setting or meeting minute that proves the item, mark it partial until the evidence is available.

Use a single action log to record the gap, owner, due date, priority, remediation action and evidence location. This prevents the checklist from becoming another document that is completed once and then ignored.

  • Ready to validate: most items are complete, evidence is current and the ISMS has already operated through an internal audit and management review.
  • Partially ready: the core system exists, but material gaps remain in control operation, evidence, ownership or improvement activities.
  • Not ready: the scope, risk method, control selection or management-system foundations are not yet established.

The score should start a conversation, not replace judgement. A single high-risk gap, such as no risk treatment plan, no internal audit or no management review, can block readiness even if many other items are complete.

Understand What ISO 27001 Certification Assesses

ISO 27001 is not a one-off security audit. It assesses whether an organisation operates a structured, auditable and continually improving ISMS. The management-system requirements sit in clauses 4 to 10 of ISO/IEC 27001:2022. Annex A contains a reference set of 93 controls that the organisation considers through its risk-treatment process.

Certification is issued by an independent external certification body. PrivaLex can support implementation, readiness and preparation, but we do not certify our own clients.

Certification can strengthen trust with clients, partners and investors, support enterprise procurement and help organise security risk management. A well-run ISMS can also support overlapping work under NIS2, GDPR and other frameworks. It does not automatically prove compliance with those laws: each legal obligation still requires its own assessment and evidence.

PrivaLex helps organisations avoid creating separate compliance projects for every framework. Where requirements overlap, we map shared controls and evidence into one operating programme while keeping the framework-specific obligations visible.

Confirm the ISMS Scope and Leadership Ownership

Before reviewing controls, confirm that the ISMS boundary is clear and defensible.

  • The ISMS scope identifies the legal entities, locations, services, systems, people and suppliers included.
  • Exclusions are documented and justified, especially where customers or regulated services are involved.
  • Internal and external issues, interested parties and relevant requirements are recorded.
  • Top management has approved the scope, information-security policy, objectives and responsibilities.
  • Security roles have authority, budget and time to carry out their responsibilities.

Evidence to prepare: scope statement, context and interested-party record, organisational chart or RACI, approved policy, security objectives and management meeting minutes.

In PrivaLex readiness work, scope is one of the first areas we test because it affects every later decision: which assets enter the risk assessment, which suppliers require review, which controls apply and what the certification body will sample.

Build a Consistent Risk Process

The risk process must be consistent and repeatable. ISO 27001 does not prescribe one scoring method, but the organisation must define risk criteria, assess risks using that method and decide which risks it will treat or accept.

  • Risk-assessment and acceptance criteria are documented.
  • Assets, processes, threats, vulnerabilities and relevant impacts are identified within scope.
  • Each material risk has an owner, inherent rating, existing controls, treatment decision and residual-risk decision.
  • A treatment plan assigns actions, owners, deadlines and required evidence.
  • Residual risks outside the organisation’s acceptance criteria have management approval or further treatment.

Evidence to prepare: risk methodology, risk register, treatment plan, risk-acceptance records and action tracker.

A structured ISO 27001 risk assessment makes this process easier to follow and audit. PrivaLex facilitates risk workshops with the people who understand the systems and business impact, then helps turn the results into an actionable treatment plan rather than a static spreadsheet.

Review the Statement of Applicability

The Statement of Applicability, or SoA, is the bridge between risk decisions and controls. It should identify applicable Annex A controls, justify inclusions and exclusions, and show whether each control is implemented. It should also include any necessary controls that are not in Annex A.

  • The SoA is linked to the risk assessment and treatment decisions.
  • Each Annex A control has an applicability decision and justification.
  • The implementation status is accurate and supported by evidence.
  • Additional controls are documented where the risk treatment requires them.
  • Control owners know how the control operates and where the evidence is stored.

Evidence to prepare: current SoA, control inventory, policy and procedure set, configuration records, control-owner list and links to supporting evidence.

ISO’s auditing practice note explains how auditors interpret the Statement of Applicability.

PrivaLex reviews the connection between the SoA, risk register and treatment plan before certification preparation. This helps identify common gaps, such as controls listed as implemented with no supporting evidence, or risk treatments that have no corresponding control decision.

Test Whether Controls Operate in Practice

Policies alone do not prove that a control works. The readiness review should sample operating evidence from across the organisation.

  • Access rights are approved, reviewed and removed when people change roles or leave.
  • Vulnerabilities, patches, backups and recovery tests are tracked and reviewed.
  • Security incidents have a defined response process, records and lessons learned.
  • Supplier risks are assessed, with security requirements and review records for critical providers.
  • Security awareness and role-specific training have completion records.
  • Change management, logging, secure development and continuity arrangements are appropriate to the systems in scope.

Evidence to prepare: access-review exports, onboarding and offboarding tickets, vulnerability reports, backup and recovery-test results, incident records, supplier assessments, signed agreements, training logs and change tickets.

PrivaLex helps teams identify the evidence an auditor is likely to request and organise it around actual controls and owners. That work is especially valuable for organisations that have implemented technical controls but have not yet created a consistent evidence trail.

Run Internal Audit and Management Review

An ISMS must be alive before certification. The organisation should not wait for the external auditor to discover whether the controls work.

  • An internal audit programme covers the ISMS requirements and relevant controls.
  • Internal auditors are sufficiently independent of the work they audit.
  • Findings have root causes, corrective actions, owners, deadlines and closure evidence.
  • Management review considers audit results, risk, objectives, resources, incidents, supplier issues and opportunities for improvement.
  • The organisation records decisions and follows through on assigned actions.

Evidence to prepare: audit programme, audit plan and report, nonconformity register, corrective-action records, management-review agenda, minutes and action log.

PrivaLex can support internal-audit preparation and management-review readiness, helping teams test the ISMS before the external audit. We focus on whether the organisation can explain how controls work, show the associated evidence and demonstrate that findings lead to corrective action.

Understand the Path to Certification

Readiness is a preparation phase. It is different from implementing the ISMS, performing an internal audit and receiving external certification.

  1. Readiness assessment: identifies the current state, gaps, owners and priorities.
  2. Implementation: establishes the ISMS, treats risks, implements controls and collects operating evidence.
  3. Internal audit and management review: test whether the ISMS works, correct findings and confirm leadership oversight.
  4. Stage 1 audit: the certification body reviews the ISMS design, scope, documented information and preparedness for Stage 2.
  5. Stage 2 audit: the certification body tests implementation and operating effectiveness using samples of evidence and interviews.

The exact audit plan depends on the certification body, scope and organisation. The key readiness test is simple: can the team trace a risk to a treatment decision, selected controls, operating evidence, internal review and management action?

PrivaLex supports organisations at each implementation stage, from early scope definition through to evidence review before Stage 1 and Stage 2. We help teams understand what the auditor is likely to ask, without taking the certification body’s independent role.

Preparing for ISO 27001 with PrivaLex

At PrivaLex, we help startups, scale-ups and technology companies turn ISO 27001 requirements into practical controls that fit the business, technology stack and customer commitments.

We begin by defining the scope of the ISMS and assessing the current position. This includes the systems, teams, suppliers, locations and services that matter most to the certification scope, as well as the evidence already available and the gaps that need attention first.

From there, we support risk workshops, treatment planning, SoA mapping, policy and control implementation, evidence collection, staff training, internal-audit preparation and management review. Each action is linked to an owner, deadline and expected evidence, so the programme remains manageable for the internal team.

We also help teams prepare for the questions that customers and auditors commonly ask: how access is controlled, how suppliers are assessed, how vulnerabilities and incidents are managed, how backups are tested and how leadership reviews security risks and improvement actions.

Where NIS2 or GDPR also apply, we map shared requirements into one operating programme while keeping framework-specific obligations visible. This reduces duplicated work and helps ensure that the security controls, privacy processes and customer commitments tell a consistent story.

Before certification, we coordinate preparation for Stage 1 and Stage 2 so the team understands what evidence is needed, who will provide it and where it is stored. The independent certification body always makes the certification decision, but we help make the process more structured and predictable.

Our role is not to create paperwork for its own sake. We help build an ISMS that can be used day to day, explained confidently to customers and tested by an independent certification body

Suggested 90-Day Readiness Plan

First 30 Days: Scope, Ownership and Risk

Confirm scope and ownership, document the risk method, build the first risk register and identify the highest-priority gaps. Establish an evidence structure so teams know where records will be stored.

PrivaLex can facilitate the initial workshops, helping leadership, IT, product and operations align on the scope and priorities before implementation effort expands.

Days 31 to 60: Controls and Evidence

Complete the treatment plan and SoA, implement priority controls, update policies and begin collecting operational evidence. Address access, backups, vulnerability management, supplier oversight, incident response and training according to the risks in scope.

This is where PrivaLex helps turn high-level requirements into practical actions, control owners, deadlines and evidence requirements that fit the organisation’s existing tools and ways of working.

Days 61 to 90: Test and Improve

Run an internal audit, hold a management review, close material findings and perform a final evidence check. If the ISMS is genuinely operating, begin planning the certification audit with an appropriate certification body.

PrivaLex can review the evidence trail, test the readiness of control owners and help close gaps before the external audit starts.

Conclusion

An ISO 27001 readiness checklist is useful only when it turns into owned actions and evidence. Define the scope, assess risks, map controls, keep records that show the ISMS operating and test the system through internal audit and management review.

The objective is not to implement every control in the same way as another organisation or to create documents for their own sake. It is to build an ISMS that reflects the organisation’s services, technology, people and business risks. When control owners understand their responsibilities and evidence is collected as part of normal operations, certification preparation becomes more predictable and less disruptive.

PrivaLex helps organisations make that transition from a checklist to an operating management system. We support the teams responsible for security and compliance while ensuring leadership has a realistic view of priorities, resources and residual risk.

Start with the gaps that create the greatest risk to the business or to the certification timeline. Assign an owner and deadline to each action, verify the evidence after implementation and keep leadership involved in decisions that affect scope, resources and residual risk.

Book a strategic session with PrivaLex to review your ISO 27001 readiness and prioritise the work before certification.


Frequently Asked Questions (FAQs)

It is a self-assessment tool that helps organisations evaluate how prepared they are for ISO 27001 certification before starting a formal implementation. It covers the core areas of an ISMS and gives you a clear picture of where you stand and what needs to close before an audit.

It is designed for CEOs, compliance leads, security managers and IT teams considering ISO 27001 certification or wanting to understand their current security maturity. It is especially useful for startups and scale-ups in regulated sectors or those selling to enterprise clients.

For most startups and SMEs, the process takes between 3 and 12 months depending on organisation size, ISMS scope and the maturity of existing controls. A readiness assessment at the start helps set a realistic timeline and budget.

ISO 27001 is not legally mandatory in most cases, but it is increasingly required by enterprise clients, public sector buyers and regulated industries as a condition of doing business. It is also strongly aligned with the security requirements of NIS2 and GDPR.

ISO 27001 is a formal certification issued by an accredited body, widely recognised across the EU and global markets. SOC 2 is a US-based audit report valued mainly by American buyers and investors. For EU companies, ISO 27001 is usually the priority. Many organisations add SOC 2 later when expanding to North America.

Yes. Many of our clients start with no formal ISMS in place. We guide you from the initial readiness assessment through scoping, implementation and certification, at a pace that fits your team and resources.

FREE CHECKLIST
Do you know what you need to certify for ISO 27001?
Download our readiness checklist and discover which controls are in place and where you have real gaps before starting the process.
Download Free Checklist