Free ISO 27001 Assessment

ISO/IEC 27001:2022

A prospect wants ISO 27001 by a date. Here is how it gets there.

Gap analysis to an audit-ready ISMS for teams of 10 to 300, built in the platform that keeps collecting evidence after certification, with the certification body booked around your date.

Statement of ApplicabilityExample, ISO/IEC 27001:2022

93 controls: 89 applicable, 4 excluded with justification

5 Organisational
37 controls
37 / 37
6 People
8 controls
8 / 8
7 Physical
14 controls, 4 excluded: no owned premises
10 / 10
8 Technological
34 controls
34 / 34
Signed off by the ISMS owner, week 9Export · DOCX, PDF

Who this is for

Teams whose customers ask for the certificate, not the brochure.

  • A fit

    • A SaaS company of 10 to 300 people whose enterprise prospect requires ISO 27001 before signing or renewing.
    • An IT services or MSP business bidding for a public or regulated contract that lists ISO 27001 as a condition.
    • A team on AWS, Google Cloud or Azure with GitHub and Google Workspace or Microsoft 365, where most evidence can be collected automatically.
  • Also a fit

    • A company that already holds SOC 2 or has a GDPR programme and needs an ISMS for European and international customers.
    • A company whose first certification attempt stalled on documentation nobody owned.
    • A team that wants ISO 27001 and SOC 2 from one control set, with the second report mostly mapping.
  • Not a fit

    • Organisations that need the certification audit itself. We prepare you; an accredited certification body audits and certifies.
    • Companies with owned data centres or manufacturing sites. The physical controls need an on-site partner, which we would name in the quote.
    • Teams that want a document pack without operating the controls. The auditor checks that the ISMS runs, and so do we.

What you walk away with

An ISMS the auditor can follow, and your team can run.

Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.

ISO 27001 readiness

14 deliverables, 8 to 10 weeks
  • ISMS scope and context statement

    Interested parties, boundaries, interfaces

    • DOCX
    • PDF
  • Information security policy and management commitment

    Approved and communicated, with the record

    • DOCX
    • PDF
  • Risk assessment method, risk register and treatment plan

    Owners, likelihood, impact, treatment, residual risk

    • CSV
    • PDF
  • Statement of Applicability for all 93 Annex A controls

    Applicable or excluded, with justification and status

    • CSV
    • PDF
  • Policy set for the controls you apply

    Access, cryptography, secure development, supplier, acceptable use, and the rest your SoA selects

    • DOCX
    • PDF
  • Procedures for access, change, incident, supplier and business continuity

    Written for how your team actually works

    • Procedure
  • Asset inventory and supplier register

    Owners, classification, contract and review status

    • CSV
  • Competence, awareness and training records

    Who was trained on what, and when

    • Platform
    • PDF
  • Internal audit programme and first internal audit report

    Findings and corrective actions logged

    • PDF
  • Management review record

    Inputs, decisions, actions, as clause 9.3 requires

    • PDF
  • Evidence linked to each control

    From GitHub, cloud and identity systems where connected; uploaded where not

    • Platform
  • Objectives, metrics and measurement plan

    What you measure and how often

    • DOCX
  • Certification body shortlist and audit plan

    Stage 1 and Stage 2 booked around your date

    • DOCX
  • Recorded hand-over and readiness sign-off

    With whoever owns the ISMS afterwards

    • Video
    • PDF

How it works

Ten weeks to hand-over. Then the auditor, then every year without us.

The certification audit is yours to contract; we book it around your date and join the calls.

  • GRCTrail
  • Hand-over
  • Without us
  1. Week 0

    Scoping call

    Scope, cloud footprint, what exists. Written fixed price within 3 business days.

  2. Weeks 1 to 2

    Assessment

    Gap analysis against clauses 4 to 10 and Annex A. Risk method agreed. Implementation price confirmed.

  3. Weeks 3 to 9

    Implementation

    Policies, procedures, SoA, evidence linked to each control. Two review sittings with your team.

  4. Week 10

    Internal audit, management review, hand-over

    First internal audit, management review record, recorded hand-over, readiness sign-off.

  5. Your auditor

    Stage 1 and Stage 2

    Booked around your date with the certification body you contract. We join the calls and fix findings against our work.

  6. Every year

    Surveillance audits

    The ISMS keeps operating: reviews, internal audits, evidence collecting. In GRCTrail or in your export.

How we price

What moves the price

Three things we ask about on the call.

  • How much of the stack is cloud.

    Controls on AWS, GitHub and Google Workspace are evidenced automatically; owned hardware is not.

  • What already exists.

    A SOC 2 report or a working security programme shortens the work considerably.

  • Scope and sites.

    One product and one office is the base case; each extra product, office or legal entity adds controls to evidence.

Never in our price, named in the quote so you can budget

  • The Stage 1 and Stage 2 certification audit, contracted with an accredited certification body
  • Penetration testing
  • Formal legal opinions
  • Acting as your information security officer after hand-over

Questions before the call

Who issues the ISO 27001 certificate?

An accredited certification body, after a Stage 1 and Stage 2 audit that you contract directly. We prepare the ISMS and evidence, help you choose the body, book the dates around your deadline and join the calls. We do not issue certificates.

Can a company of 15 people get certified?

Yes. The standard scales to the organisation. A narrow scope and a small control set still meet every clause. The work is the same shape; it is shorter.

Do we need SOC 2 as well?

Only if your customers ask for it. ISO 27001 is recognised worldwide; SOC 2 is expected mainly by US customers. The two share most controls, so adding SOC 2 readiness later is mostly mapping and evidence formatting.

What happens after certification?

The certificate is valid for three years with annual surveillance audits. The ISMS must keep operating: reviews, internal audits, evidence. In GRCTrail that schedule is tracked and evidence keeps collecting from connected systems. The documents remain yours either way.

What if the auditor raises a nonconformity?

If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.

Tell us your date, your cloud footprint and what exists today.

You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.