ISO 27001 Readiness Check
Ten operating questions drawn from the mandatory clauses a certification audit tests — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
ISO 27001 is a certifiable standard, not law — any organization can build an ISMS to it and seek certification through an accredited body. The check scores the mandatory clauses 4–10 that the audit tests.
1.Scope: is the ISMS scope documented — the boundaries, the exclusions, and why each exclusion is justified?
Cl. 4.3 — ISMS scope
2.Leadership: is an information-security policy defined, communicated, and are roles and responsibilities assigned?
Cl. 5.1–5.3 — leadership, policy, roles
3.Risk assessment: is a repeatable method applied to identify, analyse and evaluate information-security risks on a cadence?
Cl. 6.1.2, 8.2 — risk assessment
4.Statement of Applicability: does the SoA exist, naming each Annex A control as applicable or not — with justification and status?
Cl. 6.1.3(d) — Statement of Applicability
5.Risk treatment: is the treatment plan implemented, and is residual risk formally accepted by the risk owners?
Cl. 6.1.3, 8.3 — risk treatment
6.Competence: are the people running the ISMS competent for their role, and is security awareness delivered across the workforce?
Cl. 7.2–7.3 — competence and awareness
7.Operation: are the chosen controls actually operated — organizational, people, physical and technological — under planned control?
Cl. 8.1 + Annex A — operational control
8.Monitoring: are controls measured at defined intervals and evaluated — including an internal audit programme at planned intervals?
Cl. 9.1–9.2 — monitoring, measurement, internal audit
9.Management review: does leadership formally review the ISMS at planned intervals, with inputs and decisions on record?
Cl. 9.3 — management review
10.Improvement: are nonconformities corrected with root cause, and is there evidence the ISMS improves over time?
Cl. 10.1–10.2 — nonconformity and continual improvement
ISO 27001 readiness
Answer to scoreWhat the score means
80–100% · Low risk
The ISMS machinery exists and can mostly be shown. Next step: continuous evidence — measures, reviews and audits reading from live state, not audit-season archaeology.
40–79% · Medium / High
The usual state: real work done, proof missing — usually the SoA, audits and management review. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with scope, risk method and the Statement of Applicability — the ISO 27001 framework page maps the clause set to operating controls.
The ISO 27001 frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel. TruSecure is not a certification body and does not issue ISO, SOC 2, or CMMC certifications.