Skip to main content
TOOLS

ISO 27001 Readiness Check

Ten operating questions drawn from the mandatory clauses a certification audit tests — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

ISO 27001 is a certifiable standard, not law — any organization can build an ISMS to it and seek certification through an accredited body. The check scores the mandatory clauses 4–10 that the audit tests.

0/10
  1. 1.Scope: is the ISMS scope documented — the boundaries, the exclusions, and why each exclusion is justified?

    Cl. 4.3 — ISMS scope

  2. 2.Leadership: is an information-security policy defined, communicated, and are roles and responsibilities assigned?

    Cl. 5.1–5.3 — leadership, policy, roles

  3. 3.Risk assessment: is a repeatable method applied to identify, analyse and evaluate information-security risks on a cadence?

    Cl. 6.1.2, 8.2 — risk assessment

  4. 4.Statement of Applicability: does the SoA exist, naming each Annex A control as applicable or not — with justification and status?

    Cl. 6.1.3(d) — Statement of Applicability

  5. 5.Risk treatment: is the treatment plan implemented, and is residual risk formally accepted by the risk owners?

    Cl. 6.1.3, 8.3 — risk treatment

  6. 6.Competence: are the people running the ISMS competent for their role, and is security awareness delivered across the workforce?

    Cl. 7.2–7.3 — competence and awareness

  7. 7.Operation: are the chosen controls actually operated — organizational, people, physical and technological — under planned control?

    Cl. 8.1 + Annex A — operational control

  8. 8.Monitoring: are controls measured at defined intervals and evaluated — including an internal audit programme at planned intervals?

    Cl. 9.1–9.2 — monitoring, measurement, internal audit

  9. 9.Management review: does leadership formally review the ISMS at planned intervals, with inputs and decisions on record?

    Cl. 9.3 — management review

  10. 10.Improvement: are nonconformities corrected with root cause, and is there evidence the ISMS improves over time?

    Cl. 10.1–10.2 — nonconformity and continual improvement

0%

ISO 27001 readiness

Answer to score

What the score means

80–100% · Low risk

The ISMS machinery exists and can mostly be shown. Next step: continuous evidence — measures, reviews and audits reading from live state, not audit-season archaeology.

40–79% · Medium / High

The usual state: real work done, proof missing — usually the SoA, audits and management review. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with scope, risk method and the Statement of Applicability — the ISO 27001 framework page maps the clause set to operating controls.

The ISO 27001 framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel. TruSecure is not a certification body and does not issue ISO, SOC 2, or CMMC certifications.

Frequently Asked Questions

Is ISO 27001 a law?
No — it is a certifiable international standard. Nobody is legally required to hold it, but buyers and regulators increasingly demand it as proof of a working ISMS. Certification is issued by an accredited certification body after a stage 1 and stage 2 audit, then surveillance audits.
What is the Statement of Applicability?
The SoA is the ISMS decision record: every Annex A control marked applicable or not, with the justification and implementation status. Certification auditors read it first — it is the map from your risk assessment to the controls they will test.
Which clauses does the check cover?
The mandatory ones — clauses 4 through 10: scope, leadership, planning, support, operation, performance evaluation and improvement. These are what the audit tests regardless of sector; the Annex A control themes appear as the operational question.
Is the score an official ISO assessment?
No. It is an indicative maturity score from ten questions drawn from the standard — not an audit and not a certification. Only an accredited certification body can audit and certify an organization against ISO 27001; the check tells you how far the ISMS is from being auditable.