ISO 27001 Certification Readiness Assessment
Comprehensive evaluation of your organization's readiness for ISO 27001 certification, examining your information security management system (ISMS) against the standard's requirements. Our assessment provides a detailed gap analysis and implementation roadmap to help you achieve certification efficiently and effectively.
In scope
- ISO 27001 gap analysis
- ISMS documentation review
- Control implementation assessment
- Risk assessment methodology review
- Statement of Applicability evaluation
- Management review process assessment
- Internal audit program evaluation
- Security policy framework review
- ISMS metrics assessment
- Certification preparation guidance
You receive
- ISO 27001 gap analysis report
- ISMS implementation roadmap
- Documentation enhancement recommendations
- Control remediation plan
- Certification preparation checklist
- Risk assessment framework enhancements
- ISMS process improvements
- Implementation timeline
- Resource requirements
- Certification strategy
Tiers
Choose the depth.
Entry — market-sized scope
$13K
Gap analysis only: one ISMS scope, up to 50 employees and 1 location. Clauses 4-10 and the Annex A controls scored from document review and up to 6 interviews, run remotely. Output is a gap report and a prioritized action list.
- employees
- 50
- Sites
- 1
- months
- 1
- Clause 4-10 and Annex A gap scoring
- Review of existing ISMS documents
- Up to 6 stakeholder interviews (remote)
- Gap report with prioritized action list
- — Implementation roadmap with timeline and resourcing
- — Risk methodology and Statement of Applicability review
- — Internal audit program evaluation
- — Writing any documentation
Essential ISO 27001 Gap Analysis
$38K
Gap analysis plus certification plan: up to 250 employees and up to 2 locations. Adds risk assessment methodology, Statement of Applicability, management review and internal audit program evaluation, with an implementation roadmap, resource estimate and certification checklist.
- employees
- 250
- Sites
- 2
- months
- 2
- Full clause and Annex A gap analysis
- Risk methodology and Statement of Applicability evaluation
- Management review and internal audit program assessment
- ISMS implementation roadmap with timeline and resource requirements
- Certification preparation checklist and auditor-selection guidance
- — Authoring policies, procedures or the SoA
- — Hands-on control implementation
- — Running the internal audit
- — Support during the certification audit
Comprehensive ISO 27001 Preparation
$65K
Complete certification preparation with detailed documentation development and implementation assistance
- employees
- 1000
- Sites
- 5
- — Hands-on technical control implementation
- — Conducting the internal audit
- — Attendance at Stage 1 and Stage 2 audits
- — The certification body's audit fees
Enterprise ISO 27001 Implementation Program
$110K
Full-service ISO 27001 implementation support including documentation development, control implementation, and certification guidance
- employees
- 2500
- Sites
- 10
- — The certification audit itself and certification body fees
- — Security tooling or licence costs
- — Post-certification surveillance-year support
- — Scopes above 2,500 employees (scoped separately)
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a readiness & governance assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Scoping & framework selection
The standard or regulation, the systems and the business units in scope are fixed.
You see · Your audit or regulatory driver.
02Evidence collection & interviews
Policies, configurations and records reviewed; control owners interviewed.
You see · Documents and time with control owners.
03Gap analysis
Each requirement mapped to current state: met, partial or missing, with the evidence behind it.
You see · A clear gap register.
04Roadmap & evidence plan
Prioritized remediation with owners, and the evidence an auditor will ask for.
You see · A plan you can execute or hand to us.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
Continuous Attack Surface Monitoring
Comprehensive continuous monitoring of your external attack surface with regular assessments and testing.
Active Directory Security Assessment
Comprehensive security assessment of Active Directory infrastructure, focusing on privilege escalation, lateral movement, and domain compromise scenarios.
Business Continuity Planning Assessment
Comprehensive evaluation of your organization's business continuity capabilities and operational resilience through detailed Business Impact Analysis (BIA), risk assessment, and continuity planning. Our specialized approach combines regulatory compliance requirements with practical business resilience strategies to ensure your organization can maintain critical operations during disruptions and recover effectively from various business interruption scenarios.
Research
Latest from the blog

compliance · Jan 7, 2026
Why Your Policy Management Strategy Is Costing You More Than You Think
Most CISOs don't realize they're bleeding budget on policy management until they calculate the actual cost. Here's how to reclaim 240+ hours of senior technical time annually by treating policy management as a technology problem.

incident-response · Nov 1, 2025
Incident Response Modernization: CISO's Breach Readiness Framework for 2026
Strategic incident response framework for CISOs where 79% faster containment and $3.9M breach cost savings come from modernized IR capabilities, automated playbooks, and proactive breach simulation.
cryptography · Jul 15, 2025
Post-Quantum Cryptography Readiness: CISO's 2025 Implementation Guide
Essential guide for CISOs navigating the quantum threat landscape and implementing post-quantum cryptography strategies in 2025.
Start an engagement