# ISO 27001 Certification Readiness Assessment

> From $13K · Compliance & GRC · https://cisomarketplace.services/services/iso-27001-certification-readiness

Comprehensive evaluation of your organization's readiness for ISO 27001 certification, examining your information security management system (ISMS) against the standard's requirements. Our assessment provides a detailed gap analysis and implementation roadmap to help you achieve certification efficiently and effectively.

## In scope

- ISO 27001 gap analysis
- ISMS documentation review
- Control implementation assessment
- Risk assessment methodology review
- Statement of Applicability evaluation
- Management review process assessment
- Internal audit program evaluation
- Security policy framework review
- ISMS metrics assessment
- Certification preparation guidance

## Deliverables

- ISO 27001 gap analysis report
- ISMS implementation roadmap
- Documentation enhancement recommendations
- Control remediation plan
- Certification preparation checklist
- Risk assessment framework enhancements
- ISMS process improvements
- Implementation timeline
- Resource requirements
- Certification strategy

## Tiers

### Entry — market-sized scope: $13K

Gap analysis only: one ISMS scope, up to 50 employees and 1 location. Clauses 4-10 and the Annex A controls scored from document review and up to 6 interviews, run remotely. Output is a gap report and a prioritized action list.

Limits: employees 50, locations 1, months 1

Includes:
- Clause 4-10 and Annex A gap scoring
- Review of existing ISMS documents
- Up to 6 stakeholder interviews (remote)
- Gap report with prioritized action list

Excludes:
- Implementation roadmap with timeline and resourcing
- Risk methodology and Statement of Applicability review
- Internal audit program evaluation
- Writing any documentation

### Essential ISO 27001 Gap Analysis: $38K

Gap analysis plus certification plan: up to 250 employees and up to 2 locations. Adds risk assessment methodology, Statement of Applicability, management review and internal audit program evaluation, with an implementation roadmap, resource estimate and certification checklist.

Limits: employees 250, locations 2, months 2

Includes:
- Full clause and Annex A gap analysis
- Risk methodology and Statement of Applicability evaluation
- Management review and internal audit program assessment
- ISMS implementation roadmap with timeline and resource requirements
- Certification preparation checklist and auditor-selection guidance

Excludes:
- Authoring policies, procedures or the SoA
- Hands-on control implementation
- Running the internal audit
- Support during the certification audit

### Comprehensive ISO 27001 Preparation: $65K

Complete certification preparation with detailed documentation development and implementation assistance

Limits: employees 1000, locations 5

Excludes:
- Hands-on technical control implementation
- Conducting the internal audit
- Attendance at Stage 1 and Stage 2 audits
- The certification body's audit fees

### Enterprise ISO 27001 Implementation Program: $110K

Full-service ISO 27001 implementation support including documentation development, control implementation, and certification guidance

Limits: employees 2500, locations 10

Excludes:
- The certification audit itself and certification body fees
- Security tooling or licence costs
- Post-certification surveillance-year support
- Scopes above 2,500 employees (scoped separately)

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=iso-27001-certification-readiness
