How close are you to ISO/IEC 27001?
Bigger clients increasingly ask for ISO/IEC 27001 before they'll sign. This check shows what you already have in place and what's still missing, before you spend money on consultants or an audit.
33 questions · about 15 minutes · no card needed
This is for you if…
- A client, tender or insurer has asked whether you're ISO 27001 certified
- You're thinking about certification and want to know the size of the job
- You want to tighten up security without hiring a full-time security person
What you get
- A score across 8 areas, from management basics to suppliers and incidents
- A view of which documents auditors will ask for and which you're missing
- A prioritised gap list you can work through in-house
What the questions cover
One area per screen, each with a handful of yes, no or partly questions.
Security management basics
The foundations: scope, leadership support and how you decide what risks matter.
5 questions
People and awareness
How you screen, train and manage the people who work with your information.
4 questions
Information and asset management
Knowing what information and equipment you have, and looking after it from start to finish.
4 questions
Access control
Making sure the right people, and only the right people, can get to your systems.
4 questions
Operations and technology
Day-to-day technical protection: updates, malware, backups and monitoring.
5 questions
Physical security and suppliers
Protecting your premises and managing the companies that handle your data.
4 questions
Incidents and continuity
Being ready when something goes wrong.
4 questions
Checking and improving
How you check the programme works and keep making it better.
3 questions
Common questions
Is this the same as being certified?
No. Certification only comes from an accredited certification body after a formal audit. This check helps you get ready and shows where the gaps are, so the audit costs you less.
We're a small team. Is ISO 27001 realistic for us?
Yes. The standard scales to your size and risk. Many small businesses certify with a handful of documents and a few practical controls. The assessment is written for that reality, not for enterprises.
Which version does this follow?
It follows ISO/IEC 27001:2022, including the 93 Annex A controls grouped into the four themes.
More answers in the help centre.
Ready to see where you stand?
Free 14-day Pro trial, no card needed. You'll have a score and an action list in about 15 minutes.
Start the free checkAlso available: ISO/IEC 42001 readiness