A readiness assessment, a Statement of Applicability for all 93 Annex A controls, facilitation guides, board-ready templates, and a phased roadmap to certification. Everything an ISMS needs to reach Stage 2 — in weeks, not quarters.
Score your readiness across eight domains, build your Statement of Applicability, and work the roadmap to Stage 1 and Stage 2. Instant download — no subscription.
For teams beginning their ISO 27001 journey and needing a structured read.
For teams actively driving toward certification.
For the full certification programme, end to end.
Redirecting to secure checkout…
The free ISO 27001 readiness assessment scores you across eight domains — the management system and all four Annex A themes — and shows your gaps and certification blockers. The toolkit is how you close them, and the Annex A tracker turns it into your audit trail.
No. This is the readiness and implementation toolkit. Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit — this toolkit gets your ISMS ready to pass it, faster.
ISO/IEC 27001:2022 — the current version, with the 93 Annex A controls organized into the four themes (organizational, people, physical, technological).
ISO 27001 is an international certification of a management system (ISMS); SOC 2 is a US attestation report on controls. Many companies eventually need both, and the controls overlap heavily. Pair this with our SOC 2 toolkit if customers ask for both.
No. You document a Statement of Applicability and can justify excluding controls that do not apply. The toolkit includes the SoA so you scope deliberately rather than boiling the ocean.
Typically 3–6 months of preparation, then the Stage 1 and Stage 2 audits. The toolkit compresses the prep — assessment, SoA, policies, internal audit, and roadmap are all included.
Yes. Our vCISO team can build the ISMS and manage the certification audit with you. Start with the free assessment or book a consultation.
If you'd rather we run the assessment, build the ISMS, and run your internal audit, that's what our vCISO engagements are for. Tell us where you are and we'll recommend the right scope.