Skip to main content
FaizZab

Readiness assessment

ISO 27001 Readiness Assessment

Understand your current certification readiness before entering the formal audit process.

The business problem

Why organizations bring this to us

Entering a certification audit without knowing where you stand is an expensive way to find out. Major nonconformities at Stage 2 delay certification by months, consume the audit budget twice, and damage credibility with the customers who asked for the certificate in the first place.

The failure points are rarely exotic. A scope that cannot be defended, a Statement of Applicability that contradicts the risk treatment plan, documentation that describes a process nobody follows, and controls with no record proving they operated - these account for the majority of findings.

A FaizZab readiness assessment tells you, with evidence rather than opinion, which of those conditions apply to you and what has to change before the certification body arrives.

Who this is for

  • Organizations with an ISMS already in place that are about to book a Stage 1 or Stage 2 audit.
  • Companies that inherited an ISMS through acquisition, consultancy handover or staff turnover and cannot vouch for it.
  • Security leaders who need an independent, defensible view to take to the board or to a customer.
  • Organizations that have received findings at a previous audit and need to confirm remediation actually landed.

Service scope

Assessment areas

The assessment is evidence-led. Each area is tested against records and interviews, and rated on how it would be viewed in a formal certification audit.

ISMS Scope & Boundary Challenge

Stress-test the declared scope against the real technology estate, locations, people and outsourced services. Scope statements that quietly exclude in-scope systems are a common source of major findings.

Clause-Level Readiness Benchmark

Assess management-system clauses 4 to 10 individually - context, leadership, planning, support, operation, performance evaluation and improvement - and rate each on demonstrable conformity.

Annex A Control Readiness

Review the applicable Annex A controls for implementation status and operating maturity, distinguishing controls that are designed, controls that are running, and controls that exist only on paper.

SoA Consistency Review

Reconcile the Statement of Applicability against the risk assessment, risk treatment plan and observed control reality. Internal contradictions here are among the fastest ways to lose auditor confidence.

Documentation Sufficiency

Test whether documented information is present, current, approved, version-controlled and consistent with practice - and whether it would satisfy an auditor asking how a process actually runs.

Evidence Sampling Readiness

Sample real records the way an auditor would: pick controls, request the evidence, and assess whether it can be produced within the audit window and whether it proves what it claims.

Internal Audit Preparedness

Evaluate whether the internal audit programme is risk-based, competently staffed, genuinely independent, documented in working papers, and capable of finding real issues.

Management Review Preparedness

Check that management review covers the required inputs, produces recorded decisions and demonstrates leadership engagement rather than a signature on a template.

Corrective Action Readiness

Test the nonconformity process end to end: are findings recorded, is root cause reached, are actions closed, and is effectiveness verified?

Priority Certification Gaps

Classify every finding by the likely audit consequence - major nonconformity, minor nonconformity, or observation - so effort goes where it changes the certification outcome.

30/60/90-Day Remediation Roadmap

Sequence remediation into a dated plan with owners and dependencies, showing what must close before Stage 1, before Stage 2, and what can follow certification.

Methodology

How the assessment runs

  1. Scoping and document request

    Agree the assessment boundary and issue a structured request for the ISMS documentation and control evidence set.

  2. Documentation review

    Analyse policies, risk artefacts, the SoA and records against clause and Annex A expectations before any interview takes place.

  3. Control owner interviews

    Walk through how each significant control actually runs with the people who run it, rather than with the person who wrote the policy.

  4. Evidence sampling

    Request and test real records under audit-like conditions to establish whether evidence can be produced on demand.

  5. Rating and prioritization

    Score each area, classify gaps by likely audit consequence, and identify the small number of issues that carry the most certification risk.

  6. Readout and roadmap

    Present findings to leadership and hand over a dated 30/60/90-day remediation roadmap with owners.

What you receive

Key deliverables

  • ISO 27001 readiness assessment report with clause-by-clause ratings
  • Annex A control readiness heatmap
  • Scope and boundary challenge findings
  • SoA consistency analysis against risk treatment and observed practice
  • Evidence sampling results showing what could and could not be produced
  • Gap register classified by likely audit consequence with owners
  • 30/60/90-day remediation roadmap
  • Executive readout for leadership and the certification decision

Outcome

Understand the gaps before formal assessment begins.

Commercial value

Why this service matters

Avoid a failed Stage 2

Major nonconformities restart the clock and the cost. Finding them beforehand is materially cheaper than finding them in front of an auditor.

Independent view

Teams cannot audit their own work objectively. An external benchmark gives leadership a defensible basis for the go/no-go decision.

Focused remediation

Not every gap matters equally. Prioritization by audit consequence stops teams spending months on findings that would never have been raised.

Questions

Common questions

How long does a readiness assessment take?

Duration depends on scope size, number of locations and the state of the evidence set. The assessment is scoped after an initial discussion so the effort matches the estate rather than a fixed template.

Will you fix the gaps you find?

The assessment itself is deliberately independent and diagnostic. Remediation can be delivered separately through our ISO 27001 implementation service if you want support closing the gaps.

Is this the same as an internal audit?

No. An internal audit is a required part of your management system and tests conformity against your own ISMS. A readiness assessment benchmarks you against what a certification body is likely to conclude, and prioritizes gaps by audit consequence.

Related

Related services

View all services
ImplementationAVAILABLE NOW

ISO 27001 Implementation

End-to-end implementation of an ISO/IEC 27001:2022 Information Security Management System - governance, risk methodology, Statement of Applicability, controls, evidence and the internal audit and management review cycle that keeps it alive.

Explore this service
Audit supportAVAILABLE NOW

Internal Audit

Internal audit programme design and delivery - audit universe and planning, fieldwork, evidence, findings, corrective action and reporting, for management systems and business processes.

Explore this service
Readiness assessmentAVAILABLE NOW

ISO 27701 Readiness Assessment

An evidence-based review of your privacy management system against ISO/IEC 27701:2025 - PIMS boundary, accountability, transparency evidence, controller/processor obligation mapping, rights-handling records and a PIMS assurance heatmap.

Explore this service
Audit supportAVAILABLE NOW

IT Audit

Independent IT audit covering IT general controls, access controls, change management and IT operations, with structured evidence testing, findings and tracked remediation.

Explore this service

Important

Readiness/advisory support only. FaizZab does not issue ISO certification. Certification decisions rest solely with an independent, accredited certification body, and a readiness assessment does not guarantee a certification outcome.

Find out where you actually stand

Tell us your obligation, your timeline and where you are today. We will confirm whether this is the right engagement for you.