Exciting news: British Assessment Bureau will rebrand as Amtivo in Autumn 2026! Find out more here >>

ISO 27001 Readiness Tool

What Is the ISO 27001 Readiness Tool?

This tool is designed to help you build an initial picture of where your organisation currently stands in relation to ISO/IEC 27001 requirements.

It works through key areas of the standard – including organisational context, information security risk assessment and treatment, policies, access control, and operational security – and asks straightforward questions about what is already in place.

No technical background is required to complete it. The questions are framed around practical activities and processes rather than formal terminology.

What the tool covers

The tool is broadly aligned with key ISO/IEC 27001 requirements and is intended to help you:

  • Identify which elements of an Information Security Management System (ISMS) may already exist within your organisation
  • Highlight areas that may need further review against ISO/IEC 27001 requirements
  • Understand the broad scope of what ISO/IEC 27001 involves
  • Support internal discussions about information security priorities

Who it is for

This tool may be useful if you are:

  • New to ISO/IEC 27001 certification and exploring what it involves
  • Considering an initial internal review before engaging with the certification process
  • Working in a role with responsibility for IT, operations, compliance, or management

How it works

The tool is structured as a series of yes / no / unsure questions, each with a brief explanation of what it relates to in practice.

There are no pass or fail scores. The purpose is to give you a clearer view of your current position, not to determine whether you meet certification requirements.

Please note

This tool is a general readiness check only. It is not an audit, does not provide consultancy advice, and does not form part of any certification process. Results are indicative only.

Welcome to Our ISO 27001 Readiness Tool!

In just a few minutes, you can understand your business’s readiness for ISO 27001 certification using our simple tool. You’ll also gain access to valuable resources designed to help you identify and address any gaps. Take the first step toward ISO 27001 certification today.

Understanding your results

Your score provides a broad indication of where your organisation may currently sit in relation to key ISO/IEC 27001 requirements. Results are based on self-reported responses and are intended as a general guide only.

Based on your self-reported responses, a higher score suggests more relevant elements may already be in place. A lower score may suggest there are more areas to review before considering the certification process. Most organisations will have a mix – some areas well established, others requiring further attention.

 

What you might want to look at next

Your results show which areas returned “no” or “unsure” responses. You may want to use these as a starting point for internal discussion before deciding whether to progress toward certification.

 

Familiarise yourself with key ISO/IEC 27001 topics

Examples of areas covered by ISO/IEC 27001 include:

  • Defining the scope and context of the ISMS
  • Information security risk assessment and information security risk treatment
  • Relevant documented information, such as the information security policy and other documentation determined by the organisation

Consider what may already exist. In many organisations, some activities relevant to ISO/IEC 27001 may already exist informally. These can be useful to consider when reviewing your current position against the standard’s requirements.

If your score suggests broader coverage

Examples of further areas that may be relevant include:

  • Internal audit processes
  • Management review
  • Availability of relevant documented information and records

 

About the Certification Process

Certification against ISO/IEC 27001 is granted by an independent accredited certification body following a formal audit of the organisation’s Information Security Management System. It is not awarded on the basis of self-assessment tools such as this one.

Before a certification audit, the organisation is responsible for establishing, implementing, maintaining, and retaining relevant documented information for its ISMS.

Before and during the certification audit process, this typically includes:

  • Defining the scope of the ISMS
  • A Stage 1 audit, which reviews documented information and helps determine preparedness for the Stage 2 audit
  • A Stage 2 audit, which evaluates the implementation and effectiveness of the ISMS
  • A certification decision by the certification body
  • Surveillance audits if certification is granted

You may want to familiarise yourself with each of these stages before engaging with a certification body.

 

Want To Find Out More? 

If you would like to understand how the certification process works, what a formal audit involves, or what information is typically reviewed during an audit, our team is happy to talk you through the audit and certification process.

Speak to a Certification Specialist    Download the ISO/IEC 27001 Checklist