Know where your ISMS stands before your customer or auditor asks.
A pre-audit of your information security management system against ISO 27001 and your customers' security requirements, ending in a clear plan to close the gaps.
Book a free callPreparation for certification, not certification itself.
| Area | Readiness |
|---|---|
| Scope and context | Ready |
| Risk assessment | Partly in place |
| Statement of Applicability | Partly in place |
| Access control | Ready |
| Supplier management | Missing |
| Incident response | Missing |
When a pre-audit helps
- A customer is asking for ISO 27001 or a security questionnaire
- You need to show what you already do and what you can commit to, without overpromising in a contract.
- You plan to certify later
- Find out how far you are, what the work involves and where to start, before paying a certification body.
- You already have some policies or controls
- Get an independent check of whether they cover the standard and whether you can prove they are followed.
What you receive
- A gap report against the ISO 27001 requirements and the Annex A controls that apply to you.
- A review of your risk assessment and Statement of Applicability.
- A list of missing or weak evidence, so you know what an auditor would ask for.
- A prioritised action plan your team can follow, with the most important items first.
- A short readiness summary you can share with customers, if you choose to.
How it works
- Scoping callWe agree what is in scope, which customer requirements apply, and a fixed price and timeline.
- Document and evidence reviewI go through your policies, records and system settings against the standard.
- WalkthroughShort conversations with the people who run the processes, to check practice matches paper.
- Report and roadmapYou receive the findings and a prioritised plan, and we go through it together.
Common questions
Will this get us ISO 27001 certified?
No. Only an accredited certification body can certify you. The pre-audit shows you how ready you are and what to fix first.
How long does it take?
It depends on the size of your company and how much is already documented. You get a fixed timeline and price after the scoping call.
Can you help us fix the findings?
The plan is written so your team can act on it. If you want hands-on help, we can agree that separately.
Is it only for ISO 27001?
No. If a customer sends their own security requirements, I can check your position against those as well.
Book a free call
Tell me about your company and what your customer has asked for. I will reply with the next step and a fixed quote.
Email to book a call office@@informationsecuritymanagementsystems.com