Information Security Management Systems Book a free call

Know where your ISMS stands before your customer or auditor asks.

A pre-audit of your information security management system against ISO 27001 and your customers' security requirements, ending in a clear plan to close the gaps.

Book a free call

Preparation for certification, not certification itself.

Pre-audit summary (example)
AreaReadiness
Scope and contextReady
Risk assessmentPartly in place
Statement of ApplicabilityPartly in place
Access controlReady
Supplier managementMissing
Incident responseMissing

When a pre-audit helps

A customer is asking for ISO 27001 or a security questionnaire
You need to show what you already do and what you can commit to, without overpromising in a contract.
You plan to certify later
Find out how far you are, what the work involves and where to start, before paying a certification body.
You already have some policies or controls
Get an independent check of whether they cover the standard and whether you can prove they are followed.

What you receive

  • A gap report against the ISO 27001 requirements and the Annex A controls that apply to you.
  • A review of your risk assessment and Statement of Applicability.
  • A list of missing or weak evidence, so you know what an auditor would ask for.
  • A prioritised action plan your team can follow, with the most important items first.
  • A short readiness summary you can share with customers, if you choose to.
A pre-audit is not a certificate. Certification is issued by an accredited certification body after its own audit. My work is to make that audit, or your customer's review, go smoothly.

How it works

  1. Scoping callWe agree what is in scope, which customer requirements apply, and a fixed price and timeline.
  2. Document and evidence reviewI go through your policies, records and system settings against the standard.
  3. WalkthroughShort conversations with the people who run the processes, to check practice matches paper.
  4. Report and roadmapYou receive the findings and a prioritised plan, and we go through it together.

Common questions

Will this get us ISO 27001 certified?

No. Only an accredited certification body can certify you. The pre-audit shows you how ready you are and what to fix first.

How long does it take?

It depends on the size of your company and how much is already documented. You get a fixed timeline and price after the scoping call.

Can you help us fix the findings?

The plan is written so your team can act on it. If you want hands-on help, we can agree that separately.

Is it only for ISO 27001?

No. If a customer sends their own security requirements, I can check your position against those as well.

Book a free call

Tell me about your company and what your customer has asked for. I will reply with the next step and a fixed quote.

Email to book a call office@@informationsecuritymanagementsystems.com