Free checker
ISO 27001 readiness checker
Where you stand against ISO 27001:2022, clause by clause and across all 93 Annex A controls.
Run it now
Answer the questions and you get the number, the working behind it and what we would do about it. The calculation itself runs in your browser, so your answers stay with you.
What you tell it
- Scope of the ISMS as you intend to declare it
- State of clauses 4 to 10, from nothing written to fully operating
- Which of the 93 Annex A controls are applied, and which are excluded
- Whether internal audit and management review have actually run
What you get back
- Readiness by clause and by the four Annex A themes
- A draft Statement of Applicability position
- Findings likely to be raised as major or minor at Stage 2
- What Stage 1 will ask for, so nothing is a surprise
How the score is worked out
- 1
Structured on ISO/IEC 27001:2022 and the 93 controls in the 2022 Annex A, grouped into organisational, people, physical and technological.
- 2
Clause 4 to 10 gaps are treated as majors, because certification bodies do.
- 3
An exclusion without a justification is scored as a gap, not as an exclusion.
- 4
Internal audit and management review are scored separately, since they are the most commonly missed evidence.
Where this stops being useful
Certification bodies differ in how strictly they read the same clause. This tells you where you stand against the standard. Your auditor still gets the final word.
Other tools
- Compliance effort estimatorWork out roughly how many person days a certification will take your team before you commit to a date.Open it
- Compliance cost estimatorA budget range for getting certified and staying certified, with the recurring costs people forget until year two.Open it
- VAPT and security testing cost estimatorPrice a penetration test properly, by counting the things that actually drive effort rather than by counting IP addresses.Open it
What certification readiness actually measures
The difficulty of ISO 27001:2022 is not the controls. Annex A controls are largely things a competent security team either already does or can implement. The difficulty is proving they operated consistently across the period an auditor examines.
An auditor does not accept that access is reviewed quarterly. They ask for the last four reviews, look at who signed them, check whether anything was revoked as a result, and notice if all four are dated in the same week.
So readiness is a question about evidence and about the management system, not about your security posture. Organisations with genuinely strong security fail readiness assessments routinely, because nothing was written down.
The management system is where first-timers underestimate
Clauses 4 to 10 of the standard, the part that is not Annex A, is where most of the authoring effort sits: context, interested parties, scope, leadership commitment, objectives, risk assessment methodology, internal audit, management review and continual improvement.
Internal audit and management review are the two most commonly missing entirely. Both require records showing decisions rather than attendance, and both need to have happened before certification rather than being produced for it.
Risk assessment is the other. A risk register is easy. A register where each accepted risk has a named accepter, a date and a review point, and each treated risk traces to the control that treats it, is what survives scrutiny.
The 2022 controls where evidence is thinnest
The revision restructured Annex A into 93 controls across four themes and introduced eleven new ones. Those eleven matter disproportionately for readiness because no organisation has years of accumulated artefacts behind them.
Threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
Information deletion and data masking overlap directly with DPDP Act obligations. Evidence collected once satisfies both, and organisations running privacy and ISO as separate programmes produce it twice.
How to move from this score to a date
Start the time-dimensioned evidence today, whatever your score. Access reviews, internal audit, management review and scan cycles cannot be produced retrospectively, and they are what determines the earliest possible certification date.
Then close the management system gaps, because they are authoring work with no external dependency and they block certification absolutely, unlike an Annex A control which can be justified as not applicable.
Then work the Annex A gaps in order of evidence lead time rather than in order of severity. A control you can implement and evidence in a week can wait; one that needs three months of records cannot.
A realistic first certification for an organisation starting from a middling score is nine to twelve months. Programmes compressed below six months are usually producing documentation rather than a management system, and it shows at the first surveillance audit.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












