Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is an ISO 27001 readiness assessment?
Last verifiedA readiness or gap assessment compares your ISMS to Clauses 4–10 and Annex A so you can decide go/no-go for Stage 1. It is best practice, not a mandatory clause. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. A self-assessment or consultant review is not an IAF-MLA accredited audit. Only a certification body operating to ISO/IEC 17021-1 and ISO/IEC 27006 issues a recognised certificate.
What this page is, and what it is not
Audience: an engineering or compliance lead who wants to find gaps before paying for Stage 1.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file anything with a certification body. Last verified 10 September 2026.
A gap assessment is industry best practice. ISO/IEC 27001 does not require you to run one. It also does not replace Stage 1 or Stage 2.
Gap areas and go/no-go signals
Signals below are planning aids, not a certification decision. Last verified 10 September 2026. Not legal advice.
| Gap area | What to inspect | Go/no-go signal | Kind of text |
|---|---|---|---|
| Scope (Clause 4) | Written ISMS boundaries, interested parties, and exclusions you can defend. | No-go for Stage 1 if the scope is a slogan rather than a testable boundary. | Certification standard (context) inspected in a best-practice review. |
| Risk assessment and treatment (Clause 6) | A method, a current assessment, and treatment decisions with owners. | No-go if risk is a slide with no records. | Certification standard (planning). |
| Statement of Applicability (Clause 6.1.3) | Necessary controls listed; inclusion justified; any Annex A exclusion justified; implementation status stated. | No-go if the SoA is a copy-paste of all 93 controls with no exclusions explained. | Certification standard (SoA). Annex A is selectable — 93 controls / four themes, not all mandatory. |
| Mandatory documented information | Scope, information security policy, risk records, SoA, internal-audit results, management review, corrective actions. | No-go if internal audit or management review have never run. | Certification standard (documented information). Typical list, paraphrased. |
| Operating evidence for implemented controls | Populations and samples for controls marked implemented (access, change, logging, suppliers). | No-go for Stage 2 if Stage 1 passed on paper but no operating records exist. Stage 1 may still proceed if you plan the evidence window. | Auditor-typical practice plus Clause 7.5 / 9 — distinguish mandate from sampling habit. |
| Leadership and improvement (Clauses 5, 9, 10) | Policy approval, roles, monitoring, corrective-action follow-through. | No-go if top management cannot speak to the ISMS. | Certification standard (leadership, performance, improvement). |
Legal requirement, regulatory guidance, best practice, or our recommendation
The readiness review is the easiest place to over-claim authority. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| ISO/IEC 27001 does not mandate a gap assessment. | Certification standard (by omission) — readiness is not a clause. | Does not mean a gap assessment is useless. |
| ISO/IEC 27002:2022 implementation guidance for Annex A. | Guidance, not the certifiable ISMS text. | Does not make every 27002 hint a Stage 1 finding. |
| Run a written gap review before buying Stage 1 days. | Industry best practice. | Does not replace an accredited audit. |
| IAF-MLA accreditation of the later certification body. | Accreditation requirement for a recognised certificate. | Does not accredit your consultant’s gap report. |
| Use the crosswalk-density layer to see thin coverage before you call the body. | ShipReady Metrics recommendation. | Does not determine YOUR obligations and is not a pass. |
Self, consultant, or accredited auditor
You can run a readiness review yourself, with a consultant, or as a pre-audit service from a body. The last option still is not Stage 1 unless contracted and performed as Stage 1. Independence rules matter if the same firm wants to certify you later — that is an ISO/IEC 17021-1 impartiality question, not something this page decides. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for a readiness pass. Last verified 10 September 2026. Not legal advice.
- Have we labelled this exercise as best practice, not as a mandatory clause?
- Can we map current practice to Clauses 4–10 and to Annex A themes (Organizational 37, People 8, Physical 14, Technological 34)?
- Is every SoA exclusion justified, and every “implemented” row backed by at least one artifact?
- Have internal audit and management review run at least once?
- Is the go/no-go decision written, with owners for remaining gaps?
- Are we clear that this review does not start a clock and does not file with a certification body?
What to do now
None of these steps is Stage 1.
- Score each gap area in the table as ready, partial, or missing.
- Fix documented-information gaps before operating-evidence polish.
- Read the controls-explained and auditor-evidence pages next.
- Only then book Stage 1 with an IAF-MLA accredited body.
- Re-verify sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance obligation map and the Annex A crosswalk (about 72 canonical controls) with a crosswalk-density honesty layer show coverage, not a pass. Evidence collection shows current posture. Evidence review records a met-verdict from a named human.
Those views can feed a readiness discussion. They are not an accredited gap audit and not legal advice.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022; ISO/IEC 27002:2022 as guidance. IAF for what “accredited” means when you later certify. Not legal advice.