Free checklist
The ISO 27001 readiness checklist for startups
Forty plain-English checks covering everything a certification body will look at, from scope and leadership through risk, controls and the audit itself. Written by Lead Auditor trained practitioners for companies without a compliance team.
Tick items off as you go: your progress saves automatically and helps us tailor any follow-up conversation. Anything you cannot tick is a conversation worth having.
1. Scope and context
Auditors confirm scope before anything else, because everything hangs off it.
2. Leadership and policy
Certification fails at the top more often than at the firewall.
3. Risk assessment and treatment
The engine of the whole standard. Everything else should trace back to it.
4. The Statement of Applicability
The document auditors read next to reality. Mismatches here are classic findings.
5. People
Awareness that exists only in attendance records is a finding waiting to happen.
6. Operations and technical controls
The checks an auditor samples hardest in a cloud-native company.
7. Monitoring, internal audit and management review
The clauses that prove the system runs, rather than merely exists.
8. Certification audit preparation
What makes the certification body's visit boring, which is the goal.
What to do with the gaps
Anything unticked is normal: that is what a gap analysis is for. If you want a prioritised, fixed-price plan for closing them, book a free introductory call or try the cost calculator to get a tailored estimate.