Loading tools
Loading tools
Applies ISO/IEC 27001:2022 (with Amd 1:2024) — the Clauses 4–10 management-system requirements and the 93-control Annex A (IAF MD26 transition closed 2025-10-31) — to score your ISMS readiness, diagnose the four Stage-1 certification gates (SoA, risk assessment, internal audit, management review) and build a prioritized 90-day roadmap, with NIS2 Art. 21(2) evidence reuse mapped throughout.
Is the ISMS scope (Clause 4.3) documented in a versioned document stating which products, systems and offices are included?
An accredited auditor's first request is the Scope Document. It must articulate physical locations, internal networks, cloud environments (AWS/GCP/Azure) and external interfaces. For SaaS startups the scope typically covers the cloud production infrastructure, the CI/CD pipeline and all personnel accessing customer data.
// Answer all 22 questions to see your results. (0 answered)
Deterministic self-assessment based on ISO/IEC 27001:2022 (3rd edition, with Amendment 1:2024), IAF MD26:2022 transition requirements and the ENISA NIS2 Technical Implementation Guidance (June 2025). Informational guidance only — not legal advice; only an accredited Certification Body can grant ISO 27001 certification.
A second pair of eyes before the expensive mistakes. Get in touch for a strategy call.