ISO 27001 Readiness and Compliance Services
- Readiness establishes what the standard requires of you specifically and what you already have.
- The deliverable is a clause-by-clause and control-by-control position plus a draft Statement of Applicability, not an opinion that you are ready.
- Run readiness before booking a certification body, so remediation happens on your timetable.
- Readiness typically costs £5,000 to £15,000 and takes two to four weeks.
- The most common finding is that controls operate but leave no retained record an auditor can sample.
What readiness establishes
ISO 27001 readiness services establish where you stand before you commit to a certification date. The output is a clause-by-clause position against Clauses 4 to 10, a control-by-control position against the 93 Annex A controls, a draft view of your Statement of Applicability, and a remediation plan.
Compliance services then cover the build: writing the ISMS, running it long enough to generate records, completing the internal audit and management review, and supporting the certification audit.
What a readiness assessment should contain
| Element | What good looks like |
|---|---|
| Scope proposal | Which organisational units, services, locations and information the ISMS will cover, and what is excluded |
| Asset and system picture | What is in scope, who owns it, and where information lives |
| Clause-by-clause position | Clauses 4 to 10 assessed individually, with current evidence and a judgement on sufficiency |
| Control-by-control position | All 93 Annex A controls assessed as applicable or not, with draft justifications |
| Risk assessment approach | How risks will be identified, assessed and treated, and how that justifies control selection |
| Remediation plan | What closes each gap, who does it, how long it takes |
| Certification route | Which accredited bodies are appropriate, and the earliest defensible audit window |
| Delivery call | A conversation where the scope decisions and borderline judgements get explained |
Findings should be stated as findings. “These clauses are met, these are not, here is what closes each” is defensible. “You are ready to certify” is a warranty, and the certification body makes that decision, not your adviser.
When to run readiness
Before you engage a certification body, and before you write documentation.
Certification bodies price from scope and maturity, so knowing both produces an accurate quote. And anything found at Stage 1 delays Stage 2, which moves your certificate date by weeks in a market where audit slots are booked ahead.
Our readiness and gap assessment is a fixed fee with a delivery call for that reason.
Readiness versus certification
They cannot be combined, and the reason is structural.
Readiness is advisory. Its purpose is to help you, and the firm doing it can tell you exactly what to fix and how.
Certification is independent. Under ISO/IEC 17021 the certification body cannot consult on the system it will certify. Your certifier cannot help you prepare, which is why readiness exists as a separate service.
What readiness commonly finds
Controls that operate but leave no record. Access is reviewed, but in a spreadsheet that is overwritten each quarter, so nothing survives for the auditor to sample.
No defined scope. Every conversation about controls goes in circles until someone decides what is in.
A risk assessment written after the control list. The standard expects control selection to follow from risk. Where the order was reversed, auditors notice.
The eleven new controls not addressed. Threat intelligence, cloud security, configuration management, data masking, data leakage prevention, monitoring, web filtering and secure coding are the usual gaps for organisations with an older security posture.
Supplier security handled informally. A.5.19 to A.5.23 cover supplier relationships, and most organisations have contracts but no assessment records.
The climate consideration missing. Amendment 1 of February 2024 requires it in the context analysis. A one-paragraph fix, routinely raised when absent.
No independent internal auditor. Clause 9.2 requires one, and small organisations rarely have someone who understands the ISMS and did not build it.
Cost and timing
| Service | Typical cost | Typical duration |
|---|---|---|
| Readiness and gap analysis | £5,000 to £15,000 | 2 to 4 weeks |
| Implementation and build | £15,000 to £50,000 | 2 to 4 months |
| Operating period before audit | Internal effort | Long enough to produce records |
| Internal audit | £4,000 to £12,000 | 1 to 2 weeks |
| Certification body, Stage 1 and Stage 2 | £5,000 to £20,000 | 4 to 8 weeks including scheduling |
Cost scales with scope, headcount within scope, number of sites and existing maturity.
What compliance services cover after readiness
Writing the information security policy and assigning roles. Building the risk assessment and treatment process. Producing the Statement of Applicability with justified inclusions and exclusions. Implementing the control set. Establishing supplier security assessment. Setting up logging, monitoring and incident response. Establishing the evidence cadence. Then running the ISMS, the internal audit, the management review, and supporting both audit stages.
What to do next
Decide your scope, at least provisionally. It is the input every proposal needs and the decision that most affects cost.
Our free readiness diagnostic gives an immediate first view, and the ISO 27001 service page sets out how readiness and implementation fit together.
References
FAQ
What is an ISO 27001 readiness assessment?
A clause-by-clause and control-by-control comparison of your position against the standard, with a draft Statement of Applicability and a remediation plan.
Can our certification body do the readiness assessment?
No. ISO/IEC 17021 prevents a certification body from consulting on the system it will certify.
How long does readiness take?
Two to four weeks for most organisations, including the delivery call.
What does readiness cost?
Typically £5,000 to £15,000, scaling with scope, sites and headcount within scope.
Do we need readiness if we hold SOC 2?
It is usually shorter, because much of the control substance transfers, but the management system requirements in Clauses 4 to 10 are new work.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings clause by clause and control by control rather than issuing an opinion. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.