Hael
Book a meeting
ISO 27001 · Readiness

ISO 27001 Readiness and Compliance Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Readiness establishes what the standard requires of you specifically and what you already have.
  • The deliverable is a clause-by-clause and control-by-control position plus a draft Statement of Applicability, not an opinion that you are ready.
  • Run readiness before booking a certification body, so remediation happens on your timetable.
  • Readiness typically costs £5,000 to £15,000 and takes two to four weeks.
  • The most common finding is that controls operate but leave no retained record an auditor can sample.

What readiness establishes

ISO 27001 readiness services establish where you stand before you commit to a certification date. The output is a clause-by-clause position against Clauses 4 to 10, a control-by-control position against the 93 Annex A controls, a draft view of your Statement of Applicability, and a remediation plan.

Compliance services then cover the build: writing the ISMS, running it long enough to generate records, completing the internal audit and management review, and supporting the certification audit.

What a readiness assessment should contain

ElementWhat good looks like
Scope proposalWhich organisational units, services, locations and information the ISMS will cover, and what is excluded
Asset and system pictureWhat is in scope, who owns it, and where information lives
Clause-by-clause positionClauses 4 to 10 assessed individually, with current evidence and a judgement on sufficiency
Control-by-control positionAll 93 Annex A controls assessed as applicable or not, with draft justifications
Risk assessment approachHow risks will be identified, assessed and treated, and how that justifies control selection
Remediation planWhat closes each gap, who does it, how long it takes
Certification routeWhich accredited bodies are appropriate, and the earliest defensible audit window
Delivery callA conversation where the scope decisions and borderline judgements get explained

Findings should be stated as findings. “These clauses are met, these are not, here is what closes each” is defensible. “You are ready to certify” is a warranty, and the certification body makes that decision, not your adviser.

When to run readiness

Before you engage a certification body, and before you write documentation.

Certification bodies price from scope and maturity, so knowing both produces an accurate quote. And anything found at Stage 1 delays Stage 2, which moves your certificate date by weeks in a market where audit slots are booked ahead.

Our readiness and gap assessment is a fixed fee with a delivery call for that reason.

Readiness versus certification

They cannot be combined, and the reason is structural.

Readiness is advisory. Its purpose is to help you, and the firm doing it can tell you exactly what to fix and how.

Certification is independent. Under ISO/IEC 17021 the certification body cannot consult on the system it will certify. Your certifier cannot help you prepare, which is why readiness exists as a separate service.

What readiness commonly finds

Controls that operate but leave no record. Access is reviewed, but in a spreadsheet that is overwritten each quarter, so nothing survives for the auditor to sample.

No defined scope. Every conversation about controls goes in circles until someone decides what is in.

A risk assessment written after the control list. The standard expects control selection to follow from risk. Where the order was reversed, auditors notice.

The eleven new controls not addressed. Threat intelligence, cloud security, configuration management, data masking, data leakage prevention, monitoring, web filtering and secure coding are the usual gaps for organisations with an older security posture.

Supplier security handled informally. A.5.19 to A.5.23 cover supplier relationships, and most organisations have contracts but no assessment records.

The climate consideration missing. Amendment 1 of February 2024 requires it in the context analysis. A one-paragraph fix, routinely raised when absent.

No independent internal auditor. Clause 9.2 requires one, and small organisations rarely have someone who understands the ISMS and did not build it.

Cost and timing

ServiceTypical costTypical duration
Readiness and gap analysis£5,000 to £15,0002 to 4 weeks
Implementation and build£15,000 to £50,0002 to 4 months
Operating period before auditInternal effortLong enough to produce records
Internal audit£4,000 to £12,0001 to 2 weeks
Certification body, Stage 1 and Stage 2£5,000 to £20,0004 to 8 weeks including scheduling

Cost scales with scope, headcount within scope, number of sites and existing maturity.

What compliance services cover after readiness

Writing the information security policy and assigning roles. Building the risk assessment and treatment process. Producing the Statement of Applicability with justified inclusions and exclusions. Implementing the control set. Establishing supplier security assessment. Setting up logging, monitoring and incident response. Establishing the evidence cadence. Then running the ISMS, the internal audit, the management review, and supporting both audit stages.

What to do next

Decide your scope, at least provisionally. It is the input every proposal needs and the decision that most affects cost.

Our free readiness diagnostic gives an immediate first view, and the ISO 27001 service page sets out how readiness and implementation fit together.

References

FAQ

What is an ISO 27001 readiness assessment?

A clause-by-clause and control-by-control comparison of your position against the standard, with a draft Statement of Applicability and a remediation plan.

Can our certification body do the readiness assessment?

No. ISO/IEC 17021 prevents a certification body from consulting on the system it will certify.

How long does readiness take?

Two to four weeks for most organisations, including the delivery call.

What does readiness cost?

Typically £5,000 to £15,000, scaling with scope, sites and headcount within scope.

Do we need readiness if we hold SOC 2?

It is usually shorter, because much of the control substance transfers, but the management system requirements in Clauses 4 to 10 are new work.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings clause by clause and control by control rather than issuing an opinion. We are not a certification body and we do not issue certificates. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.