Ga naar de inhoud
Kosten & Budget
11 min leestijd

Estimate ISO 27001 Costs and Timeline From Your Readiness Assessment

support@ismscalculator.com|

Compliance lead reviewing ISO readiness plan

Run a short readiness check now. It turns vague anxiety about your certification date into a prioritized gap list you can actually work through, mapped against ISO/IEC 27001 and its Annex A controls. If you already have a risk register, start converting it into a Statement of Applicability today, using a tool to estimate the remaining work rather than rely on guesswork.


TL;DR:

  • Completing an ISO 27001 readiness assessment requires documented evidence for all Clauses 4-10, with a focus on the risk register, policies, and internal audits.
  • Organizing evidence by Annex A themes and having a clear, traceable Statement of Applicability prevents common audit red flags.
  • Stage 1 audits review documentation, while Stage 2 tests control operation through logs and interviews, with duration influenced by staff and system complexity.
  • Prioritize fixing major gaps like missing policies and risk assessments early, aiming to have controls and internal audits mature before the formal audit.
  • Using benchmarking tools and a structured gap analysis helps generate realistic timelines and budgets, improving certification readiness planning.

Ismscalculator
Estimate Your ISO 27001 Journey
Get a tailored estimate based on your company size, industry, and security maturity, with benchmarks to support realistic planning.
Estimate your ISO 27001 costs

Table of Contents

How Do You Assess ISO 27001 Readiness?

An ISO 27001 readiness assessment measures how close your information security management system (ISMS) is to satisfying Clauses 4 through 10 and the Annex A controls, before you pay a certification body to find the gaps for you. Auditors evaluate two things: whether the mandatory clauses are documented and whether the controls you selected in your Statement of Applicability (SoA) are actually operating, not just written down. Below is a compact checklist mapped to what a Stage 1 auditor will actually ask to see.

Clauses 4 to 10, condensed into evidence you need on hand:

  • Context and scope (Clause 4): a written ISMS scope statement naming which sites, systems, and data are in and out.
  • Leadership (Clause 5): a signed information security policy and an org chart showing who owns the ISMS.
  • Planning (Clause 6): a risk assessment methodology, a completed risk register, and security objectives with owners and dates.
  • Support (Clause 7): training records, a documented awareness program, and a controlled document repository.
  • Operation (Clause 8): evidence the risk treatment plan is executed, asset inventories, and change records.
  • Performance evaluation (Clause 9): internal audit reports, metrics tied to objectives, and management review minutes.
  • Improvement (Clause 10): a corrective action log showing nonconformities were tracked to closure.

Annex A in the 2022 revision holds 93 controls across four themes: Organizational, People, Physical, and Technological. You do not need all Annex A controls in force. You need a documented, defensible reason for every one you exclude, recorded in the SoA.

The most overlooked scoping trap: teams assume the Physical and People themes don’t apply because they’re “cloud-native.” Auditors still expect a clean-desk policy, screen-lock enforcement, and background-check records for anyone touching sensitive data, remote or not.

Pro Tip: Build a single evidence folder per Annex A theme now, even before your gap analysis is finished. Auditors reward organized evidence almost as much as complete evidence.

What Should a Readiness Self-Assessment Cover?

A short questionnaire, answered honestly by the people who actually run each control, tells you more in twenty minutes than a glossy audit checklist you fill out alone. Structure it around the four Annex A themes plus your management-clause maturity, using roughly ten to fourteen yes/partial/no questions such as:

  1. Do you have a documented, approved information security policy reviewed in the last 12 months?
  2. Is there a current risk register with owners assigned to each identified risk?
  3. Can you produce a complete, up-to-date asset inventory covering hardware, software, and data?
  4. Do you run background checks before granting access to sensitive systems?
  5. Is physical access to server rooms or data centers logged and reviewed?
  6. Do you have centralized logging and someone who reviews those logs regularly?
  7. Has security awareness training been delivered and tracked in the last year?
  8. Have you completed at least one internal audit cycle with documented findings?

Score each “yes” as 1, “partial” as 0.5, “no” as 0, then divide by the total. Sort every “no” into critical (blocks certification outright) versus partial (weakens evidence but isn’t fatal), and let that split drive your remediation order.

Turning Gaps Into a Defensible Statement of Applicability

Your Statement of Applicability is the document auditors scrutinize hardest, and it’s also where most Stage 1 findings originate. The SoA has to trace a straight line from identified risk to treatment decision to control selection or exclusion, and it needs version control showing that line has stayed consistent as your risk register evolved.

The practical sequence looks like this:

  • Build or update the risk register first, with named owners and current risk ratings.
  • Draft a risk treatment plan showing how each significant risk gets mitigated, accepted, transferred, or avoided.
  • Populate the SoA control by control, citing the specific risk each selected control addresses.
  • For every excluded control, write a one or two sentence justification tied to scope, not convenience.
  • Version the document and log every change with a date and reason.

Auditors treat a few patterns as immediate red flags: exclusions with no justification, controls listed in the SoA that don’t trace back to anything in the risk register, and an SoA that doesn’t match the current risk treatment plan because one got updated and the other didn’t. The auditing practices guidance on SoA is explicit that these mismatches get flagged fast.

Pro Tip: Before you submit for Stage 1, have someone who did not write the SoA review it cold. If they can’t trace a control back to a risk in under a minute, your auditor won’t be able to either.

What Happens During Stage 1 and Stage 2 Audits?

Stage 1 is a documentation review. The auditor checks whether your ISMS scope, policies, risk register, and SoA exist, are internally consistent, and cover the mandatory clauses. Stage 2 is where they test whether those documents describe reality, pulling logs, interviewing staff, and sampling evidence that controls actually operate day to day.

How long that takes isn’t arbitrary. IAF MD5 sets the formula certification bodies use, and it runs on a handful of concrete inputs:

  • Total employee count within the certification scope.
  • Number of physical sites and how work is distributed across them.
  • System and process complexity, including how many services touch the ISMS.
  • Whether you’re running an integrated management system (ISO 27001 alongside ISO 9001 or ISO 14001, for instance), which can earn up to a 20% reduction in audit time.

An ISMS where evidence collection is baked into daily operations, tickets automatically logging changes, access reviews running on a schedule, tends to move through Stage 2 with far less friction than one where someone assembles evidence manually the week before the audit. Get quotes from two or three accredited certification bodies early using your actual employee count and site list. Estimates vary more than people expect once complexity factors get applied.

How Do You Prioritize Remediation Before Stage 1?

Fix the gaps that block certification outright before you touch anything cosmetic. That means missing policies, an absent risk register, and no evidence of an internal audit cycle jump to the front of the queue, ahead of things like refining a training slide deck.

A realistic sequence, tied to your self-assessment score:

  1. Weeks 2 to 4: draft or finalize missing policies, stand up a basic asset inventory, and appoint clear control owners.
  2. Weeks 4 to 12: complete the risk assessment, populate the SoA, implement centralized logging, and run your first internal audit.
  3. Months 3 to 6: close corrective actions from that internal audit, run a management review, and let evidence accumulate long enough to look mature rather than freshly manufactured.

Auditors accept records over assertions every time. A policy that says training happens is worth far less than a spreadsheet showing who completed it and when. Schedule your internal audit and management review deliberately before Stage 1, not as an afterthought, since both are mandatory clause requirements and both generate exactly the kind of evidence Stage 1 reviewers want to see.

Pro Tip: If your internal audit surfaces more than a handful of major findings, push your Stage 1 date back rather than hoping the auditor won’t notice. They will.

How Do You Prioritize Remediation Before Stage 1? — overview diagram

How Tools and Benchmarks Speed Up ISO 27001 Readiness

A readiness score only becomes useful once it’s translated into a timeline and a budget. Benchmarking against industry data turns a raw gap count into a realistic project plan instead of a guess pulled from a consultant’s memory.

Readiness score flowing into budget timeline

What Practitioners Get Wrong About Readiness Prep

Most Stage 1 findings trace back to three blind spots: an SoA that doesn’t cleanly trace to the risk register, People and Physical controls dismissed as irrelevant for cloud-first teams, and evidence scattered across five different tools with nobody owning the folder. None of these are hard problems. They’re organizational ones.

The fix is almost boring in its simplicity: centralize evidence by Annex A theme, use policy templates instead of writing from scratch, and track your awareness program the same way you’d track a sales pipeline, with dates and completion rates, not a one-time email blast. If you want a one-line test for leadership, ask this: “If an auditor asked for evidence of any single control right now, could someone find it in under five minutes?” If the honest answer is no, that’s your actual priority list, not whatever gap analysis spreadsheet is sitting in a shared drive.

— Martin

Get a Cost and Timeline Estimate for Your ISO 27001 Gap List

A gap analysis tells you what’s missing. It doesn’t tell you what closing those gaps will cost or how long Stage 1 readiness will actually take, and that’s the piece most checklists skip entirely. ISMS Calculator fills that gap with a real-time cost and effort calculator that factors in your company size, industry, and current security maturity to produce estimates you can actually plan a budget around, not a generic model reference value.

Ismscalculator

Start with the free 2-minute readiness check if you just need a quick maturity snapshot across the four Annex A control themes. If you’re further along and need a full prioritized remediation plan tied to Annex A mapping, the ISO 27001 Readiness Assessment generates an exportable gap report and a customizable timeline you can hand straight to leadership, along with the option to save and compare multiple estimates as your scope evolves.

Where to Go for Authoritative ISO 27001 Guidance

Start with ISO/IEC 27001:2022 for the actual certification requirements and ISO/IEC 27002 for implementation guidance on individual controls. For audit-duration math, IAF MD5 is the definitive source certification bodies use.

Sources

FAQ

What Is an ISO 27001 Readiness Assessment?

It’s a structured review, usually a checklist paired with a scored questionnaire, that measures how close your ISMS is to meeting Clauses 4 through 10 and Annex A before you schedule a formal Stage 1 audit. Tools like the ISO 27001 Readiness Assessment automate the scoring and generate a gap report.

How Long Does ISO 27001 Certification Take After a Readiness Check?

Audit duration itself is calculated separately, using the IAF MD5 formula based on employee count, sites, and complexity.

What’s the Difference Between a Gap Analysis and an SoA?

A gap analysis identifies where your current controls fall short of Annex A requirements. The Statement of Applicability is the formal document that maps each of the 93 controls to your risk register, stating whether it’s applied and why, or justifying its exclusion.

Can Integrated Management Systems Reduce Audit Time?

Yes. Under IAF MD5, certification bodies can adjust audit time by up to 20% for organizations running an integrated management system, such as ISO 27001 alongside ISO 9001, because evidence collection overlaps across standards.

Does ISMS Calculator Cost Anything to Try?

The free 2-minute readiness check has no published price and requires no signup to get an initial maturity snapshot. Pricing for the full cost calculator and readiness assessment is available directly on the ISMS Calculator site.

Klaar om uw ISO 27001-kosten te schatten?

Gebruik onze gratis calculator voor een op maat gemaakte schatting van kosten, inspanning en planning op basis van uw bedrijfsprofiel.

Bereken uw raming — gratis
Terug naar alle artikelen