ISO/IEC 27001 readiness is the process of assessing whether an organisation
is prepared to implement and certify an Information Security Management System (ISMS).
It focuses on identifying gaps, confirming evidence, and ensuring alignment
with certification expectations before engaging a certification body.
Poleis supports organisations throughout the full readiness journey — from
defining scope, to gap analysis, Statement of Applicability (SoA), and internal
audit preparation — helping reduce risk and avoid surprises during certification.
ISMS scope definition
A clear and well-defined ISMS scope is essential for a successful ISO/IEC 27001
implementation and certification.
We support scope definition by helping you identify:
- Organisational boundaries and locations
- In-scope systems, processes, and information assets
- Interfaces with suppliers and third parties
- Exclusions and assumptions
The scope is reviewed to ensure it is realistic, auditable, and aligned with
your business objectives and risk profile.
ISO/IEC 27001 gap analysis
We perform a structured gap analysis against:
- ISO/IEC 27001 clauses (4–10)
- Annex A controls (ISO/IEC 27001:2022)
The assessment focuses on both documentation and operational effectiveness.
Particular attention is given to evidence availability and consistency.
Each requirement is assessed and classified (for example: in place, partially
in place, or not in place), with clear and prioritised recommendations to close gaps.
Statement of Applicability (SoA)
The Statement of Applicability is a critical audit artefact and a common source
of certification findings.
Poleis supports the creation or review of the SoA, ensuring:
- Clear inclusion and exclusion decisions for Annex A controls
- Justifications aligned to risk assessment results
- Consistency between controls, implementation, and evidence
This ensures the SoA is defensible, traceable, and aligned with auditor expectations.
Risk assessment alignment
We review your information security risk assessment to confirm it aligns with
ISO/IEC 27001 requirements and Annex A control selection.
This includes reviewing:
- Risk identification and evaluation approach
- Risk treatment decisions
- Linkage between risks, controls, and residual risk
This step helps avoid common audit findings related to weak or inconsistent
risk-control alignment.
Internal audit support
Internal audit is a mandatory requirement before certification.
We support internal audit readiness by:
- Reviewing internal audit plans and scope
- Conducting independent internal audits (where appropriate)
- Supporting evidence preparation
- Assisting with management review inputs
The objective is to identify and address issues before the certification audit,
not during it.
How we work
Our ISO/IEC 27001 readiness approach is:
- Structured — aligned to the standard and certification expectations
- Evidence-aware — focused on what auditors actually test
- Practical — based on real implementation and audit experience
- Proportionate — tailored to your organisation’s size and risk
Who this service is for
This service is suitable for organisations that:
- Are preparing for first-time ISO/IEC 27001 certification
- Are transitioning to ISO/IEC 27001:2022
- Want an independent readiness assessment
- Need structured support before engaging a certification body
Next steps
If you are planning ISO/IEC 27001 certification and want a clear and structured
view of your readiness, we can help.
Contact us to discuss ISO/IEC 27001 readiness