ISO/IEC 27001 Readiness

Structured ISO/IEC 27001 readiness support to help organisations prepare for certification in an evidence-aware, audit-ready, and proportionate way.

ISO/IEC 27001 readiness is the process of assessing whether an organisation is prepared to implement and certify an Information Security Management System (ISMS). It focuses on identifying gaps, confirming evidence, and ensuring alignment with certification expectations before engaging a certification body.

Poleis supports organisations throughout the full readiness journey — from defining scope, to gap analysis, Statement of Applicability (SoA), and internal audit preparation — helping reduce risk and avoid surprises during certification.

ISMS scope definition

A clear and well-defined ISMS scope is essential for a successful ISO/IEC 27001 implementation and certification.

We support scope definition by helping you identify:

The scope is reviewed to ensure it is realistic, auditable, and aligned with your business objectives and risk profile.

ISO/IEC 27001 gap analysis

We perform a structured gap analysis against:

The assessment focuses on both documentation and operational effectiveness. Particular attention is given to evidence availability and consistency.

Each requirement is assessed and classified (for example: in place, partially in place, or not in place), with clear and prioritised recommendations to close gaps.

Statement of Applicability (SoA)

The Statement of Applicability is a critical audit artefact and a common source of certification findings.

Poleis supports the creation or review of the SoA, ensuring:

This ensures the SoA is defensible, traceable, and aligned with auditor expectations.

Risk assessment alignment

We review your information security risk assessment to confirm it aligns with ISO/IEC 27001 requirements and Annex A control selection.

This includes reviewing:

This step helps avoid common audit findings related to weak or inconsistent risk-control alignment.

Internal audit support

Internal audit is a mandatory requirement before certification. We support internal audit readiness by:

The objective is to identify and address issues before the certification audit, not during it.

How we work

Our ISO/IEC 27001 readiness approach is:

Who this service is for

This service is suitable for organisations that:

Next steps

If you are planning ISO/IEC 27001 certification and want a clear and structured view of your readiness, we can help.

Contact us to discuss ISO/IEC 27001 readiness