Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Certification Readiness Self-Assessment

Scores readiness across clause and Annex A requirements and returns an estimated time-to-certification with the specific blocking items.

Available soon

Format
Excel
Size
112 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Settings
  • Assessment
  • Example Answers
  • Results by Requirement
  • Summary & Estimate
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Scope: assess the ISMS as defined in your approved scope (clause 4.3). Every clause requirement applies; an Annex A control can be marked not applicable only where your Statement of Applicability excludes it, with the same reason (IS-03). Assess monthly from the start of Phase 4 until certification (IS-10: "Readiness must be reassessed monthly from the start of Phase 4 until certification.").
2Settings: enter your as-at date (today's date, or =TODAY()), your planned Stage 1 and Stage 2 audit dates, and the planned end of the internal audit fieldwork and date of the management review, in column D. The EXAMPLE values in column E are used while D5 says the example.
3Assessment: for each row, answer Applicable? (controls only), then the readiness score 0 to 3 from the drop-down, using the anchors below. Choose the lower score when in doubt: the score describes what an auditor could see today, not what is planned.
4For a score of 2 or 3, enter the date it went In place (column I). For a score of 0 or 1, name the owner (column J) and estimate the weeks of work still needed to put it in place (column K), counting the owner's real availability. Note the evidence in column L.
5Settings: change D5 from 'Example organisation' to 'My answers'. The Results by Requirement and Summary & Estimate sheets now describe your organisation.
6Summary & Estimate: read the counts ('x of y at Operating'), the blockers, the three steps of the estimate and the verdict against your planned Stage 2 date. The blocking items list is the order to work in.
7Copy every row below Operating into the ISMS Gap & Remediation Tracker with its owner, weeks and dates, and track it there. The tracker uses the same calculation, so its weeks to certification (ISM-04) match this workbook's.
8Export: select the Results by Requirement table, copy, and paste as values into your records. Keep each month's copy so you can compare.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The readiness scale and what each score means for a requirement:

0 — Not started: Nothing exists yet.

1 — Planned: Owner and approach agreed; not yet in place.

2 — In place: Documented and working, but little or no record yet.

3 — Operating: Working, with records covering at least [[3]] months, and an auditor could sample it. This workbook uses 3 months (IS-05); change it on the Settings sheet if your certification body expects more.

Examples of the anchors. Clause 9.2.2 at 1: the audit programme is being drafted and an auditor is being chosen. At 2: the programme is approved and the first audit has started. At 3: at least one audit cycle is complete with a report, and its findings are in the corrective action log. Annex A 8.13 at 2: backups run to an approved standard but no restore test is recorded yet; at 3: [[3]] months of backup logs and at least one recorded restore test.

Blockers (weights). 8 clause requirements are blockers: without them a Stage 2 audit cannot pass. They are 4.3 Determining the scope of the information security management system; 5.2 Policy; 6.1.2 Information security risk assessment; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 9.2.2 Internal audit programme; 9.3.3 Management review results; 10.2 Nonconformity and corrective action. Blockers come first in every owner's queue (IS-08: "Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date.") and all must be at Operating before the Stage 2 date (ISM-01).

How the estimate is worked out. (a) Remaining work: each owner works through their items below In place one after another, blockers first, then in the standard's order, starting from the as-at date; the last item's date is when the work is done. Items at In place need no more work, only time. (b) IS-05: "The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit." — the last blocker's In place date plus 3 months. (c) IS-06: "At least one full internal audit cycle and one management review must be completed before Stage 2." — the later of your planned management review, your planned end of audit fieldwork, and the earliest possible end of the Check phase (the audit programme in place, plus 4 weeks, the Check phase in the ISO 27001 Implementation Methodology & Project Plan). The earliest Stage 2 date is the latest of the three. Weeks are calendar weeks.

The critical path: an item is on it when a slip of 2 weeks or less would move the estimated Stage 2 date (Settings, 'Critical-path float'). For a blocker the date that counts is when it reaches Operating; for any other item, when it is In place.

The worked example: while D5 says 'Example organisation', results come from the Example Answers sheet: the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), which started its ISMS project on 2026-04-06 and has booked Stage 1 for 2027-01-18 and Stage 2 for 2027-03-01, as at 2026-09-30. To clear the example, set D5 to 'My answers' and fill column D of the Settings sheet. Keep the Example Answers sheet: the results read it whenever D5 is set back to the example.

Tailoring — small organisation: the scale works the same with fewer people, but the owner queue is shorter and usually one person long. Be honest about that person's weeks; in a small organisation the ISMS manager's queue is nearly always the critical path. A contracted internal auditor is normal and satisfies IS-07.

Tailoring — regulated entity: certification to ISO/IEC 27001:2022 is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Assess the same requirements, and add the regulatory duties to your register of legal requirements (Annex A 5.31). A supervisor may ask for this assessment and its history: keep each month's export.

Tailoring — IT run by a service provider: score a control for what you can evidence, not for what the provider says it does. Where the provider operates a control, the owner in column J is the person who manages the provider, and 'In place' needs the provider's records to be available to you and to the auditor.

Limitations: see the foot of the Summary & Estimate sheet.

Settings

Settings

Choose which answers the results use, and set the dates and numbers the estimate needs. Column D is yours; column E holds the EXAMPLE.

Results useExample organisationEXAMPLE — change to 'My answers' once you have answered the Assessment sheet and filled column D below.
SettingYour valueEXAMPLEValue usedNote
As-at date30 Sep 202630 Sep 2026EXAMPLE — the example's as-at date. Enter today's date, or =TODAY(). Every forecast counts from it.
Planned Stage 1 audit18 Jan 202718 Jan 2027The date booked with your certification body. Shown for reference; the estimate is for Stage 2.
Planned Stage 2 audit1 Mar 20271 Mar 2027The date booked with your certification body. The verdict compares the estimate with it.
Internal audits end (planned)9 Dec 20269 Dec 2026Leave blank if not planned yet; the estimate then uses the earliest possible end of the Check phase.
Management review (planned)6 Jan 20276 Jan 2027After the audit report, so the review can consider it (clause 9.3.2).
Months of operation before Stage 2 (IS-05)333The [[3]] in IS-05 and in the Operating anchor. Ask your certification body; some expect more.
Check phase: audit programme in place to review done (weeks)444PH-5 Check: 4 weeks in the ISO 27001 Implementation Methodology & Project Plan.
Critical-path float (weeks)222An item whose slip of this many weeks or fewer would move the estimate is on the critical path.

Assessment

Your answers, one row per requirement. Score each from 0 to 3 using the anchors on the Instructions sheet. Clauses are always applicable.

IDKindClause or themeRequirement (number and title only)Blocker?Applicable? (controls)Reason if not applicable (as in your SoA)Readiness (0–3)In place since (score 2 or 3)Owner (score 0 or 1)Weeks of work to In placeEvidence and notes
4.1Clause4Understanding the organization and its contextNoYes
4.2Clause4Understanding the needs and expectations of interested partiesNoYes
4.3Clause4Determining the scope of the information security management systemYesYes
4.4Clause4Information security management systemNoYes
5.1Clause5Leadership and commitmentNoYes
5.2Clause5PolicyYesYes
5.3Clause5Organizational roles, responsibilities and authoritiesNoYes
6.1.1Clause6GeneralNoYes
6.1.2Clause6Information security risk assessmentYesYes
6.1.3Clause6Information security risk treatmentYesYes
6.2Clause6Information security objectives and planning to achieve themYesYes
6.3Clause6Planning of changesNoYes
7.1Clause7ResourcesNoYes
7.2Clause7CompetenceNoYes
7.3Clause7AwarenessNoYes
7.4Clause7CommunicationNoYes
7.5.1Clause7GeneralNoYes
7.5.2Clause7Creating and updatingNoYes
7.5.3Clause7Control of documented informationNoYes
8.1Clause8Operational planning and controlNoYes
8.2Clause8Information security risk assessmentNoYes
8.3Clause8Information security risk treatmentNoYes
9.1Clause9Monitoring, measurement, analysis and evaluationNoYes
9.2.1Clause9GeneralNoYes
9.2.2Clause9Internal audit programmeYesYes
9.3.1Clause9GeneralNoYes
9.3.2Clause9Management review inputsNoYes
9.3.3Clause9Management review resultsYesYes
10.1Clause10Continual improvementNoYes
10.2Clause10Nonconformity and corrective actionYesYes
A.5.1Annex AA.5Policies for information securityNo
A.5.2Annex AA.5Information security roles and responsibilitiesNo
A.5.3Annex AA.5Segregation of dutiesNo
A.5.4Annex AA.5Management responsibilitiesNo
A.5.5Annex AA.5Contact with authoritiesNo
A.5.6Annex AA.5Contact with special interest groupsNo
A.5.7Annex AA.5Threat intelligenceNo
A.5.8Annex AA.5Information security in project managementNo
A.5.9Annex AA.5Inventory of information and other associated assetsNo
A.5.10Annex AA.5Acceptable use of information and other associated assetsNo
A.5.11Annex AA.5Return of assetsNo
A.5.12Annex AA.5Classification of informationNo
A.5.13Annex AA.5Labelling of informationNo
A.5.14Annex AA.5Information transferNo
A.5.15Annex AA.5Access controlNo
A.5.16Annex AA.5Identity managementNo
A.5.17Annex AA.5Authentication informationNo
A.5.18Annex AA.5Access rightsNo
A.5.19Annex AA.5Information security in supplier relationshipsNo
A.5.20Annex AA.5Addressing information security within supplier agreementsNo
A.5.21Annex AA.5Managing information security in the ICT supply chainNo
A.5.22Annex AA.5Monitoring, review and change management of supplier servicesNo
A.5.23Annex AA.5Information security for use of cloud servicesNo
A.5.24Annex AA.5Information security incident management planning and preparationNo
A.5.25Annex AA.5Assessment and decision on information security eventsNo
A.5.26Annex AA.5Response to information security incidentsNo
A.5.27Annex AA.5Learning from information security incidentsNo
A.5.28Annex AA.5Collection of evidenceNo
A.5.29Annex AA.5Information security during disruptionNo
A.5.30Annex AA.5ICT readiness for business continuityNo
A.5.31Annex AA.5Legal, statutory, regulatory and contractual requirementsNo
A.5.32Annex AA.5Intellectual property rightsNo
A.5.33Annex AA.5Protection of recordsNo
A.5.34Annex AA.5Privacy and protection of PIINo
A.5.35Annex AA.5Independent review of information securityNo
A.5.36Annex AA.5Compliance with policies, rules and standards for information securityNo
A.5.37Annex AA.5Documented operating proceduresNo
A.6.1Annex AA.6ScreeningNo
A.6.2Annex AA.6Terms and conditions of employmentNo
A.6.3Annex AA.6Information security awareness, education and trainingNo
A.6.4Annex AA.6Disciplinary processNo
A.6.5Annex AA.6Responsibilities after termination or change of employmentNo
A.6.6Annex AA.6Confidentiality or non-disclosure agreementsNo
A.6.7Annex AA.6Remote workingNo
A.6.8Annex AA.6Information security event reportingNo
A.7.1Annex AA.7Physical security perimetersNo
A.7.2Annex AA.7Physical entryNo
A.7.3Annex AA.7Securing offices, rooms and facilitiesNo
A.7.4Annex AA.7Physical security monitoringNo
A.7.5Annex AA.7Protecting against physical and environmental threatsNo
A.7.6Annex AA.7Working in secure areasNo
A.7.7Annex AA.7Clear desk and clear screenNo
A.7.8Annex AA.7Equipment siting and protectionNo
A.7.9Annex AA.7Security of assets off-premisesNo
A.7.10Annex AA.7Storage mediaNo
A.7.11Annex AA.7Supporting utilitiesNo
A.7.12Annex AA.7Cabling securityNo
A.7.13Annex AA.7Equipment maintenanceNo
A.7.14Annex AA.7Secure disposal or re-use of equipmentNo
A.8.1Annex AA.8User endpoint devicesNo
A.8.2Annex AA.8Privileged access rightsNo
A.8.3Annex AA.8Information access restrictionNo
A.8.4Annex AA.8Access to source codeNo
A.8.5Annex AA.8Secure authenticationNo
A.8.6Annex AA.8Capacity managementNo
A.8.7Annex AA.8Protection against malwareNo
A.8.8Annex AA.8Management of technical vulnerabilitiesNo
A.8.9Annex AA.8Configuration managementNo
A.8.10Annex AA.8Information deletionNo
A.8.11Annex AA.8Data maskingNo
A.8.12Annex AA.8Data leakage preventionNo
A.8.13Annex AA.8Information backupNo
A.8.14Annex AA.8Redundancy of information processing facilitiesNo
A.8.15Annex AA.8LoggingNo
A.8.16Annex AA.8Monitoring activitiesNo
A.8.17Annex AA.8Clock synchronizationNo
A.8.18Annex AA.8Use of privileged utility programsNo
A.8.19Annex AA.8Installation of software on operational systemsNo
A.8.20Annex AA.8Networks securityNo
A.8.21Annex AA.8Security of network servicesNo
A.8.22Annex AA.8Segregation of networksNo
A.8.23Annex AA.8Web filteringNo
A.8.24Annex AA.8Use of cryptographyNo
A.8.25Annex AA.8Secure development life cycleNo
A.8.26Annex AA.8Application security requirementsNo
A.8.27Annex AA.8Secure system architecture and engineering principlesNo
A.8.28Annex AA.8Secure codingNo
A.8.29Annex AA.8Security testing in development and acceptanceNo
A.8.30Annex AA.8Outsourced developmentNo
A.8.31Annex AA.8Separation of development, test and production environmentsNo
A.8.32Annex AA.8Change managementNo
A.8.33Annex AA.8Test informationNo
A.8.34Annex AA.8Protection of information systems during audit testingNo

Example Answers

EXAMPLE — the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), as at 2026-09-30, about six months into its ISMS project.

ExampleIDKindClause or themeRequirement (number and title only)Blocker?Applicable? (controls)Reason if not applicable (as in your SoA)Readiness (0–3)In place since (score 2 or 3)Owner (score 0 or 1)Weeks of work to In placeEvidence and notes
EXAMPLE4.1Clause4Understanding the organization and its contextNoYes327 Apr 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-04-27, with records covering more than 3 months.
EXAMPLE4.2Clause4Understanding the needs and expectations of interested partiesNoYes327 Apr 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-04-27, with records covering more than 3 months.
EXAMPLE4.3Clause4Determining the scope of the information security management systemYesYes311 May 2026Chief Operating OfficerEXAMPLE — Operating: in place since 2026-05-11, with records covering more than 3 months.
EXAMPLE4.4Clause4Information security management systemNoYes224 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. The ISMS processes and how they connect are described in the ISMS manual; it has run as a whole only since late August.
EXAMPLE5.1Clause5Leadership and commitmentNoYes36 Apr 2026Chief Operating OfficerEXAMPLE — Operating: in place since 2026-04-06, with records covering more than 3 months.
EXAMPLE5.2Clause5PolicyYesYes312 Mar 2026Chief Operating OfficerEXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months.
EXAMPLE5.3Clause5Organizational roles, responsibilities and authoritiesNoYes23 Aug 2026Chief Operating OfficerEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. Roles and responsibilities approved in August; control owners confirmed their roles in writing.
EXAMPLE6.1.1Clause6GeneralNoYes26 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLE6.1.2Clause6Information security risk assessmentYesYes315 Jun 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-06-15, with records covering more than 3 months.
EXAMPLE6.1.3Clause6Information security risk treatmentYesYes224 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. Statement of Applicability and risk treatment plan approved on 2026-08-24; treatment is under way.
EXAMPLE6.2Clause6Information security objectives and planning to achieve themYesYes1Head of Information Security3EXAMPLE — Gap: Objectives drafted but not approved; no measure, owner or date for each. Action: Agree five to seven measurable objectives, each with an owner, a measure and a date; have top management approve them and communicate them.
EXAMPLE6.3Clause6Planning of changesNoYes1Chief Operating Officer1EXAMPLE — Gap: No agreed way to plan changes to the ISMS itself (scope, roles, processes). Action: Add a short ISMS change step to the steering group's agenda (the Chief Operating Officer chairs it): purpose, consequences, resources and who is responsible, recorded in the minutes.
EXAMPLE7.1Clause7ResourcesNoYes36 Apr 2026Chief Operating OfficerEXAMPLE — Operating: in place since 2026-04-06, with records covering more than 3 months.
EXAMPLE7.2Clause7CompetenceNoYes21 Sep 2026HR DirectorEXAMPLE — In place since 2026-09-01; 3 months of records by 2026-12-01. Competence requirements for ISMS roles set in September; training records are in the HR system.
EXAMPLE7.3Clause7AwarenessNoYes214 Sep 2026Head of Information SecurityEXAMPLE — In place since 2026-09-14; 3 months of records by 2026-12-14. Awareness campaign launched in September; completion is tracked.
EXAMPLE7.4Clause7CommunicationNoYes23 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03.
EXAMPLE7.5.1Clause7GeneralNoYes224 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLE7.5.2Clause7Creating and updatingNoYes312 Mar 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months.
EXAMPLE7.5.3Clause7Control of documented informationNoYes1Head of Information Security1EXAMPLE — Gap: Two documents are past their review date (AUP-001, BKP-001) and one is awaiting approval (the Supplier Security Policy, P04 register SUP-001) in the policy register. Action: Complete the two overdue reviews, take the Supplier Security Policy (P04 register SUP-001) to its approver, and add a monthly check of review dates to the ISMS manager's routine.
EXAMPLE8.1Clause8Operational planning and controlNoYes26 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLE8.2Clause8Information security risk assessmentNoYes220 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. The first full risk assessment was accepted by risk owners in July; the planned reassessment has not run yet.
EXAMPLE8.3Clause8Information security risk treatmentNoYes1Head of Information Security2EXAMPLE — Gap: Treatment actions are under way but their completion and the residual risk are not recorded. Action: Record each completed treatment action and the residual risk it leaves in the risk register, and have risk owners accept it.
EXAMPLE9.1Clause9Monitoring, measurement, analysis and evaluationNoYes1Head of Information Security3EXAMPLE — Gap: Measures are listed but not yet collected or reported; no one analyses the results. Action: Choose the measures, their owners and frequency; produce the first monthly report and take it to the steering group.
EXAMPLE9.2.1Clause9GeneralNoYes1Head of Information Security1EXAMPLE — Gap: No check yet that each audit has set criteria and scope, an independent auditor and results reported to management. Action: After the first audit cycle, confirm each audit had criteria, scope and an independent auditor (IS-07) and that its results reached management; correct the programme where they did not.
EXAMPLE9.2.2Clause9Internal audit programmeYesYes1Head of Information Security1EXAMPLE — Gap: Internal audit not started: the programme is drafted but not approved, and the contracted auditors are not yet confirmed. Action: Finish the audit programme so it covers every clause and the applicable controls before Stage 2, have the Chief Operating Officer approve it as sponsor, confirm the independent auditors (IS-07) and book the fieldwork.
EXAMPLE9.3.1Clause9GeneralNoYes1Chief Operating Officer1EXAMPLE — Gap: No management review held or scheduled. Action: Schedule the first management review with top management after the internal audit report, and a yearly cycle after that.
EXAMPLE9.3.2Clause9Management review inputsNoYes1Head of Information Security1EXAMPLE — Gap: No template for the inputs the review must consider. Action: Prepare the review pack with every required input, from the Management Review Meeting Pack.
EXAMPLE9.3.3Clause9Management review resultsYesYes1Chief Operating Officer1EXAMPLE — Gap: No review held, so no recorded decisions. Action: Confirm the date, attendees and minute-taker, and a template that records decisions and actions.
EXAMPLE10.1Clause10Continual improvementNoYes1Head of Information Security1EXAMPLE — Gap: Improvements are made but not recorded as such. Action: Keep an improvement log fed by audits, incidents, measures and suggestions, reviewed by the steering group.
EXAMPLE10.2Clause10Nonconformity and corrective actionYesYes1Head of Information Security2EXAMPLE — Gap: Corrective actions are raised only for incidents; no procedure for nonconformities, root cause or effectiveness checks. Action: Approve a nonconformity and corrective action procedure (root cause, correction, corrective action, effectiveness check — IS-09) and start the log.
EXAMPLEA.5.1Annex AA.5Policies for information securityNoYes312 Mar 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months.
EXAMPLEA.5.2Annex AA.5Information security roles and responsibilitiesNoYes23 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03.
EXAMPLEA.5.3Annex AA.5Segregation of dutiesNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.5.4Annex AA.5Management responsibilitiesNoYes23 Aug 2026Chief Operating OfficerEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03.
EXAMPLEA.5.5Annex AA.5Contact with authoritiesNoYes1Head of Information Security1EXAMPLE — Gap: No list of which authorities to contact, when, and who may do it. Action: Record the authorities (regulator, national incident response team, police, data protection authority), the route and who may contact them; link it from the incident procedure.
EXAMPLEA.5.6Annex AA.5Contact with special interest groupsNoYes26 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.5.7Annex AA.5Threat intelligenceNoYes1Head of Information Security2EXAMPLE — Gap: Threat information is read informally; nothing is recorded or acted on. Action: Choose two or three threat sources relevant to the platform, review them weekly, and record what was relevant and what was done.
EXAMPLEA.5.8Annex AA.5Information security in project managementNoYes1Head of Engineering1EXAMPLE — Gap: Security is not a step in the project method. Action: Add a security checkpoint (risks and requirements) to the project start and go-live gates, with a short record.
EXAMPLEA.5.9Annex AA.5Inventory of information and other associated assetsNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.5.10Annex AA.5Acceptable use of information and other associated assetsNoYes31 Jul 2025Head of ITEXAMPLE — Operating: in place since 2025-07-01, with records covering more than 3 months.
EXAMPLEA.5.11Annex AA.5Return of assetsNoYes26 Jul 2026HR DirectorEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.5.12Annex AA.5Classification of informationNoYes217 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-17; 3 months of records by 2026-11-17.
EXAMPLEA.5.13Annex AA.5Labelling of informationNoYes0Head of IT2EXAMPLE — Gap: No labelling of classified information. Action: Apply the classification labels in the document and email tools, default to Internal, and brief staff.
EXAMPLEA.5.14Annex AA.5Information transferNoYes217 Aug 2026Head of Information SecurityEXAMPLE — In place since 2026-08-17; 3 months of records by 2026-11-17.
EXAMPLEA.5.15Annex AA.5Access controlNoYes320 Jan 2026Head of ITEXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months.
EXAMPLEA.5.16Annex AA.5Identity managementNoYes320 Jan 2026Head of ITEXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months.
EXAMPLEA.5.17Annex AA.5Authentication informationNoYes320 Jan 2026Head of ITEXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months.
EXAMPLEA.5.18Annex AA.5Access rightsNoYes23 Aug 2026Head of ITEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. Quarterly access reviews started in August (see the P07 pack).
EXAMPLEA.5.19Annex AA.5Information security in supplier relationshipsNoYes1Head of Procurement1EXAMPLE — Gap: The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied. Action: Obtain approval of the Supplier Security Policy (P04 register SUP-001), publish it, and tier the existing suppliers, using the supplier-assessment templates in the P06 pack.
EXAMPLEA.5.20Annex AA.5Addressing information security within supplier agreementsNoYes1Head of Procurement4EXAMPLE — Gap: Security clauses are missing from most key supplier contracts. Action: Add the security clauses for each supplier tier to the contracts of the Tier 1 suppliers at renewal, or by side letter.
EXAMPLEA.5.21Annex AA.5Managing information security in the ICT supply chainNoYes1Head of Procurement2EXAMPLE — Gap: No check of the security of the software and cloud supply chain. Action: Ask Tier 1 technology suppliers about their own suppliers and components, and record the answers with the supplier assessment.
EXAMPLEA.5.22Annex AA.5Monitoring, review and change management of supplier servicesNoYes1Head of Procurement2EXAMPLE — Gap: Supplier performance and changes are not reviewed for security. Action: Set a review interval per supplier tier and hold the first reviews of Tier 1 suppliers.
EXAMPLEA.5.23Annex AA.5Information security for use of cloud servicesNoYes210 Aug 2026Head of ITEXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10.
EXAMPLEA.5.24Annex AA.5Information security incident management planning and preparationNoYes34 May 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months.
EXAMPLEA.5.25Annex AA.5Assessment and decision on information security eventsNoYes34 May 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months.
EXAMPLEA.5.26Annex AA.5Response to information security incidentsNoYes34 May 2026Head of Information SecurityEXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months.
EXAMPLEA.5.27Annex AA.5Learning from information security incidentsNoYes26 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.5.28Annex AA.5Collection of evidenceNoYes1Legal Counsel1EXAMPLE — Gap: No agreed way to collect and preserve evidence from an incident. Action: Write a one-page evidence-handling note (what to keep, who, how, chain of custody) and add it to the incident procedure.
EXAMPLEA.5.29Annex AA.5Information security during disruptionNoYes27 Sep 2026IT Operations ManagerEXAMPLE — In place since 2026-09-07; 3 months of records by 2026-12-07.
EXAMPLEA.5.30Annex AA.5ICT readiness for business continuityNoYes1IT Operations Manager4EXAMPLE — Gap: Recovery objectives are set but the platform's recovery has not been tested. Action: Test the recovery of the production platform against its recovery objectives and record the result and the fixes.
EXAMPLEA.5.31Annex AA.5Legal, statutory, regulatory and contractual requirementsNoYes1Legal Counsel3EXAMPLE — Gap: No register of legal, regulatory and contractual security requirements. Action: Build the register (including NIS2 duties and customer contract terms), with an owner for each and a yearly review.
EXAMPLEA.5.32Annex AA.5Intellectual property rightsNoYes26 Jul 2026Legal CounselEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.5.33Annex AA.5Protection of recordsNoYes1Legal Counsel2EXAMPLE — Gap: Retention periods are not set for security records. Action: Set retention and protection for the ISMS and security records in the records schedule.
EXAMPLEA.5.34Annex AA.5Privacy and protection of PIINoYes26 Jul 2026Legal CounselEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.5.35Annex AA.5Independent review of information securityNoYes1Chief Operating Officer1EXAMPLE — Gap: No plan for independent review of the ISMS beyond the certification audit. Action: Record in the audit programme how and how often the ISMS is independently reviewed.
EXAMPLEA.5.36Annex AA.5Compliance with policies, rules and standards for information securityNoYes210 Sep 2026Head of Information SecurityEXAMPLE — In place since 2026-09-10; 3 months of records by 2026-12-10. Security Exception & Waiver Standard EXC-STD approved on 2026-09-10.
EXAMPLEA.5.37Annex AA.5Documented operating proceduresNoYes224 Aug 2026IT Operations ManagerEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLEA.6.1Annex AA.6ScreeningNoYes36 Jan 2025HR DirectorEXAMPLE — Operating: in place since 2025-01-06, with records covering more than 3 months.
EXAMPLEA.6.2Annex AA.6Terms and conditions of employmentNoYes26 Jul 2026HR DirectorEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.6.3Annex AA.6Information security awareness, education and trainingNoYes214 Sep 2026Head of Information SecurityEXAMPLE — In place since 2026-09-14; 3 months of records by 2026-12-14.
EXAMPLEA.6.4Annex AA.6Disciplinary processNoYes1HR Director1EXAMPLE — Gap: The disciplinary procedure does not mention information security breaches. Action: Add security breaches to the disciplinary procedure and tell staff through the awareness programme.
EXAMPLEA.6.5Annex AA.6Responsibilities after termination or change of employmentNoYes33 Feb 2025HR DirectorEXAMPLE — Operating: in place since 2025-02-03, with records covering more than 3 months.
EXAMPLEA.6.6Annex AA.6Confidentiality or non-disclosure agreementsNoYes26 Jul 2026HR DirectorEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.6.7Annex AA.6Remote workingNoYes318 Nov 2025Head of ITEXAMPLE — Operating: in place since 2025-11-18, with records covering more than 3 months.
EXAMPLEA.6.8Annex AA.6Information security event reportingNoYes26 Jul 2026Head of Information SecurityEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.1Annex AA.7Physical security perimetersNoYes32 Sep 2024Office ManagerEXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months.
EXAMPLEA.7.2Annex AA.7Physical entryNoYes32 Sep 2024Office ManagerEXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months.
EXAMPLEA.7.3Annex AA.7Securing offices, rooms and facilitiesNoYes26 Jul 2026Office ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.4Annex AA.7Physical security monitoringNoYes1Office Manager2EXAMPLE — Gap: Camera coverage and alarm monitoring of the second office are not confirmed. Action: Agree monitoring of both offices with the landlord, confirm coverage of entrances and the equipment room, and record the check.
EXAMPLEA.7.5Annex AA.7Protecting against physical and environmental threatsNoYes26 Jul 2026Office ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.6Annex AA.7Working in secure areasNoYes26 Jul 2026Office ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.7Annex AA.7Clear desk and clear screenNoYes1Office Manager1EXAMPLE — Gap: No clear desk and clear screen rule. Action: Publish the rule, set screen lock by policy on every device, and check the offices monthly.
EXAMPLEA.7.8Annex AA.7Equipment siting and protectionNoYes26 Jul 2026Office ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.9Annex AA.7Security of assets off-premisesNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.7.10Annex AA.7Storage mediaNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.7.11Annex AA.7Supporting utilitiesNoYes26 Jul 2026IT Operations ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.12Annex AA.7Cabling securityNoYes26 Jul 2026IT Operations ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.13Annex AA.7Equipment maintenanceNoYes26 Jul 2026IT Operations ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.7.14Annex AA.7Secure disposal or re-use of equipmentNoYes1IT Operations Manager1EXAMPLE — Gap: Disposal of laptops and drives is done by a supplier without certificates. Action: Require a destruction certificate for every disposed device and reconcile it with the asset inventory.
EXAMPLEA.8.1Annex AA.8User endpoint devicesNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.2Annex AA.8Privileged access rightsNoYes23 Aug 2026Head of ITEXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03.
EXAMPLEA.8.3Annex AA.8Information access restrictionNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.4Annex AA.8Access to source codeNoYes220 Jul 2026Head of EngineeringEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.5Annex AA.8Secure authenticationNoYes36 Oct 2025Head of ITEXAMPLE — Operating: in place since 2025-10-06, with records covering more than 3 months.
EXAMPLEA.8.6Annex AA.8Capacity managementNoYes1IT Operations Manager2EXAMPLE — Gap: Capacity is watched but no thresholds or forecast exist. Action: Set capacity thresholds and alerts for the platform and review a quarterly forecast.
EXAMPLEA.8.7Annex AA.8Protection against malwareNoYes32 Sep 2024Head of ITEXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months.
EXAMPLEA.8.8Annex AA.8Management of technical vulnerabilitiesNoYes210 Sep 2026Head of ITEXAMPLE — In place since 2026-09-10; 3 months of records by 2026-12-10. Vulnerability & Exposure Management Standard VMS-001 approved on 2026-09-10 (see the P01 pack).
EXAMPLEA.8.9Annex AA.8Configuration managementNoYes1Head of IT4EXAMPLE — Gap: No approved baseline configurations for servers, laptops or cloud services. Action: Approve baseline configurations for the main system types, apply them, and check drift monthly.
EXAMPLEA.8.10Annex AA.8Information deletionNoYes1IT Operations Manager2EXAMPLE — Gap: Customer data is not deleted on a set schedule after contracts end. Action: Define deletion periods for customer and internal data, automate the deletion job, and keep its log.
EXAMPLEA.8.11Annex AA.8Data maskingNoYes0Head of Engineering3EXAMPLE — Gap: Production data is copied to test without masking. Action: Mask personal and customer data in every copy made for testing, and block unmasked copies.
EXAMPLEA.8.12Annex AA.8Data leakage preventionNoYes0Head of IT3EXAMPLE — Gap: No controls to detect data leaving through email, storage or endpoints. Action: Turn on data loss prevention rules for customer data in email and cloud storage, in report-only mode first, then block.
EXAMPLEA.8.13Annex AA.8Information backupNoYes315 Aug 2025IT Operations ManagerEXAMPLE — Operating: in place since 2025-08-15, with records covering more than 3 months.
EXAMPLEA.8.14Annex AA.8Redundancy of information processing facilitiesNoYes210 Aug 2026IT Operations ManagerEXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10.
EXAMPLEA.8.15Annex AA.8LoggingNoYes210 Aug 2026Head of ITEXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10.
EXAMPLEA.8.16Annex AA.8Monitoring activitiesNoYes1Head of IT3EXAMPLE — Gap: Logs are collected but not monitored for anomalies. Action: Define the alerts that matter, route them to the on-call rota, and record the weekly review.
EXAMPLEA.8.17Annex AA.8Clock synchronizationNoYes26 Jul 2026IT Operations ManagerEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.
EXAMPLEA.8.18Annex AA.8Use of privileged utility programsNoYes1Head of IT1EXAMPLE — Gap: Use of privileged utility programs is not restricted. Action: List the utility programs that can override controls, restrict them to named administrators and log their use.
EXAMPLEA.8.19Annex AA.8Installation of software on operational systemsNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.20Annex AA.8Networks securityNoYes33 Mar 2025Head of ITEXAMPLE — Operating: in place since 2025-03-03, with records covering more than 3 months.
EXAMPLEA.8.21Annex AA.8Security of network servicesNoYes210 Aug 2026Head of ITEXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10.
EXAMPLEA.8.22Annex AA.8Segregation of networksNoYes220 Jul 2026Head of ITEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.23Annex AA.8Web filteringNoYes1Head of IT1EXAMPLE — Gap: Web filtering is on in the offices only, not on remote devices. Action: Extend the web filter to every managed device wherever it connects.
EXAMPLEA.8.24Annex AA.8Use of cryptographyNoYes224 Aug 2026Head of ITEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLEA.8.25Annex AA.8Secure development life cycleNoYes224 Aug 2026Head of EngineeringEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLEA.8.26Annex AA.8Application security requirementsNoYes1Head of Engineering2EXAMPLE — Gap: Security requirements are not written into feature specifications. Action: Add a security requirements section to the specification template and review it at design sign-off.
EXAMPLEA.8.27Annex AA.8Secure system architecture and engineering principlesNoYes1Head of Engineering2EXAMPLE — Gap: Architecture principles for security are not written down. Action: Write the secure architecture principles for the platform and apply them in design reviews.
EXAMPLEA.8.28Annex AA.8Secure codingNoYes224 Aug 2026Head of EngineeringEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLEA.8.29Annex AA.8Security testing in development and acceptanceNoYes224 Aug 2026Head of EngineeringEXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24.
EXAMPLEA.8.30Annex AA.8Outsourced developmentNoNoAll software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code.Excluded in the example's Statement of Applicability.
EXAMPLEA.8.31Annex AA.8Separation of development, test and production environmentsNoYes220 Jul 2026Head of EngineeringEXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20.
EXAMPLEA.8.32Annex AA.8Change managementNoYes35 May 2025Head of EngineeringEXAMPLE — Operating: in place since 2025-05-05, with records covering more than 3 months.
EXAMPLEA.8.33Annex AA.8Test informationNoYes1Head of Engineering2EXAMPLE — Gap: No rules for selecting and protecting test data. Action: Set rules for choosing, protecting and deleting test data, together with the masking in A.8.11.
EXAMPLEA.8.34Annex AA.8Protection of information systems during audit testingNoYes26 Jul 2026Head of ITEXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06.

Results by Requirement

Calculated: one row per requirement, from the answers the Settings sheet selects. This table is the export — copy it and paste as values. Do not type in it.

IDKindClause or themeRequirementBlocker?Applicable?ScoreLevelOwnerWeeks to In placeIn place sinceQueue orderForecast In placeForecast OperatingDate that counts for Stage 2Float (weeks)Critical path?Blocker In place (working)Blocking list order (working)
4.1Clause4Understanding the organization and its contextNoYes3Operating027 Apr 202610004
4.2Clause4Understanding the needs and expectations of interested partiesNoYes3Operating027 Apr 202610005
4.3Clause4Determining the scope of the information security management systemYesYes3Operating011 May 20266
4.4Clause4Information security management systemNoYes2In place024 Aug 20261000724 Aug 202624 Nov 202624 Aug 202624.4No
5.1Clause5Leadership and commitmentNoYes3Operating06 Apr 202610008
5.2Clause5PolicyYesYes3Operating012 Mar 20269
5.3Clause5Organizational roles, responsibilities and authoritiesNoYes2In place03 Aug 2026100103 Aug 20263 Nov 20263 Aug 202627.4No
6.1.1Clause6GeneralNoYes2In place06 Jul 2026100116 Jul 20266 Oct 20266 Jul 202631.4No
6.1.2Clause6Information security risk assessmentYesYes3Operating015 Jun 202612
6.1.3Clause6Information security risk treatmentYesYes2In place024 Aug 20261324 Aug 202624 Nov 202624 Nov 202611.3No24 Aug 20261129013
6.2Clause6Information security objectives and planning to achieve themYesYes1PlannedHead of Information Security31421 Oct 202621 Jan 202721 Jan 20273.0No21 Oct 2026300014
6.3Clause6Planning of changesNoYes1PlannedChief Operating Officer11001514 Oct 202614 Jan 202714 Oct 202617.1No
7.1Clause7ResourcesNoYes3Operating06 Apr 202610016
7.2Clause7CompetenceNoYes2In place01 Sep 2026100171 Sep 20261 Dec 20261 Sep 202623.3No
7.3Clause7AwarenessNoYes2In place014 Sep 20261001814 Sep 202614 Dec 202614 Sep 202621.4No
7.4Clause7CommunicationNoYes2In place03 Aug 2026100193 Aug 20263 Nov 20263 Aug 202627.4No
7.5.1Clause7GeneralNoYes2In place024 Aug 20261002024 Aug 202624 Nov 202624 Aug 202624.4No
7.5.2Clause7Creating and updatingNoYes3Operating012 Mar 202610021
7.5.3Clause7Control of documented informationNoYes1PlannedHead of Information Security11002218 Nov 202618 Feb 202718 Nov 202612.1No
8.1Clause8Operational planning and controlNoYes2In place06 Jul 2026100236 Jul 20266 Oct 20266 Jul 202631.4No
8.2Clause8Information security risk assessmentNoYes2In place020 Jul 20261002420 Jul 202620 Oct 202620 Jul 202629.4No
8.3Clause8Information security risk treatmentNoYes1PlannedHead of Information Security2100252 Dec 20262 Mar 20272 Dec 202610.1No
9.1Clause9Monitoring, measurement, analysis and evaluationNoYes1PlannedHead of Information Security31002623 Dec 202623 Mar 202723 Dec 20267.1No
9.2.1Clause9GeneralNoYes1PlannedHead of Information Security11002730 Dec 202630 Mar 202730 Dec 20266.1No
9.2.2Clause9Internal audit programmeYesYes1PlannedHead of Information Security12828 Oct 202628 Jan 202728 Jan 20272.0Yes28 Oct 2026200028
9.3.1Clause9GeneralNoYes1PlannedChief Operating Officer11002921 Oct 202621 Jan 202721 Oct 202616.1No
9.3.2Clause9Management review inputsNoYes1PlannedHead of Information Security1100306 Jan 20276 Apr 20276 Jan 20275.1No
9.3.3Clause9Management review resultsYesYes1PlannedChief Operating Officer1317 Oct 20267 Jan 20277 Jan 20275.0No7 Oct 2026500031
10.1Clause10Continual improvementNoYes1PlannedHead of Information Security11003213 Jan 202713 Apr 202713 Jan 20274.1No
10.2Clause10Nonconformity and corrective actionYesYes1PlannedHead of Information Security23311 Nov 202611 Feb 202711 Feb 20270.0Yes11 Nov 202633
A.5.1Annex AA.5Policies for information securityNoYes3Operating012 Mar 202610034
A.5.2Annex AA.5Information security roles and responsibilitiesNoYes2In place03 Aug 2026100353 Aug 20263 Nov 20263 Aug 202627.4No
A.5.3Annex AA.5Segregation of dutiesNoYes2In place020 Jul 20261003620 Jul 202620 Oct 202620 Jul 202629.4No
A.5.4Annex AA.5Management responsibilitiesNoYes2In place03 Aug 2026100373 Aug 20263 Nov 20263 Aug 202627.4No
A.5.5Annex AA.5Contact with authoritiesNoYes1PlannedHead of Information Security11003820 Jan 202720 Apr 202720 Jan 20273.1No
A.5.6Annex AA.5Contact with special interest groupsNoYes2In place06 Jul 2026100396 Jul 20266 Oct 20266 Jul 202631.4No
A.5.7Annex AA.5Threat intelligenceNoYes1PlannedHead of Information Security2100403 Feb 20273 May 20273 Feb 20271.1Yes114040
A.5.8Annex AA.5Information security in project managementNoYes1PlannedHead of Engineering1100417 Oct 20267 Jan 20277 Oct 202618.1No
A.5.9Annex AA.5Inventory of information and other associated assetsNoYes2In place020 Jul 20261004220 Jul 202620 Oct 202620 Jul 202629.4No
A.5.10Annex AA.5Acceptable use of information and other associated assetsNoYes3Operating01 Jul 202510043
A.5.11Annex AA.5Return of assetsNoYes2In place06 Jul 2026100446 Jul 20266 Oct 20266 Jul 202631.4No
A.5.12Annex AA.5Classification of informationNoYes2In place017 Aug 20261004517 Aug 202617 Nov 202617 Aug 202625.4No
A.5.13Annex AA.5Labelling of informationNoYes0Not startedHead of IT21004614 Oct 202614 Jan 202714 Oct 202617.1No
A.5.14Annex AA.5Information transferNoYes2In place017 Aug 20261004717 Aug 202617 Nov 202617 Aug 202625.4No
A.5.15Annex AA.5Access controlNoYes3Operating020 Jan 202610048
A.5.16Annex AA.5Identity managementNoYes3Operating020 Jan 202610049
A.5.17Annex AA.5Authentication informationNoYes3Operating020 Jan 202610050
A.5.18Annex AA.5Access rightsNoYes2In place03 Aug 2026100513 Aug 20263 Nov 20263 Aug 202627.4No
A.5.19Annex AA.5Information security in supplier relationshipsNoYes1PlannedHead of Procurement1100527 Oct 20267 Jan 20277 Oct 202618.1No
A.5.20Annex AA.5Addressing information security within supplier agreementsNoYes1PlannedHead of Procurement4100534 Nov 20264 Feb 20274 Nov 202614.1No
A.5.21Annex AA.5Managing information security in the ICT supply chainNoYes1PlannedHead of Procurement21005418 Nov 202618 Feb 202718 Nov 202612.1No
A.5.22Annex AA.5Monitoring, review and change management of supplier servicesNoYes1PlannedHead of Procurement2100552 Dec 20262 Mar 20272 Dec 202610.1No
A.5.23Annex AA.5Information security for use of cloud servicesNoYes2In place010 Aug 20261005610 Aug 202610 Nov 202610 Aug 202626.4No
A.5.24Annex AA.5Information security incident management planning and preparationNoYes3Operating04 May 202610057
A.5.25Annex AA.5Assessment and decision on information security eventsNoYes3Operating04 May 202610058
A.5.26Annex AA.5Response to information security incidentsNoYes3Operating04 May 202610059
A.5.27Annex AA.5Learning from information security incidentsNoYes2In place06 Jul 2026100606 Jul 20266 Oct 20266 Jul 202631.4No
A.5.28Annex AA.5Collection of evidenceNoYes1PlannedLegal Counsel1100617 Oct 20267 Jan 20277 Oct 202618.1No
A.5.29Annex AA.5Information security during disruptionNoYes2In place07 Sep 2026100627 Sep 20267 Dec 20267 Sep 202622.4No
A.5.30Annex AA.5ICT readiness for business continuityNoYes1PlannedIT Operations Manager41006328 Oct 202628 Jan 202728 Oct 202615.1No
A.5.31Annex AA.5Legal, statutory, regulatory and contractual requirementsNoYes1PlannedLegal Counsel31006428 Oct 202628 Jan 202728 Oct 202615.1No
A.5.32Annex AA.5Intellectual property rightsNoYes2In place06 Jul 2026100656 Jul 20266 Oct 20266 Jul 202631.4No
A.5.33Annex AA.5Protection of recordsNoYes1PlannedLegal Counsel21006611 Nov 202611 Feb 202711 Nov 202613.1No
A.5.34Annex AA.5Privacy and protection of PIINoYes2In place06 Jul 2026100676 Jul 20266 Oct 20266 Jul 202631.4No
A.5.35Annex AA.5Independent review of information securityNoYes1PlannedChief Operating Officer11006828 Oct 202628 Jan 202728 Oct 202615.1No
A.5.36Annex AA.5Compliance with policies, rules and standards for information securityNoYes2In place010 Sep 20261006910 Sep 202610 Dec 202610 Sep 202622.0No
A.5.37Annex AA.5Documented operating proceduresNoYes2In place024 Aug 20261007024 Aug 202624 Nov 202624 Aug 202624.4No
A.6.1Annex AA.6ScreeningNoYes3Operating06 Jan 202510071
A.6.2Annex AA.6Terms and conditions of employmentNoYes2In place06 Jul 2026100726 Jul 20266 Oct 20266 Jul 202631.4No
A.6.3Annex AA.6Information security awareness, education and trainingNoYes2In place014 Sep 20261007314 Sep 202614 Dec 202614 Sep 202621.4No
A.6.4Annex AA.6Disciplinary processNoYes1PlannedHR Director1100747 Oct 20267 Jan 20277 Oct 202618.1No
A.6.5Annex AA.6Responsibilities after termination or change of employmentNoYes3Operating03 Feb 202510075
A.6.6Annex AA.6Confidentiality or non-disclosure agreementsNoYes2In place06 Jul 2026100766 Jul 20266 Oct 20266 Jul 202631.4No
A.6.7Annex AA.6Remote workingNoYes3Operating018 Nov 202510077
A.6.8Annex AA.6Information security event reportingNoYes2In place06 Jul 2026100786 Jul 20266 Oct 20266 Jul 202631.4No
A.7.1Annex AA.7Physical security perimetersNoYes3Operating02 Sep 202410079
A.7.2Annex AA.7Physical entryNoYes3Operating02 Sep 202410080
A.7.3Annex AA.7Securing offices, rooms and facilitiesNoYes2In place06 Jul 2026100816 Jul 20266 Oct 20266 Jul 202631.4No
A.7.4Annex AA.7Physical security monitoringNoYes1PlannedOffice Manager21008214 Oct 202614 Jan 202714 Oct 202617.1No
A.7.5Annex AA.7Protecting against physical and environmental threatsNoYes2In place06 Jul 2026100836 Jul 20266 Oct 20266 Jul 202631.4No
A.7.6Annex AA.7Working in secure areasNoYes2In place06 Jul 2026100846 Jul 20266 Oct 20266 Jul 202631.4No
A.7.7Annex AA.7Clear desk and clear screenNoYes1PlannedOffice Manager11008521 Oct 202621 Jan 202721 Oct 202616.1No
A.7.8Annex AA.7Equipment siting and protectionNoYes2In place06 Jul 2026100866 Jul 20266 Oct 20266 Jul 202631.4No
A.7.9Annex AA.7Security of assets off-premisesNoYes2In place020 Jul 20261008720 Jul 202620 Oct 202620 Jul 202629.4No
A.7.10Annex AA.7Storage mediaNoYes2In place020 Jul 20261008820 Jul 202620 Oct 202620 Jul 202629.4No
A.7.11Annex AA.7Supporting utilitiesNoYes2In place06 Jul 2026100896 Jul 20266 Oct 20266 Jul 202631.4No
A.7.12Annex AA.7Cabling securityNoYes2In place06 Jul 2026100906 Jul 20266 Oct 20266 Jul 202631.4No
A.7.13Annex AA.7Equipment maintenanceNoYes2In place06 Jul 2026100916 Jul 20266 Oct 20266 Jul 202631.4No
A.7.14Annex AA.7Secure disposal or re-use of equipmentNoYes1PlannedIT Operations Manager1100924 Nov 20264 Feb 20274 Nov 202614.1No
A.8.1Annex AA.8User endpoint devicesNoYes2In place020 Jul 20261009320 Jul 202620 Oct 202620 Jul 202629.4No
A.8.2Annex AA.8Privileged access rightsNoYes2In place03 Aug 2026100943 Aug 20263 Nov 20263 Aug 202627.4No
A.8.3Annex AA.8Information access restrictionNoYes2In place020 Jul 20261009520 Jul 202620 Oct 202620 Jul 202629.4No
A.8.4Annex AA.8Access to source codeNoYes2In place020 Jul 20261009620 Jul 202620 Oct 202620 Jul 202629.4No
A.8.5Annex AA.8Secure authenticationNoYes3Operating06 Oct 202510097
A.8.6Annex AA.8Capacity managementNoYes1PlannedIT Operations Manager21009818 Nov 202618 Feb 202718 Nov 202612.1No
A.8.7Annex AA.8Protection against malwareNoYes3Operating02 Sep 202410099
A.8.8Annex AA.8Management of technical vulnerabilitiesNoYes2In place010 Sep 20261010010 Sep 202610 Dec 202610 Sep 202622.0No
A.8.9Annex AA.8Configuration managementNoYes1PlannedHead of IT41010111 Nov 202611 Feb 202711 Nov 202613.1No
A.8.10Annex AA.8Information deletionNoYes1PlannedIT Operations Manager2101022 Dec 20262 Mar 20272 Dec 202610.1No
A.8.11Annex AA.8Data maskingNoYes0Not startedHead of Engineering31010328 Oct 202628 Jan 202728 Oct 202615.1No
A.8.12Annex AA.8Data leakage preventionNoYes0Not startedHead of IT3101042 Dec 20262 Mar 20272 Dec 202610.1No
A.8.13Annex AA.8Information backupNoYes3Operating015 Aug 202510105
A.8.14Annex AA.8Redundancy of information processing facilitiesNoYes2In place010 Aug 20261010610 Aug 202610 Nov 202610 Aug 202626.4No
A.8.15Annex AA.8LoggingNoYes2In place010 Aug 20261010710 Aug 202610 Nov 202610 Aug 202626.4No
A.8.16Annex AA.8Monitoring activitiesNoYes1PlannedHead of IT31010823 Dec 202623 Mar 202723 Dec 20267.1No
A.8.17Annex AA.8Clock synchronizationNoYes2In place06 Jul 2026101096 Jul 20266 Oct 20266 Jul 202631.4No
A.8.18Annex AA.8Use of privileged utility programsNoYes1PlannedHead of IT11011030 Dec 202630 Mar 202730 Dec 20266.1No
A.8.19Annex AA.8Installation of software on operational systemsNoYes2In place020 Jul 20261011120 Jul 202620 Oct 202620 Jul 202629.4No
A.8.20Annex AA.8Networks securityNoYes3Operating03 Mar 202510112
A.8.21Annex AA.8Security of network servicesNoYes2In place010 Aug 20261011310 Aug 202610 Nov 202610 Aug 202626.4No
A.8.22Annex AA.8Segregation of networksNoYes2In place020 Jul 20261011420 Jul 202620 Oct 202620 Jul 202629.4No
A.8.23Annex AA.8Web filteringNoYes1PlannedHead of IT1101156 Jan 20276 Apr 20276 Jan 20275.1No
A.8.24Annex AA.8Use of cryptographyNoYes2In place024 Aug 20261011624 Aug 202624 Nov 202624 Aug 202624.4No
A.8.25Annex AA.8Secure development life cycleNoYes2In place024 Aug 20261011724 Aug 202624 Nov 202624 Aug 202624.4No
A.8.26Annex AA.8Application security requirementsNoYes1PlannedHead of Engineering21011811 Nov 202611 Feb 202711 Nov 202613.1No
A.8.27Annex AA.8Secure system architecture and engineering principlesNoYes1PlannedHead of Engineering21011925 Nov 202625 Feb 202725 Nov 202611.1No
A.8.28Annex AA.8Secure codingNoYes2In place024 Aug 20261012024 Aug 202624 Nov 202624 Aug 202624.4No
A.8.29Annex AA.8Security testing in development and acceptanceNoYes2In place024 Aug 20261012124 Aug 202624 Nov 202624 Aug 202624.4No
A.8.30Annex AA.8Outsourced developmentNoNoNot applicable010122
A.8.31Annex AA.8Separation of development, test and production environmentsNoYes2In place020 Jul 20261012320 Jul 202620 Oct 202620 Jul 202629.4No
A.8.32Annex AA.8Change managementNoYes3Operating05 May 202510124
A.8.33Annex AA.8Test informationNoYes1PlannedHead of Engineering2101259 Dec 20269 Mar 20279 Dec 20269.1No
A.8.34Annex AA.8Protection of information systems during audit testingNoYes2In place06 Jul 2026101266 Jul 20266 Oct 20266 Jul 202631.4No

Summary & Estimate

Summary and estimate

Readiness as 'x of y at Operating', the blockers, the estimated earliest Stage 2 date worked out step by step, and the items that decide it. Everything here is calculated.

EXAMPLE: results for the example organisation, as at 2026-09-30. Choose 'My answers' on the Settings sheet to see your own.

Readiness by clause and Annex A theme

AreaTitleAssessedOperatingIn placePlannedNot startedNot answeredResult: at Operating
Clause 4Context of the organization4310003 of 4 at Operating
Clause 5Leadership3210002 of 3 at Operating
Clause 6Planning5122001 of 5 at Operating
Clause 7Support7241002 of 7 at Operating
Clause 8Operation3021000 of 3 at Operating
Clause 9Performance evaluation6006000 of 6 at Operating
Clause 10Improvement2002000 of 2 at Operating
Annex A 5Organizational controls3781612108 of 37 at Operating
Annex A 6People controls8341003 of 8 at Operating
Annex A 7Physical controls14293002 of 14 at Operating
Annex A 8Technological controls335179205 of 33 at Operating
All clause requirements3081012008 of 30 at Operating
All applicable Annex A controls921846253018 of 92 at Operating
Everything assessed1222656373026 of 122 at Operating
Read the counts, not a percentage: a requirement at In place is working but has not yet produced the 3 months of records an auditor samples. 0 Not started · 1 Planned · 2 In place · 3 Operating.

Headline measures

IDMeasureResultTarget
ISM-01Blocking items operating3 of 8 blockers at OperatingAll, before the Stage 2 date
ISM-02Requirements operating26 of 122 requirements at OperatingRising monthly
ISM-03Gaps overdueKept in the ISMS Gap & Remediation Tracker, which holds the agreed dates.Zero on the critical path
ISM-04Weeks to certification20 weeks to the earliest Stage 2 date (planned: 22 weeks)On or before the planned date

The 8 blockers — each must be at Operating before Stage 2

ClauseTitleScoreLevelForecast In placeForecast OperatingFloat (weeks)Critical path?Owner
4.3Determining the scope of the information security management system3Operating
5.2Policy3Operating
6.1.2Information security risk assessment3Operating
6.1.3Information security risk treatment2In place24 Aug 202624 Nov 202611.3No
6.2Information security objectives and planning to achieve them1Planned21 Oct 202621 Jan 20273.0NoHead of Information Security
9.2.2Internal audit programme1Planned28 Oct 202628 Jan 20272.0YesHead of Information Security
9.3.3Management review results1Planned7 Oct 20267 Jan 20275.0NoChief Operating Officer
10.2Nonconformity and corrective action1Planned11 Nov 202611 Feb 20270.0YesHead of Information Security

Estimated earliest Stage 2 date, step by step

StepWhat it measuresDateWorking
(a)Remaining work: every item In place3 Feb 2027The last item to be put in place is A.5.7 (Head of Information Security), at the end of that owner's queue of 18 weeks of work.
(b)IS-05: 3 months of operation after the last blocker is In place11 Feb 2027The last blocker to be In place is 10.2 on 2026-11-11, plus 3 months of records.
(c)IS-06: internal audit and management review done6 Jan 2027Earliest end of the Check phase 2026-11-25 (audit programme In place 2026-10-28 + 4 weeks); planned audit end 2026-12-09; planned management review 2027-01-06.
Estimated earliest Stage 2 date11 Feb 2027The latest of (a), (b) and (c): set by (b), the months of operation after the last blocker (IS-05).
Planned Stage 2 date1 Mar 2027From the Settings sheet.
VerdictOn track: 2.6 weeks to spare before the planned Stage 2 date.

The blocking items, in the order to work on them

No.RequirementLevelForecast In placeForecast OperatingFloat (weeks)Why it blocksRowOwner
110.2 Nonconformity and corrective actionPlanned11 Nov 202611 Feb 20270.0Blocker; critical path30Head of Information Security
2A.5.7 Threat intelligencePlanned3 Feb 20273 May 20271.1Critical path37Head of Information Security
39.2.2 Internal audit programmePlanned28 Oct 202628 Jan 20272.0Blocker; critical path25Head of Information Security
46.2 Information security objectives and planning to achieve themPlanned21 Oct 202621 Jan 20273.0Blocker11Head of Information Security
59.3.3 Management review resultsPlanned7 Oct 20267 Jan 20275.0Blocker28Chief Operating Officer
66.1.3 Information security risk treatmentIn place24 Aug 202624 Nov 202611.3Blocker10

7

8

9

10

11

12

13

14

15

Order: smallest float first — the items whose slip would move the Stage 2 date soonest — then by position in the standard. A blocker below Operating is always listed. The grey Row column is the item's position in the Results by Requirement table. Put every item in the ISMS Gap & Remediation Tracker with its agreed date.

Limitations

This is a self-assessment: it is as accurate as the scores and the weeks of work entered. Evidence notes, and a second person checking the scores of the blockers, are the best defence against optimism.

The estimate assumes each owner works on one item at a time, in the order shown, from the as-at date, and that the dates you entered for the internal audit and management review hold. It does not include the certification body's lead time: book the Stage 1 and Stage 2 dates early.

A certification body decides on the evidence it samples. Every requirement at Operating makes a pass likely, not certain; a requirement at In place may still pass if it has enough records, and may not.

It does not judge whether your controls are the right ones for your risks (IS-03): that is the risk assessment and the Statement of Applicability.

Lists

AnswerModeReadinessScoreLevelNameYesNoBlockers
Example organisation0Not startedYes4.3
My answers1PlannedNo5.2
2In place6.1.2
3Operating6.1.3

6.2

9.2.2

9.3.3

10.2

Definitions

Definitions

TermMeaning in this workbook
RequirementA clause requirement (the 30 subclauses of clauses 4 to 10 that carry requirements) or an Annex A control. Shown by number and title only: read the standard for what each requires.
0 — Not startedNothing exists yet.
1 — PlannedOwner and approach agreed; not yet in place.
2 — In placeDocumented and working, but little or no record yet.
3 — OperatingWorking, with records covering at least [[3]] months, and an auditor could sample it.
BlockerOne of the 8 clause requirements without which a Stage 2 audit cannot pass. All must be at Operating before the Stage 2 date.
Owner queueThe items below In place that one owner must put in place, taken one after another: blockers first, then in the standard's order.
Forecast In placeThe date an item is expected to reach In place: its In place date if already there, otherwise the as-at date plus the weeks of the owner's queue up to and including it.
FloatHow many weeks an item could slip before the estimated Stage 2 date moves. Zero means it decides the date.
Critical pathThe items with float at or below the Settings value: the ones to protect.
Stage 1 and Stage 2 auditsThe two parts of a certification audit: Stage 1 reviews the ISMS design and documents and readiness; Stage 2 tests whether it operates as designed.
Statement of Applicability (SoA)The document that lists every Annex A control, whether it is applied and why (clause 6.1.3): see the Statement of Applicability Template.
EXAMPLEValues for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Replace them with your own.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.2 — Internal auditWhole workbook: a readiness check before, not instead of, the internal audit (IS-06)
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationResults by Requirement and Summary & Estimate: readiness measured and evaluated monthly (IS-10)
ISO/IEC 27001:2022Clause 10.1 — Continual improvementBlocking items: where improvement is needed first
NIST CSF 2.0ID.IM-01 — “Improvements are identified from evaluations”Summary & Estimate: improvements identified from the assessment
NIST CSF 2.0GV.OV-01 — “Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction”Verdict and headline measures: outcomes reviewed to adjust the plan

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0