Certification Readiness Self-Assessment
Scores readiness across clause and Annex A requirements and returns an estimated time-to-certification with the specific blocking items.
Available soon
- Format
- Excel
- Size
- 112 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Settings
- Assessment
- Example Answers
- Results by Requirement
- Summary & Estimate
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Scope: assess the ISMS as defined in your approved scope (clause 4.3). Every clause requirement applies; an Annex A control can be marked not applicable only where your Statement of Applicability excludes it, with the same reason (IS-03). Assess monthly from the start of Phase 4 until certification (IS-10: "Readiness must be reassessed monthly from the start of Phase 4 until certification."). |
| 2 | Settings: enter your as-at date (today's date, or =TODAY()), your planned Stage 1 and Stage 2 audit dates, and the planned end of the internal audit fieldwork and date of the management review, in column D. The EXAMPLE values in column E are used while D5 says the example. |
| 3 | Assessment: for each row, answer Applicable? (controls only), then the readiness score 0 to 3 from the drop-down, using the anchors below. Choose the lower score when in doubt: the score describes what an auditor could see today, not what is planned. |
| 4 | For a score of 2 or 3, enter the date it went In place (column I). For a score of 0 or 1, name the owner (column J) and estimate the weeks of work still needed to put it in place (column K), counting the owner's real availability. Note the evidence in column L. |
| 5 | Settings: change D5 from 'Example organisation' to 'My answers'. The Results by Requirement and Summary & Estimate sheets now describe your organisation. |
| 6 | Summary & Estimate: read the counts ('x of y at Operating'), the blockers, the three steps of the estimate and the verdict against your planned Stage 2 date. The blocking items list is the order to work in. |
| 7 | Copy every row below Operating into the ISMS Gap & Remediation Tracker with its owner, weeks and dates, and track it there. The tracker uses the same calculation, so its weeks to certification (ISM-04) match this workbook's. |
| 8 | Export: select the Results by Requirement table, copy, and paste as values into your records. Keep each month's copy so you can compare. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The readiness scale and what each score means for a requirement:
0 — Not started: Nothing exists yet.
1 — Planned: Owner and approach agreed; not yet in place.
2 — In place: Documented and working, but little or no record yet.
3 — Operating: Working, with records covering at least [[3]] months, and an auditor could sample it. This workbook uses 3 months (IS-05); change it on the Settings sheet if your certification body expects more.
Examples of the anchors. Clause 9.2.2 at 1: the audit programme is being drafted and an auditor is being chosen. At 2: the programme is approved and the first audit has started. At 3: at least one audit cycle is complete with a report, and its findings are in the corrective action log. Annex A 8.13 at 2: backups run to an approved standard but no restore test is recorded yet; at 3: [[3]] months of backup logs and at least one recorded restore test.
Blockers (weights). 8 clause requirements are blockers: without them a Stage 2 audit cannot pass. They are 4.3 Determining the scope of the information security management system; 5.2 Policy; 6.1.2 Information security risk assessment; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 9.2.2 Internal audit programme; 9.3.3 Management review results; 10.2 Nonconformity and corrective action. Blockers come first in every owner's queue (IS-08: "Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date.") and all must be at Operating before the Stage 2 date (ISM-01).
How the estimate is worked out. (a) Remaining work: each owner works through their items below In place one after another, blockers first, then in the standard's order, starting from the as-at date; the last item's date is when the work is done. Items at In place need no more work, only time. (b) IS-05: "The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit." — the last blocker's In place date plus 3 months. (c) IS-06: "At least one full internal audit cycle and one management review must be completed before Stage 2." — the later of your planned management review, your planned end of audit fieldwork, and the earliest possible end of the Check phase (the audit programme in place, plus 4 weeks, the Check phase in the ISO 27001 Implementation Methodology & Project Plan). The earliest Stage 2 date is the latest of the three. Weeks are calendar weeks.
The critical path: an item is on it when a slip of 2 weeks or less would move the estimated Stage 2 date (Settings, 'Critical-path float'). For a blocker the date that counts is when it reaches Operating; for any other item, when it is In place.
The worked example: while D5 says 'Example organisation', results come from the Example Answers sheet: the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), which started its ISMS project on 2026-04-06 and has booked Stage 1 for 2027-01-18 and Stage 2 for 2027-03-01, as at 2026-09-30. To clear the example, set D5 to 'My answers' and fill column D of the Settings sheet. Keep the Example Answers sheet: the results read it whenever D5 is set back to the example.
Tailoring — small organisation: the scale works the same with fewer people, but the owner queue is shorter and usually one person long. Be honest about that person's weeks; in a small organisation the ISMS manager's queue is nearly always the critical path. A contracted internal auditor is normal and satisfies IS-07.
Tailoring — regulated entity: certification to ISO/IEC 27001:2022 is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Assess the same requirements, and add the regulatory duties to your register of legal requirements (Annex A 5.31). A supervisor may ask for this assessment and its history: keep each month's export.
Tailoring — IT run by a service provider: score a control for what you can evidence, not for what the provider says it does. Where the provider operates a control, the owner in column J is the person who manages the provider, and 'In place' needs the provider's records to be available to you and to the auditor.
Limitations: see the foot of the Summary & Estimate sheet.
Settings
Settings
Choose which answers the results use, and set the dates and numbers the estimate needs. Column D is yours; column E holds the EXAMPLE.
| Results use | Example organisation | EXAMPLE — change to 'My answers' once you have answered the Assessment sheet and filled column D below. | |||
| Setting | Your value | EXAMPLE | Value used | Note | |
|---|---|---|---|---|---|
| As-at date | 30 Sep 2026 | 30 Sep 2026 | EXAMPLE — the example's as-at date. Enter today's date, or =TODAY(). Every forecast counts from it. | ||
| Planned Stage 1 audit | 18 Jan 2027 | 18 Jan 2027 | The date booked with your certification body. Shown for reference; the estimate is for Stage 2. | ||
| Planned Stage 2 audit | 1 Mar 2027 | 1 Mar 2027 | The date booked with your certification body. The verdict compares the estimate with it. | ||
| Internal audits end (planned) | 9 Dec 2026 | 9 Dec 2026 | Leave blank if not planned yet; the estimate then uses the earliest possible end of the Check phase. | ||
| Management review (planned) | 6 Jan 2027 | 6 Jan 2027 | After the audit report, so the review can consider it (clause 9.3.2). | ||
| Months of operation before Stage 2 (IS-05) | 3 | 3 | 3 | The [[3]] in IS-05 and in the Operating anchor. Ask your certification body; some expect more. | |
| Check phase: audit programme in place to review done (weeks) | 4 | 4 | 4 | PH-5 Check: 4 weeks in the ISO 27001 Implementation Methodology & Project Plan. | |
| Critical-path float (weeks) | 2 | 2 | 2 | An item whose slip of this many weeks or fewer would move the estimate is on the critical path. | |
Assessment
Your answers, one row per requirement. Score each from 0 to 3 using the anchors on the Instructions sheet. Clauses are always applicable.
| ID | Kind | Clause or theme | Requirement (number and title only) | Blocker? | Applicable? (controls) | Reason if not applicable (as in your SoA) | Readiness (0–3) | In place since (score 2 or 3) | Owner (score 0 or 1) | Weeks of work to In place | Evidence and notes |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 4.1 | Clause | 4 | Understanding the organization and its context | No | Yes | ||||||
| 4.2 | Clause | 4 | Understanding the needs and expectations of interested parties | No | Yes | ||||||
| 4.3 | Clause | 4 | Determining the scope of the information security management system | Yes | Yes | ||||||
| 4.4 | Clause | 4 | Information security management system | No | Yes | ||||||
| 5.1 | Clause | 5 | Leadership and commitment | No | Yes | ||||||
| 5.2 | Clause | 5 | Policy | Yes | Yes | ||||||
| 5.3 | Clause | 5 | Organizational roles, responsibilities and authorities | No | Yes | ||||||
| 6.1.1 | Clause | 6 | General | No | Yes | ||||||
| 6.1.2 | Clause | 6 | Information security risk assessment | Yes | Yes | ||||||
| 6.1.3 | Clause | 6 | Information security risk treatment | Yes | Yes | ||||||
| 6.2 | Clause | 6 | Information security objectives and planning to achieve them | Yes | Yes | ||||||
| 6.3 | Clause | 6 | Planning of changes | No | Yes | ||||||
| 7.1 | Clause | 7 | Resources | No | Yes | ||||||
| 7.2 | Clause | 7 | Competence | No | Yes | ||||||
| 7.3 | Clause | 7 | Awareness | No | Yes | ||||||
| 7.4 | Clause | 7 | Communication | No | Yes | ||||||
| 7.5.1 | Clause | 7 | General | No | Yes | ||||||
| 7.5.2 | Clause | 7 | Creating and updating | No | Yes | ||||||
| 7.5.3 | Clause | 7 | Control of documented information | No | Yes | ||||||
| 8.1 | Clause | 8 | Operational planning and control | No | Yes | ||||||
| 8.2 | Clause | 8 | Information security risk assessment | No | Yes | ||||||
| 8.3 | Clause | 8 | Information security risk treatment | No | Yes | ||||||
| 9.1 | Clause | 9 | Monitoring, measurement, analysis and evaluation | No | Yes | ||||||
| 9.2.1 | Clause | 9 | General | No | Yes | ||||||
| 9.2.2 | Clause | 9 | Internal audit programme | Yes | Yes | ||||||
| 9.3.1 | Clause | 9 | General | No | Yes | ||||||
| 9.3.2 | Clause | 9 | Management review inputs | No | Yes | ||||||
| 9.3.3 | Clause | 9 | Management review results | Yes | Yes | ||||||
| 10.1 | Clause | 10 | Continual improvement | No | Yes | ||||||
| 10.2 | Clause | 10 | Nonconformity and corrective action | Yes | Yes | ||||||
| A.5.1 | Annex A | A.5 | Policies for information security | No | |||||||
| A.5.2 | Annex A | A.5 | Information security roles and responsibilities | No | |||||||
| A.5.3 | Annex A | A.5 | Segregation of duties | No | |||||||
| A.5.4 | Annex A | A.5 | Management responsibilities | No | |||||||
| A.5.5 | Annex A | A.5 | Contact with authorities | No | |||||||
| A.5.6 | Annex A | A.5 | Contact with special interest groups | No | |||||||
| A.5.7 | Annex A | A.5 | Threat intelligence | No | |||||||
| A.5.8 | Annex A | A.5 | Information security in project management | No | |||||||
| A.5.9 | Annex A | A.5 | Inventory of information and other associated assets | No | |||||||
| A.5.10 | Annex A | A.5 | Acceptable use of information and other associated assets | No | |||||||
| A.5.11 | Annex A | A.5 | Return of assets | No | |||||||
| A.5.12 | Annex A | A.5 | Classification of information | No | |||||||
| A.5.13 | Annex A | A.5 | Labelling of information | No | |||||||
| A.5.14 | Annex A | A.5 | Information transfer | No | |||||||
| A.5.15 | Annex A | A.5 | Access control | No | |||||||
| A.5.16 | Annex A | A.5 | Identity management | No | |||||||
| A.5.17 | Annex A | A.5 | Authentication information | No | |||||||
| A.5.18 | Annex A | A.5 | Access rights | No | |||||||
| A.5.19 | Annex A | A.5 | Information security in supplier relationships | No | |||||||
| A.5.20 | Annex A | A.5 | Addressing information security within supplier agreements | No | |||||||
| A.5.21 | Annex A | A.5 | Managing information security in the ICT supply chain | No | |||||||
| A.5.22 | Annex A | A.5 | Monitoring, review and change management of supplier services | No | |||||||
| A.5.23 | Annex A | A.5 | Information security for use of cloud services | No | |||||||
| A.5.24 | Annex A | A.5 | Information security incident management planning and preparation | No | |||||||
| A.5.25 | Annex A | A.5 | Assessment and decision on information security events | No | |||||||
| A.5.26 | Annex A | A.5 | Response to information security incidents | No | |||||||
| A.5.27 | Annex A | A.5 | Learning from information security incidents | No | |||||||
| A.5.28 | Annex A | A.5 | Collection of evidence | No | |||||||
| A.5.29 | Annex A | A.5 | Information security during disruption | No | |||||||
| A.5.30 | Annex A | A.5 | ICT readiness for business continuity | No | |||||||
| A.5.31 | Annex A | A.5 | Legal, statutory, regulatory and contractual requirements | No | |||||||
| A.5.32 | Annex A | A.5 | Intellectual property rights | No | |||||||
| A.5.33 | Annex A | A.5 | Protection of records | No | |||||||
| A.5.34 | Annex A | A.5 | Privacy and protection of PII | No | |||||||
| A.5.35 | Annex A | A.5 | Independent review of information security | No | |||||||
| A.5.36 | Annex A | A.5 | Compliance with policies, rules and standards for information security | No | |||||||
| A.5.37 | Annex A | A.5 | Documented operating procedures | No | |||||||
| A.6.1 | Annex A | A.6 | Screening | No | |||||||
| A.6.2 | Annex A | A.6 | Terms and conditions of employment | No | |||||||
| A.6.3 | Annex A | A.6 | Information security awareness, education and training | No | |||||||
| A.6.4 | Annex A | A.6 | Disciplinary process | No | |||||||
| A.6.5 | Annex A | A.6 | Responsibilities after termination or change of employment | No | |||||||
| A.6.6 | Annex A | A.6 | Confidentiality or non-disclosure agreements | No | |||||||
| A.6.7 | Annex A | A.6 | Remote working | No | |||||||
| A.6.8 | Annex A | A.6 | Information security event reporting | No | |||||||
| A.7.1 | Annex A | A.7 | Physical security perimeters | No | |||||||
| A.7.2 | Annex A | A.7 | Physical entry | No | |||||||
| A.7.3 | Annex A | A.7 | Securing offices, rooms and facilities | No | |||||||
| A.7.4 | Annex A | A.7 | Physical security monitoring | No | |||||||
| A.7.5 | Annex A | A.7 | Protecting against physical and environmental threats | No | |||||||
| A.7.6 | Annex A | A.7 | Working in secure areas | No | |||||||
| A.7.7 | Annex A | A.7 | Clear desk and clear screen | No | |||||||
| A.7.8 | Annex A | A.7 | Equipment siting and protection | No | |||||||
| A.7.9 | Annex A | A.7 | Security of assets off-premises | No | |||||||
| A.7.10 | Annex A | A.7 | Storage media | No | |||||||
| A.7.11 | Annex A | A.7 | Supporting utilities | No | |||||||
| A.7.12 | Annex A | A.7 | Cabling security | No | |||||||
| A.7.13 | Annex A | A.7 | Equipment maintenance | No | |||||||
| A.7.14 | Annex A | A.7 | Secure disposal or re-use of equipment | No | |||||||
| A.8.1 | Annex A | A.8 | User endpoint devices | No | |||||||
| A.8.2 | Annex A | A.8 | Privileged access rights | No | |||||||
| A.8.3 | Annex A | A.8 | Information access restriction | No | |||||||
| A.8.4 | Annex A | A.8 | Access to source code | No | |||||||
| A.8.5 | Annex A | A.8 | Secure authentication | No | |||||||
| A.8.6 | Annex A | A.8 | Capacity management | No | |||||||
| A.8.7 | Annex A | A.8 | Protection against malware | No | |||||||
| A.8.8 | Annex A | A.8 | Management of technical vulnerabilities | No | |||||||
| A.8.9 | Annex A | A.8 | Configuration management | No | |||||||
| A.8.10 | Annex A | A.8 | Information deletion | No | |||||||
| A.8.11 | Annex A | A.8 | Data masking | No | |||||||
| A.8.12 | Annex A | A.8 | Data leakage prevention | No | |||||||
| A.8.13 | Annex A | A.8 | Information backup | No | |||||||
| A.8.14 | Annex A | A.8 | Redundancy of information processing facilities | No | |||||||
| A.8.15 | Annex A | A.8 | Logging | No | |||||||
| A.8.16 | Annex A | A.8 | Monitoring activities | No | |||||||
| A.8.17 | Annex A | A.8 | Clock synchronization | No | |||||||
| A.8.18 | Annex A | A.8 | Use of privileged utility programs | No | |||||||
| A.8.19 | Annex A | A.8 | Installation of software on operational systems | No | |||||||
| A.8.20 | Annex A | A.8 | Networks security | No | |||||||
| A.8.21 | Annex A | A.8 | Security of network services | No | |||||||
| A.8.22 | Annex A | A.8 | Segregation of networks | No | |||||||
| A.8.23 | Annex A | A.8 | Web filtering | No | |||||||
| A.8.24 | Annex A | A.8 | Use of cryptography | No | |||||||
| A.8.25 | Annex A | A.8 | Secure development life cycle | No | |||||||
| A.8.26 | Annex A | A.8 | Application security requirements | No | |||||||
| A.8.27 | Annex A | A.8 | Secure system architecture and engineering principles | No | |||||||
| A.8.28 | Annex A | A.8 | Secure coding | No | |||||||
| A.8.29 | Annex A | A.8 | Security testing in development and acceptance | No | |||||||
| A.8.30 | Annex A | A.8 | Outsourced development | No | |||||||
| A.8.31 | Annex A | A.8 | Separation of development, test and production environments | No | |||||||
| A.8.32 | Annex A | A.8 | Change management | No | |||||||
| A.8.33 | Annex A | A.8 | Test information | No | |||||||
| A.8.34 | Annex A | A.8 | Protection of information systems during audit testing | No |
Example Answers
EXAMPLE — the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity), as at 2026-09-30, about six months into its ISMS project.
| Example | ID | Kind | Clause or theme | Requirement (number and title only) | Blocker? | Applicable? (controls) | Reason if not applicable (as in your SoA) | Readiness (0–3) | In place since (score 2 or 3) | Owner (score 0 or 1) | Weeks of work to In place | Evidence and notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | 4.1 | Clause | 4 | Understanding the organization and its context | No | Yes | 3 | 27 Apr 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-04-27, with records covering more than 3 months. | ||
| EXAMPLE | 4.2 | Clause | 4 | Understanding the needs and expectations of interested parties | No | Yes | 3 | 27 Apr 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-04-27, with records covering more than 3 months. | ||
| EXAMPLE | 4.3 | Clause | 4 | Determining the scope of the information security management system | Yes | Yes | 3 | 11 May 2026 | Chief Operating Officer | EXAMPLE — Operating: in place since 2026-05-11, with records covering more than 3 months. | ||
| EXAMPLE | 4.4 | Clause | 4 | Information security management system | No | Yes | 2 | 24 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. The ISMS processes and how they connect are described in the ISMS manual; it has run as a whole only since late August. | ||
| EXAMPLE | 5.1 | Clause | 5 | Leadership and commitment | No | Yes | 3 | 6 Apr 2026 | Chief Operating Officer | EXAMPLE — Operating: in place since 2026-04-06, with records covering more than 3 months. | ||
| EXAMPLE | 5.2 | Clause | 5 | Policy | Yes | Yes | 3 | 12 Mar 2026 | Chief Operating Officer | EXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months. | ||
| EXAMPLE | 5.3 | Clause | 5 | Organizational roles, responsibilities and authorities | No | Yes | 2 | 3 Aug 2026 | Chief Operating Officer | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. Roles and responsibilities approved in August; control owners confirmed their roles in writing. | ||
| EXAMPLE | 6.1.1 | Clause | 6 | General | No | Yes | 2 | 6 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | 6.1.2 | Clause | 6 | Information security risk assessment | Yes | Yes | 3 | 15 Jun 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-06-15, with records covering more than 3 months. | ||
| EXAMPLE | 6.1.3 | Clause | 6 | Information security risk treatment | Yes | Yes | 2 | 24 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. Statement of Applicability and risk treatment plan approved on 2026-08-24; treatment is under way. | ||
| EXAMPLE | 6.2 | Clause | 6 | Information security objectives and planning to achieve them | Yes | Yes | 1 | Head of Information Security | 3 | EXAMPLE — Gap: Objectives drafted but not approved; no measure, owner or date for each. Action: Agree five to seven measurable objectives, each with an owner, a measure and a date; have top management approve them and communicate them. | ||
| EXAMPLE | 6.3 | Clause | 6 | Planning of changes | No | Yes | 1 | Chief Operating Officer | 1 | EXAMPLE — Gap: No agreed way to plan changes to the ISMS itself (scope, roles, processes). Action: Add a short ISMS change step to the steering group's agenda (the Chief Operating Officer chairs it): purpose, consequences, resources and who is responsible, recorded in the minutes. | ||
| EXAMPLE | 7.1 | Clause | 7 | Resources | No | Yes | 3 | 6 Apr 2026 | Chief Operating Officer | EXAMPLE — Operating: in place since 2026-04-06, with records covering more than 3 months. | ||
| EXAMPLE | 7.2 | Clause | 7 | Competence | No | Yes | 2 | 1 Sep 2026 | HR Director | EXAMPLE — In place since 2026-09-01; 3 months of records by 2026-12-01. Competence requirements for ISMS roles set in September; training records are in the HR system. | ||
| EXAMPLE | 7.3 | Clause | 7 | Awareness | No | Yes | 2 | 14 Sep 2026 | Head of Information Security | EXAMPLE — In place since 2026-09-14; 3 months of records by 2026-12-14. Awareness campaign launched in September; completion is tracked. | ||
| EXAMPLE | 7.4 | Clause | 7 | Communication | No | Yes | 2 | 3 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. | ||
| EXAMPLE | 7.5.1 | Clause | 7 | General | No | Yes | 2 | 24 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | 7.5.2 | Clause | 7 | Creating and updating | No | Yes | 3 | 12 Mar 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months. | ||
| EXAMPLE | 7.5.3 | Clause | 7 | Control of documented information | No | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: Two documents are past their review date (AUP-001, BKP-001) and one is awaiting approval (the Supplier Security Policy, P04 register SUP-001) in the policy register. Action: Complete the two overdue reviews, take the Supplier Security Policy (P04 register SUP-001) to its approver, and add a monthly check of review dates to the ISMS manager's routine. | ||
| EXAMPLE | 8.1 | Clause | 8 | Operational planning and control | No | Yes | 2 | 6 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | 8.2 | Clause | 8 | Information security risk assessment | No | Yes | 2 | 20 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. The first full risk assessment was accepted by risk owners in July; the planned reassessment has not run yet. | ||
| EXAMPLE | 8.3 | Clause | 8 | Information security risk treatment | No | Yes | 1 | Head of Information Security | 2 | EXAMPLE — Gap: Treatment actions are under way but their completion and the residual risk are not recorded. Action: Record each completed treatment action and the residual risk it leaves in the risk register, and have risk owners accept it. | ||
| EXAMPLE | 9.1 | Clause | 9 | Monitoring, measurement, analysis and evaluation | No | Yes | 1 | Head of Information Security | 3 | EXAMPLE — Gap: Measures are listed but not yet collected or reported; no one analyses the results. Action: Choose the measures, their owners and frequency; produce the first monthly report and take it to the steering group. | ||
| EXAMPLE | 9.2.1 | Clause | 9 | General | No | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: No check yet that each audit has set criteria and scope, an independent auditor and results reported to management. Action: After the first audit cycle, confirm each audit had criteria, scope and an independent auditor (IS-07) and that its results reached management; correct the programme where they did not. | ||
| EXAMPLE | 9.2.2 | Clause | 9 | Internal audit programme | Yes | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: Internal audit not started: the programme is drafted but not approved, and the contracted auditors are not yet confirmed. Action: Finish the audit programme so it covers every clause and the applicable controls before Stage 2, have the Chief Operating Officer approve it as sponsor, confirm the independent auditors (IS-07) and book the fieldwork. | ||
| EXAMPLE | 9.3.1 | Clause | 9 | General | No | Yes | 1 | Chief Operating Officer | 1 | EXAMPLE — Gap: No management review held or scheduled. Action: Schedule the first management review with top management after the internal audit report, and a yearly cycle after that. | ||
| EXAMPLE | 9.3.2 | Clause | 9 | Management review inputs | No | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: No template for the inputs the review must consider. Action: Prepare the review pack with every required input, from the Management Review Meeting Pack. | ||
| EXAMPLE | 9.3.3 | Clause | 9 | Management review results | Yes | Yes | 1 | Chief Operating Officer | 1 | EXAMPLE — Gap: No review held, so no recorded decisions. Action: Confirm the date, attendees and minute-taker, and a template that records decisions and actions. | ||
| EXAMPLE | 10.1 | Clause | 10 | Continual improvement | No | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: Improvements are made but not recorded as such. Action: Keep an improvement log fed by audits, incidents, measures and suggestions, reviewed by the steering group. | ||
| EXAMPLE | 10.2 | Clause | 10 | Nonconformity and corrective action | Yes | Yes | 1 | Head of Information Security | 2 | EXAMPLE — Gap: Corrective actions are raised only for incidents; no procedure for nonconformities, root cause or effectiveness checks. Action: Approve a nonconformity and corrective action procedure (root cause, correction, corrective action, effectiveness check — IS-09) and start the log. | ||
| EXAMPLE | A.5.1 | Annex A | A.5 | Policies for information security | No | Yes | 3 | 12 Mar 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-03-12, with records covering more than 3 months. | ||
| EXAMPLE | A.5.2 | Annex A | A.5 | Information security roles and responsibilities | No | Yes | 2 | 3 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. | ||
| EXAMPLE | A.5.3 | Annex A | A.5 | Segregation of duties | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.5.4 | Annex A | A.5 | Management responsibilities | No | Yes | 2 | 3 Aug 2026 | Chief Operating Officer | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. | ||
| EXAMPLE | A.5.5 | Annex A | A.5 | Contact with authorities | No | Yes | 1 | Head of Information Security | 1 | EXAMPLE — Gap: No list of which authorities to contact, when, and who may do it. Action: Record the authorities (regulator, national incident response team, police, data protection authority), the route and who may contact them; link it from the incident procedure. | ||
| EXAMPLE | A.5.6 | Annex A | A.5 | Contact with special interest groups | No | Yes | 2 | 6 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.5.7 | Annex A | A.5 | Threat intelligence | No | Yes | 1 | Head of Information Security | 2 | EXAMPLE — Gap: Threat information is read informally; nothing is recorded or acted on. Action: Choose two or three threat sources relevant to the platform, review them weekly, and record what was relevant and what was done. | ||
| EXAMPLE | A.5.8 | Annex A | A.5 | Information security in project management | No | Yes | 1 | Head of Engineering | 1 | EXAMPLE — Gap: Security is not a step in the project method. Action: Add a security checkpoint (risks and requirements) to the project start and go-live gates, with a short record. | ||
| EXAMPLE | A.5.9 | Annex A | A.5 | Inventory of information and other associated assets | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.5.10 | Annex A | A.5 | Acceptable use of information and other associated assets | No | Yes | 3 | 1 Jul 2025 | Head of IT | EXAMPLE — Operating: in place since 2025-07-01, with records covering more than 3 months. | ||
| EXAMPLE | A.5.11 | Annex A | A.5 | Return of assets | No | Yes | 2 | 6 Jul 2026 | HR Director | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.5.12 | Annex A | A.5 | Classification of information | No | Yes | 2 | 17 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-17; 3 months of records by 2026-11-17. | ||
| EXAMPLE | A.5.13 | Annex A | A.5 | Labelling of information | No | Yes | 0 | Head of IT | 2 | EXAMPLE — Gap: No labelling of classified information. Action: Apply the classification labels in the document and email tools, default to Internal, and brief staff. | ||
| EXAMPLE | A.5.14 | Annex A | A.5 | Information transfer | No | Yes | 2 | 17 Aug 2026 | Head of Information Security | EXAMPLE — In place since 2026-08-17; 3 months of records by 2026-11-17. | ||
| EXAMPLE | A.5.15 | Annex A | A.5 | Access control | No | Yes | 3 | 20 Jan 2026 | Head of IT | EXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months. | ||
| EXAMPLE | A.5.16 | Annex A | A.5 | Identity management | No | Yes | 3 | 20 Jan 2026 | Head of IT | EXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months. | ||
| EXAMPLE | A.5.17 | Annex A | A.5 | Authentication information | No | Yes | 3 | 20 Jan 2026 | Head of IT | EXAMPLE — Operating: in place since 2026-01-20, with records covering more than 3 months. | ||
| EXAMPLE | A.5.18 | Annex A | A.5 | Access rights | No | Yes | 2 | 3 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. Quarterly access reviews started in August (see the P07 pack). | ||
| EXAMPLE | A.5.19 | Annex A | A.5 | Information security in supplier relationships | No | Yes | 1 | Head of Procurement | 1 | EXAMPLE — Gap: The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied. Action: Obtain approval of the Supplier Security Policy (P04 register SUP-001), publish it, and tier the existing suppliers, using the supplier-assessment templates in the P06 pack. | ||
| EXAMPLE | A.5.20 | Annex A | A.5 | Addressing information security within supplier agreements | No | Yes | 1 | Head of Procurement | 4 | EXAMPLE — Gap: Security clauses are missing from most key supplier contracts. Action: Add the security clauses for each supplier tier to the contracts of the Tier 1 suppliers at renewal, or by side letter. | ||
| EXAMPLE | A.5.21 | Annex A | A.5 | Managing information security in the ICT supply chain | No | Yes | 1 | Head of Procurement | 2 | EXAMPLE — Gap: No check of the security of the software and cloud supply chain. Action: Ask Tier 1 technology suppliers about their own suppliers and components, and record the answers with the supplier assessment. | ||
| EXAMPLE | A.5.22 | Annex A | A.5 | Monitoring, review and change management of supplier services | No | Yes | 1 | Head of Procurement | 2 | EXAMPLE — Gap: Supplier performance and changes are not reviewed for security. Action: Set a review interval per supplier tier and hold the first reviews of Tier 1 suppliers. | ||
| EXAMPLE | A.5.23 | Annex A | A.5 | Information security for use of cloud services | No | Yes | 2 | 10 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10. | ||
| EXAMPLE | A.5.24 | Annex A | A.5 | Information security incident management planning and preparation | No | Yes | 3 | 4 May 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months. | ||
| EXAMPLE | A.5.25 | Annex A | A.5 | Assessment and decision on information security events | No | Yes | 3 | 4 May 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months. | ||
| EXAMPLE | A.5.26 | Annex A | A.5 | Response to information security incidents | No | Yes | 3 | 4 May 2026 | Head of Information Security | EXAMPLE — Operating: in place since 2026-05-04, with records covering more than 3 months. | ||
| EXAMPLE | A.5.27 | Annex A | A.5 | Learning from information security incidents | No | Yes | 2 | 6 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.5.28 | Annex A | A.5 | Collection of evidence | No | Yes | 1 | Legal Counsel | 1 | EXAMPLE — Gap: No agreed way to collect and preserve evidence from an incident. Action: Write a one-page evidence-handling note (what to keep, who, how, chain of custody) and add it to the incident procedure. | ||
| EXAMPLE | A.5.29 | Annex A | A.5 | Information security during disruption | No | Yes | 2 | 7 Sep 2026 | IT Operations Manager | EXAMPLE — In place since 2026-09-07; 3 months of records by 2026-12-07. | ||
| EXAMPLE | A.5.30 | Annex A | A.5 | ICT readiness for business continuity | No | Yes | 1 | IT Operations Manager | 4 | EXAMPLE — Gap: Recovery objectives are set but the platform's recovery has not been tested. Action: Test the recovery of the production platform against its recovery objectives and record the result and the fixes. | ||
| EXAMPLE | A.5.31 | Annex A | A.5 | Legal, statutory, regulatory and contractual requirements | No | Yes | 1 | Legal Counsel | 3 | EXAMPLE — Gap: No register of legal, regulatory and contractual security requirements. Action: Build the register (including NIS2 duties and customer contract terms), with an owner for each and a yearly review. | ||
| EXAMPLE | A.5.32 | Annex A | A.5 | Intellectual property rights | No | Yes | 2 | 6 Jul 2026 | Legal Counsel | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.5.33 | Annex A | A.5 | Protection of records | No | Yes | 1 | Legal Counsel | 2 | EXAMPLE — Gap: Retention periods are not set for security records. Action: Set retention and protection for the ISMS and security records in the records schedule. | ||
| EXAMPLE | A.5.34 | Annex A | A.5 | Privacy and protection of PII | No | Yes | 2 | 6 Jul 2026 | Legal Counsel | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.5.35 | Annex A | A.5 | Independent review of information security | No | Yes | 1 | Chief Operating Officer | 1 | EXAMPLE — Gap: No plan for independent review of the ISMS beyond the certification audit. Action: Record in the audit programme how and how often the ISMS is independently reviewed. | ||
| EXAMPLE | A.5.36 | Annex A | A.5 | Compliance with policies, rules and standards for information security | No | Yes | 2 | 10 Sep 2026 | Head of Information Security | EXAMPLE — In place since 2026-09-10; 3 months of records by 2026-12-10. Security Exception & Waiver Standard EXC-STD approved on 2026-09-10. | ||
| EXAMPLE | A.5.37 | Annex A | A.5 | Documented operating procedures | No | Yes | 2 | 24 Aug 2026 | IT Operations Manager | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | A.6.1 | Annex A | A.6 | Screening | No | Yes | 3 | 6 Jan 2025 | HR Director | EXAMPLE — Operating: in place since 2025-01-06, with records covering more than 3 months. | ||
| EXAMPLE | A.6.2 | Annex A | A.6 | Terms and conditions of employment | No | Yes | 2 | 6 Jul 2026 | HR Director | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.6.3 | Annex A | A.6 | Information security awareness, education and training | No | Yes | 2 | 14 Sep 2026 | Head of Information Security | EXAMPLE — In place since 2026-09-14; 3 months of records by 2026-12-14. | ||
| EXAMPLE | A.6.4 | Annex A | A.6 | Disciplinary process | No | Yes | 1 | HR Director | 1 | EXAMPLE — Gap: The disciplinary procedure does not mention information security breaches. Action: Add security breaches to the disciplinary procedure and tell staff through the awareness programme. | ||
| EXAMPLE | A.6.5 | Annex A | A.6 | Responsibilities after termination or change of employment | No | Yes | 3 | 3 Feb 2025 | HR Director | EXAMPLE — Operating: in place since 2025-02-03, with records covering more than 3 months. | ||
| EXAMPLE | A.6.6 | Annex A | A.6 | Confidentiality or non-disclosure agreements | No | Yes | 2 | 6 Jul 2026 | HR Director | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.6.7 | Annex A | A.6 | Remote working | No | Yes | 3 | 18 Nov 2025 | Head of IT | EXAMPLE — Operating: in place since 2025-11-18, with records covering more than 3 months. | ||
| EXAMPLE | A.6.8 | Annex A | A.6 | Information security event reporting | No | Yes | 2 | 6 Jul 2026 | Head of Information Security | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.1 | Annex A | A.7 | Physical security perimeters | No | Yes | 3 | 2 Sep 2024 | Office Manager | EXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months. | ||
| EXAMPLE | A.7.2 | Annex A | A.7 | Physical entry | No | Yes | 3 | 2 Sep 2024 | Office Manager | EXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months. | ||
| EXAMPLE | A.7.3 | Annex A | A.7 | Securing offices, rooms and facilities | No | Yes | 2 | 6 Jul 2026 | Office Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.4 | Annex A | A.7 | Physical security monitoring | No | Yes | 1 | Office Manager | 2 | EXAMPLE — Gap: Camera coverage and alarm monitoring of the second office are not confirmed. Action: Agree monitoring of both offices with the landlord, confirm coverage of entrances and the equipment room, and record the check. | ||
| EXAMPLE | A.7.5 | Annex A | A.7 | Protecting against physical and environmental threats | No | Yes | 2 | 6 Jul 2026 | Office Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.6 | Annex A | A.7 | Working in secure areas | No | Yes | 2 | 6 Jul 2026 | Office Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.7 | Annex A | A.7 | Clear desk and clear screen | No | Yes | 1 | Office Manager | 1 | EXAMPLE — Gap: No clear desk and clear screen rule. Action: Publish the rule, set screen lock by policy on every device, and check the offices monthly. | ||
| EXAMPLE | A.7.8 | Annex A | A.7 | Equipment siting and protection | No | Yes | 2 | 6 Jul 2026 | Office Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.9 | Annex A | A.7 | Security of assets off-premises | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.7.10 | Annex A | A.7 | Storage media | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.7.11 | Annex A | A.7 | Supporting utilities | No | Yes | 2 | 6 Jul 2026 | IT Operations Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.12 | Annex A | A.7 | Cabling security | No | Yes | 2 | 6 Jul 2026 | IT Operations Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.13 | Annex A | A.7 | Equipment maintenance | No | Yes | 2 | 6 Jul 2026 | IT Operations Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.7.14 | Annex A | A.7 | Secure disposal or re-use of equipment | No | Yes | 1 | IT Operations Manager | 1 | EXAMPLE — Gap: Disposal of laptops and drives is done by a supplier without certificates. Action: Require a destruction certificate for every disposed device and reconcile it with the asset inventory. | ||
| EXAMPLE | A.8.1 | Annex A | A.8 | User endpoint devices | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.2 | Annex A | A.8 | Privileged access rights | No | Yes | 2 | 3 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-03; 3 months of records by 2026-11-03. | ||
| EXAMPLE | A.8.3 | Annex A | A.8 | Information access restriction | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.4 | Annex A | A.8 | Access to source code | No | Yes | 2 | 20 Jul 2026 | Head of Engineering | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.5 | Annex A | A.8 | Secure authentication | No | Yes | 3 | 6 Oct 2025 | Head of IT | EXAMPLE — Operating: in place since 2025-10-06, with records covering more than 3 months. | ||
| EXAMPLE | A.8.6 | Annex A | A.8 | Capacity management | No | Yes | 1 | IT Operations Manager | 2 | EXAMPLE — Gap: Capacity is watched but no thresholds or forecast exist. Action: Set capacity thresholds and alerts for the platform and review a quarterly forecast. | ||
| EXAMPLE | A.8.7 | Annex A | A.8 | Protection against malware | No | Yes | 3 | 2 Sep 2024 | Head of IT | EXAMPLE — Operating: in place since 2024-09-02, with records covering more than 3 months. | ||
| EXAMPLE | A.8.8 | Annex A | A.8 | Management of technical vulnerabilities | No | Yes | 2 | 10 Sep 2026 | Head of IT | EXAMPLE — In place since 2026-09-10; 3 months of records by 2026-12-10. Vulnerability & Exposure Management Standard VMS-001 approved on 2026-09-10 (see the P01 pack). | ||
| EXAMPLE | A.8.9 | Annex A | A.8 | Configuration management | No | Yes | 1 | Head of IT | 4 | EXAMPLE — Gap: No approved baseline configurations for servers, laptops or cloud services. Action: Approve baseline configurations for the main system types, apply them, and check drift monthly. | ||
| EXAMPLE | A.8.10 | Annex A | A.8 | Information deletion | No | Yes | 1 | IT Operations Manager | 2 | EXAMPLE — Gap: Customer data is not deleted on a set schedule after contracts end. Action: Define deletion periods for customer and internal data, automate the deletion job, and keep its log. | ||
| EXAMPLE | A.8.11 | Annex A | A.8 | Data masking | No | Yes | 0 | Head of Engineering | 3 | EXAMPLE — Gap: Production data is copied to test without masking. Action: Mask personal and customer data in every copy made for testing, and block unmasked copies. | ||
| EXAMPLE | A.8.12 | Annex A | A.8 | Data leakage prevention | No | Yes | 0 | Head of IT | 3 | EXAMPLE — Gap: No controls to detect data leaving through email, storage or endpoints. Action: Turn on data loss prevention rules for customer data in email and cloud storage, in report-only mode first, then block. | ||
| EXAMPLE | A.8.13 | Annex A | A.8 | Information backup | No | Yes | 3 | 15 Aug 2025 | IT Operations Manager | EXAMPLE — Operating: in place since 2025-08-15, with records covering more than 3 months. | ||
| EXAMPLE | A.8.14 | Annex A | A.8 | Redundancy of information processing facilities | No | Yes | 2 | 10 Aug 2026 | IT Operations Manager | EXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10. | ||
| EXAMPLE | A.8.15 | Annex A | A.8 | Logging | No | Yes | 2 | 10 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10. | ||
| EXAMPLE | A.8.16 | Annex A | A.8 | Monitoring activities | No | Yes | 1 | Head of IT | 3 | EXAMPLE — Gap: Logs are collected but not monitored for anomalies. Action: Define the alerts that matter, route them to the on-call rota, and record the weekly review. | ||
| EXAMPLE | A.8.17 | Annex A | A.8 | Clock synchronization | No | Yes | 2 | 6 Jul 2026 | IT Operations Manager | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. | ||
| EXAMPLE | A.8.18 | Annex A | A.8 | Use of privileged utility programs | No | Yes | 1 | Head of IT | 1 | EXAMPLE — Gap: Use of privileged utility programs is not restricted. Action: List the utility programs that can override controls, restrict them to named administrators and log their use. | ||
| EXAMPLE | A.8.19 | Annex A | A.8 | Installation of software on operational systems | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.20 | Annex A | A.8 | Networks security | No | Yes | 3 | 3 Mar 2025 | Head of IT | EXAMPLE — Operating: in place since 2025-03-03, with records covering more than 3 months. | ||
| EXAMPLE | A.8.21 | Annex A | A.8 | Security of network services | No | Yes | 2 | 10 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-10; 3 months of records by 2026-11-10. | ||
| EXAMPLE | A.8.22 | Annex A | A.8 | Segregation of networks | No | Yes | 2 | 20 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.23 | Annex A | A.8 | Web filtering | No | Yes | 1 | Head of IT | 1 | EXAMPLE — Gap: Web filtering is on in the offices only, not on remote devices. Action: Extend the web filter to every managed device wherever it connects. | ||
| EXAMPLE | A.8.24 | Annex A | A.8 | Use of cryptography | No | Yes | 2 | 24 Aug 2026 | Head of IT | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | A.8.25 | Annex A | A.8 | Secure development life cycle | No | Yes | 2 | 24 Aug 2026 | Head of Engineering | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | A.8.26 | Annex A | A.8 | Application security requirements | No | Yes | 1 | Head of Engineering | 2 | EXAMPLE — Gap: Security requirements are not written into feature specifications. Action: Add a security requirements section to the specification template and review it at design sign-off. | ||
| EXAMPLE | A.8.27 | Annex A | A.8 | Secure system architecture and engineering principles | No | Yes | 1 | Head of Engineering | 2 | EXAMPLE — Gap: Architecture principles for security are not written down. Action: Write the secure architecture principles for the platform and apply them in design reviews. | ||
| EXAMPLE | A.8.28 | Annex A | A.8 | Secure coding | No | Yes | 2 | 24 Aug 2026 | Head of Engineering | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | A.8.29 | Annex A | A.8 | Security testing in development and acceptance | No | Yes | 2 | 24 Aug 2026 | Head of Engineering | EXAMPLE — In place since 2026-08-24; 3 months of records by 2026-11-24. | ||
| EXAMPLE | A.8.30 | Annex A | A.8 | Outsourced development | No | No | All software is developed by the company's own staff; no development is outsourced. Revisit if a contractor or agency writes code. | Excluded in the example's Statement of Applicability. | ||||
| EXAMPLE | A.8.31 | Annex A | A.8 | Separation of development, test and production environments | No | Yes | 2 | 20 Jul 2026 | Head of Engineering | EXAMPLE — In place since 2026-07-20; 3 months of records by 2026-10-20. | ||
| EXAMPLE | A.8.32 | Annex A | A.8 | Change management | No | Yes | 3 | 5 May 2025 | Head of Engineering | EXAMPLE — Operating: in place since 2025-05-05, with records covering more than 3 months. | ||
| EXAMPLE | A.8.33 | Annex A | A.8 | Test information | No | Yes | 1 | Head of Engineering | 2 | EXAMPLE — Gap: No rules for selecting and protecting test data. Action: Set rules for choosing, protecting and deleting test data, together with the masking in A.8.11. | ||
| EXAMPLE | A.8.34 | Annex A | A.8 | Protection of information systems during audit testing | No | Yes | 2 | 6 Jul 2026 | Head of IT | EXAMPLE — In place since 2026-07-06; 3 months of records by 2026-10-06. |
Results by Requirement
Calculated: one row per requirement, from the answers the Settings sheet selects. This table is the export — copy it and paste as values. Do not type in it.
| ID | Kind | Clause or theme | Requirement | Blocker? | Applicable? | Score | Level | Owner | Weeks to In place | In place since | Queue order | Forecast In place | Forecast Operating | Date that counts for Stage 2 | Float (weeks) | Critical path? | Blocker In place (working) | Blocking list order (working) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4.1 | Clause | 4 | Understanding the organization and its context | No | Yes | 3 | Operating | 0 | 27 Apr 2026 | 10004 | ||||||||
| 4.2 | Clause | 4 | Understanding the needs and expectations of interested parties | No | Yes | 3 | Operating | 0 | 27 Apr 2026 | 10005 | ||||||||
| 4.3 | Clause | 4 | Determining the scope of the information security management system | Yes | Yes | 3 | Operating | 0 | 11 May 2026 | 6 | ||||||||
| 4.4 | Clause | 4 | Information security management system | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10007 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| 5.1 | Clause | 5 | Leadership and commitment | No | Yes | 3 | Operating | 0 | 6 Apr 2026 | 10008 | ||||||||
| 5.2 | Clause | 5 | Policy | Yes | Yes | 3 | Operating | 0 | 12 Mar 2026 | 9 | ||||||||
| 5.3 | Clause | 5 | Organizational roles, responsibilities and authorities | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10010 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| 6.1.1 | Clause | 6 | General | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10011 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| 6.1.2 | Clause | 6 | Information security risk assessment | Yes | Yes | 3 | Operating | 0 | 15 Jun 2026 | 12 | ||||||||
| 6.1.3 | Clause | 6 | Information security risk treatment | Yes | Yes | 2 | In place | 0 | 24 Aug 2026 | 13 | 24 Aug 2026 | 24 Nov 2026 | 24 Nov 2026 | 11.3 | No | 24 Aug 2026 | 1129013 | |
| 6.2 | Clause | 6 | Information security objectives and planning to achieve them | Yes | Yes | 1 | Planned | Head of Information Security | 3 | 14 | 21 Oct 2026 | 21 Jan 2027 | 21 Jan 2027 | 3.0 | No | 21 Oct 2026 | 300014 | |
| 6.3 | Clause | 6 | Planning of changes | No | Yes | 1 | Planned | Chief Operating Officer | 1 | 10015 | 14 Oct 2026 | 14 Jan 2027 | 14 Oct 2026 | 17.1 | No | |||
| 7.1 | Clause | 7 | Resources | No | Yes | 3 | Operating | 0 | 6 Apr 2026 | 10016 | ||||||||
| 7.2 | Clause | 7 | Competence | No | Yes | 2 | In place | 0 | 1 Sep 2026 | 10017 | 1 Sep 2026 | 1 Dec 2026 | 1 Sep 2026 | 23.3 | No | |||
| 7.3 | Clause | 7 | Awareness | No | Yes | 2 | In place | 0 | 14 Sep 2026 | 10018 | 14 Sep 2026 | 14 Dec 2026 | 14 Sep 2026 | 21.4 | No | |||
| 7.4 | Clause | 7 | Communication | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10019 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| 7.5.1 | Clause | 7 | General | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10020 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| 7.5.2 | Clause | 7 | Creating and updating | No | Yes | 3 | Operating | 0 | 12 Mar 2026 | 10021 | ||||||||
| 7.5.3 | Clause | 7 | Control of documented information | No | Yes | 1 | Planned | Head of Information Security | 1 | 10022 | 18 Nov 2026 | 18 Feb 2027 | 18 Nov 2026 | 12.1 | No | |||
| 8.1 | Clause | 8 | Operational planning and control | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10023 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| 8.2 | Clause | 8 | Information security risk assessment | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10024 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| 8.3 | Clause | 8 | Information security risk treatment | No | Yes | 1 | Planned | Head of Information Security | 2 | 10025 | 2 Dec 2026 | 2 Mar 2027 | 2 Dec 2026 | 10.1 | No | |||
| 9.1 | Clause | 9 | Monitoring, measurement, analysis and evaluation | No | Yes | 1 | Planned | Head of Information Security | 3 | 10026 | 23 Dec 2026 | 23 Mar 2027 | 23 Dec 2026 | 7.1 | No | |||
| 9.2.1 | Clause | 9 | General | No | Yes | 1 | Planned | Head of Information Security | 1 | 10027 | 30 Dec 2026 | 30 Mar 2027 | 30 Dec 2026 | 6.1 | No | |||
| 9.2.2 | Clause | 9 | Internal audit programme | Yes | Yes | 1 | Planned | Head of Information Security | 1 | 28 | 28 Oct 2026 | 28 Jan 2027 | 28 Jan 2027 | 2.0 | Yes | 28 Oct 2026 | 200028 | |
| 9.3.1 | Clause | 9 | General | No | Yes | 1 | Planned | Chief Operating Officer | 1 | 10029 | 21 Oct 2026 | 21 Jan 2027 | 21 Oct 2026 | 16.1 | No | |||
| 9.3.2 | Clause | 9 | Management review inputs | No | Yes | 1 | Planned | Head of Information Security | 1 | 10030 | 6 Jan 2027 | 6 Apr 2027 | 6 Jan 2027 | 5.1 | No | |||
| 9.3.3 | Clause | 9 | Management review results | Yes | Yes | 1 | Planned | Chief Operating Officer | 1 | 31 | 7 Oct 2026 | 7 Jan 2027 | 7 Jan 2027 | 5.0 | No | 7 Oct 2026 | 500031 | |
| 10.1 | Clause | 10 | Continual improvement | No | Yes | 1 | Planned | Head of Information Security | 1 | 10032 | 13 Jan 2027 | 13 Apr 2027 | 13 Jan 2027 | 4.1 | No | |||
| 10.2 | Clause | 10 | Nonconformity and corrective action | Yes | Yes | 1 | Planned | Head of Information Security | 2 | 33 | 11 Nov 2026 | 11 Feb 2027 | 11 Feb 2027 | 0.0 | Yes | 11 Nov 2026 | 33 | |
| A.5.1 | Annex A | A.5 | Policies for information security | No | Yes | 3 | Operating | 0 | 12 Mar 2026 | 10034 | ||||||||
| A.5.2 | Annex A | A.5 | Information security roles and responsibilities | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10035 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| A.5.3 | Annex A | A.5 | Segregation of duties | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10036 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.5.4 | Annex A | A.5 | Management responsibilities | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10037 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| A.5.5 | Annex A | A.5 | Contact with authorities | No | Yes | 1 | Planned | Head of Information Security | 1 | 10038 | 20 Jan 2027 | 20 Apr 2027 | 20 Jan 2027 | 3.1 | No | |||
| A.5.6 | Annex A | A.5 | Contact with special interest groups | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10039 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.5.7 | Annex A | A.5 | Threat intelligence | No | Yes | 1 | Planned | Head of Information Security | 2 | 10040 | 3 Feb 2027 | 3 May 2027 | 3 Feb 2027 | 1.1 | Yes | 114040 | ||
| A.5.8 | Annex A | A.5 | Information security in project management | No | Yes | 1 | Planned | Head of Engineering | 1 | 10041 | 7 Oct 2026 | 7 Jan 2027 | 7 Oct 2026 | 18.1 | No | |||
| A.5.9 | Annex A | A.5 | Inventory of information and other associated assets | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10042 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.5.10 | Annex A | A.5 | Acceptable use of information and other associated assets | No | Yes | 3 | Operating | 0 | 1 Jul 2025 | 10043 | ||||||||
| A.5.11 | Annex A | A.5 | Return of assets | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10044 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.5.12 | Annex A | A.5 | Classification of information | No | Yes | 2 | In place | 0 | 17 Aug 2026 | 10045 | 17 Aug 2026 | 17 Nov 2026 | 17 Aug 2026 | 25.4 | No | |||
| A.5.13 | Annex A | A.5 | Labelling of information | No | Yes | 0 | Not started | Head of IT | 2 | 10046 | 14 Oct 2026 | 14 Jan 2027 | 14 Oct 2026 | 17.1 | No | |||
| A.5.14 | Annex A | A.5 | Information transfer | No | Yes | 2 | In place | 0 | 17 Aug 2026 | 10047 | 17 Aug 2026 | 17 Nov 2026 | 17 Aug 2026 | 25.4 | No | |||
| A.5.15 | Annex A | A.5 | Access control | No | Yes | 3 | Operating | 0 | 20 Jan 2026 | 10048 | ||||||||
| A.5.16 | Annex A | A.5 | Identity management | No | Yes | 3 | Operating | 0 | 20 Jan 2026 | 10049 | ||||||||
| A.5.17 | Annex A | A.5 | Authentication information | No | Yes | 3 | Operating | 0 | 20 Jan 2026 | 10050 | ||||||||
| A.5.18 | Annex A | A.5 | Access rights | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10051 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| A.5.19 | Annex A | A.5 | Information security in supplier relationships | No | Yes | 1 | Planned | Head of Procurement | 1 | 10052 | 7 Oct 2026 | 7 Jan 2027 | 7 Oct 2026 | 18.1 | No | |||
| A.5.20 | Annex A | A.5 | Addressing information security within supplier agreements | No | Yes | 1 | Planned | Head of Procurement | 4 | 10053 | 4 Nov 2026 | 4 Feb 2027 | 4 Nov 2026 | 14.1 | No | |||
| A.5.21 | Annex A | A.5 | Managing information security in the ICT supply chain | No | Yes | 1 | Planned | Head of Procurement | 2 | 10054 | 18 Nov 2026 | 18 Feb 2027 | 18 Nov 2026 | 12.1 | No | |||
| A.5.22 | Annex A | A.5 | Monitoring, review and change management of supplier services | No | Yes | 1 | Planned | Head of Procurement | 2 | 10055 | 2 Dec 2026 | 2 Mar 2027 | 2 Dec 2026 | 10.1 | No | |||
| A.5.23 | Annex A | A.5 | Information security for use of cloud services | No | Yes | 2 | In place | 0 | 10 Aug 2026 | 10056 | 10 Aug 2026 | 10 Nov 2026 | 10 Aug 2026 | 26.4 | No | |||
| A.5.24 | Annex A | A.5 | Information security incident management planning and preparation | No | Yes | 3 | Operating | 0 | 4 May 2026 | 10057 | ||||||||
| A.5.25 | Annex A | A.5 | Assessment and decision on information security events | No | Yes | 3 | Operating | 0 | 4 May 2026 | 10058 | ||||||||
| A.5.26 | Annex A | A.5 | Response to information security incidents | No | Yes | 3 | Operating | 0 | 4 May 2026 | 10059 | ||||||||
| A.5.27 | Annex A | A.5 | Learning from information security incidents | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10060 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.5.28 | Annex A | A.5 | Collection of evidence | No | Yes | 1 | Planned | Legal Counsel | 1 | 10061 | 7 Oct 2026 | 7 Jan 2027 | 7 Oct 2026 | 18.1 | No | |||
| A.5.29 | Annex A | A.5 | Information security during disruption | No | Yes | 2 | In place | 0 | 7 Sep 2026 | 10062 | 7 Sep 2026 | 7 Dec 2026 | 7 Sep 2026 | 22.4 | No | |||
| A.5.30 | Annex A | A.5 | ICT readiness for business continuity | No | Yes | 1 | Planned | IT Operations Manager | 4 | 10063 | 28 Oct 2026 | 28 Jan 2027 | 28 Oct 2026 | 15.1 | No | |||
| A.5.31 | Annex A | A.5 | Legal, statutory, regulatory and contractual requirements | No | Yes | 1 | Planned | Legal Counsel | 3 | 10064 | 28 Oct 2026 | 28 Jan 2027 | 28 Oct 2026 | 15.1 | No | |||
| A.5.32 | Annex A | A.5 | Intellectual property rights | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10065 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.5.33 | Annex A | A.5 | Protection of records | No | Yes | 1 | Planned | Legal Counsel | 2 | 10066 | 11 Nov 2026 | 11 Feb 2027 | 11 Nov 2026 | 13.1 | No | |||
| A.5.34 | Annex A | A.5 | Privacy and protection of PII | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10067 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.5.35 | Annex A | A.5 | Independent review of information security | No | Yes | 1 | Planned | Chief Operating Officer | 1 | 10068 | 28 Oct 2026 | 28 Jan 2027 | 28 Oct 2026 | 15.1 | No | |||
| A.5.36 | Annex A | A.5 | Compliance with policies, rules and standards for information security | No | Yes | 2 | In place | 0 | 10 Sep 2026 | 10069 | 10 Sep 2026 | 10 Dec 2026 | 10 Sep 2026 | 22.0 | No | |||
| A.5.37 | Annex A | A.5 | Documented operating procedures | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10070 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| A.6.1 | Annex A | A.6 | Screening | No | Yes | 3 | Operating | 0 | 6 Jan 2025 | 10071 | ||||||||
| A.6.2 | Annex A | A.6 | Terms and conditions of employment | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10072 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.6.3 | Annex A | A.6 | Information security awareness, education and training | No | Yes | 2 | In place | 0 | 14 Sep 2026 | 10073 | 14 Sep 2026 | 14 Dec 2026 | 14 Sep 2026 | 21.4 | No | |||
| A.6.4 | Annex A | A.6 | Disciplinary process | No | Yes | 1 | Planned | HR Director | 1 | 10074 | 7 Oct 2026 | 7 Jan 2027 | 7 Oct 2026 | 18.1 | No | |||
| A.6.5 | Annex A | A.6 | Responsibilities after termination or change of employment | No | Yes | 3 | Operating | 0 | 3 Feb 2025 | 10075 | ||||||||
| A.6.6 | Annex A | A.6 | Confidentiality or non-disclosure agreements | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10076 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.6.7 | Annex A | A.6 | Remote working | No | Yes | 3 | Operating | 0 | 18 Nov 2025 | 10077 | ||||||||
| A.6.8 | Annex A | A.6 | Information security event reporting | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10078 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.1 | Annex A | A.7 | Physical security perimeters | No | Yes | 3 | Operating | 0 | 2 Sep 2024 | 10079 | ||||||||
| A.7.2 | Annex A | A.7 | Physical entry | No | Yes | 3 | Operating | 0 | 2 Sep 2024 | 10080 | ||||||||
| A.7.3 | Annex A | A.7 | Securing offices, rooms and facilities | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10081 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.4 | Annex A | A.7 | Physical security monitoring | No | Yes | 1 | Planned | Office Manager | 2 | 10082 | 14 Oct 2026 | 14 Jan 2027 | 14 Oct 2026 | 17.1 | No | |||
| A.7.5 | Annex A | A.7 | Protecting against physical and environmental threats | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10083 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.6 | Annex A | A.7 | Working in secure areas | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10084 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.7 | Annex A | A.7 | Clear desk and clear screen | No | Yes | 1 | Planned | Office Manager | 1 | 10085 | 21 Oct 2026 | 21 Jan 2027 | 21 Oct 2026 | 16.1 | No | |||
| A.7.8 | Annex A | A.7 | Equipment siting and protection | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10086 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.9 | Annex A | A.7 | Security of assets off-premises | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10087 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.7.10 | Annex A | A.7 | Storage media | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10088 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.7.11 | Annex A | A.7 | Supporting utilities | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10089 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.12 | Annex A | A.7 | Cabling security | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10090 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.13 | Annex A | A.7 | Equipment maintenance | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10091 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.7.14 | Annex A | A.7 | Secure disposal or re-use of equipment | No | Yes | 1 | Planned | IT Operations Manager | 1 | 10092 | 4 Nov 2026 | 4 Feb 2027 | 4 Nov 2026 | 14.1 | No | |||
| A.8.1 | Annex A | A.8 | User endpoint devices | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10093 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.2 | Annex A | A.8 | Privileged access rights | No | Yes | 2 | In place | 0 | 3 Aug 2026 | 10094 | 3 Aug 2026 | 3 Nov 2026 | 3 Aug 2026 | 27.4 | No | |||
| A.8.3 | Annex A | A.8 | Information access restriction | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10095 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.4 | Annex A | A.8 | Access to source code | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10096 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.5 | Annex A | A.8 | Secure authentication | No | Yes | 3 | Operating | 0 | 6 Oct 2025 | 10097 | ||||||||
| A.8.6 | Annex A | A.8 | Capacity management | No | Yes | 1 | Planned | IT Operations Manager | 2 | 10098 | 18 Nov 2026 | 18 Feb 2027 | 18 Nov 2026 | 12.1 | No | |||
| A.8.7 | Annex A | A.8 | Protection against malware | No | Yes | 3 | Operating | 0 | 2 Sep 2024 | 10099 | ||||||||
| A.8.8 | Annex A | A.8 | Management of technical vulnerabilities | No | Yes | 2 | In place | 0 | 10 Sep 2026 | 10100 | 10 Sep 2026 | 10 Dec 2026 | 10 Sep 2026 | 22.0 | No | |||
| A.8.9 | Annex A | A.8 | Configuration management | No | Yes | 1 | Planned | Head of IT | 4 | 10101 | 11 Nov 2026 | 11 Feb 2027 | 11 Nov 2026 | 13.1 | No | |||
| A.8.10 | Annex A | A.8 | Information deletion | No | Yes | 1 | Planned | IT Operations Manager | 2 | 10102 | 2 Dec 2026 | 2 Mar 2027 | 2 Dec 2026 | 10.1 | No | |||
| A.8.11 | Annex A | A.8 | Data masking | No | Yes | 0 | Not started | Head of Engineering | 3 | 10103 | 28 Oct 2026 | 28 Jan 2027 | 28 Oct 2026 | 15.1 | No | |||
| A.8.12 | Annex A | A.8 | Data leakage prevention | No | Yes | 0 | Not started | Head of IT | 3 | 10104 | 2 Dec 2026 | 2 Mar 2027 | 2 Dec 2026 | 10.1 | No | |||
| A.8.13 | Annex A | A.8 | Information backup | No | Yes | 3 | Operating | 0 | 15 Aug 2025 | 10105 | ||||||||
| A.8.14 | Annex A | A.8 | Redundancy of information processing facilities | No | Yes | 2 | In place | 0 | 10 Aug 2026 | 10106 | 10 Aug 2026 | 10 Nov 2026 | 10 Aug 2026 | 26.4 | No | |||
| A.8.15 | Annex A | A.8 | Logging | No | Yes | 2 | In place | 0 | 10 Aug 2026 | 10107 | 10 Aug 2026 | 10 Nov 2026 | 10 Aug 2026 | 26.4 | No | |||
| A.8.16 | Annex A | A.8 | Monitoring activities | No | Yes | 1 | Planned | Head of IT | 3 | 10108 | 23 Dec 2026 | 23 Mar 2027 | 23 Dec 2026 | 7.1 | No | |||
| A.8.17 | Annex A | A.8 | Clock synchronization | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10109 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No | |||
| A.8.18 | Annex A | A.8 | Use of privileged utility programs | No | Yes | 1 | Planned | Head of IT | 1 | 10110 | 30 Dec 2026 | 30 Mar 2027 | 30 Dec 2026 | 6.1 | No | |||
| A.8.19 | Annex A | A.8 | Installation of software on operational systems | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10111 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.20 | Annex A | A.8 | Networks security | No | Yes | 3 | Operating | 0 | 3 Mar 2025 | 10112 | ||||||||
| A.8.21 | Annex A | A.8 | Security of network services | No | Yes | 2 | In place | 0 | 10 Aug 2026 | 10113 | 10 Aug 2026 | 10 Nov 2026 | 10 Aug 2026 | 26.4 | No | |||
| A.8.22 | Annex A | A.8 | Segregation of networks | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10114 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.23 | Annex A | A.8 | Web filtering | No | Yes | 1 | Planned | Head of IT | 1 | 10115 | 6 Jan 2027 | 6 Apr 2027 | 6 Jan 2027 | 5.1 | No | |||
| A.8.24 | Annex A | A.8 | Use of cryptography | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10116 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| A.8.25 | Annex A | A.8 | Secure development life cycle | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10117 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| A.8.26 | Annex A | A.8 | Application security requirements | No | Yes | 1 | Planned | Head of Engineering | 2 | 10118 | 11 Nov 2026 | 11 Feb 2027 | 11 Nov 2026 | 13.1 | No | |||
| A.8.27 | Annex A | A.8 | Secure system architecture and engineering principles | No | Yes | 1 | Planned | Head of Engineering | 2 | 10119 | 25 Nov 2026 | 25 Feb 2027 | 25 Nov 2026 | 11.1 | No | |||
| A.8.28 | Annex A | A.8 | Secure coding | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10120 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| A.8.29 | Annex A | A.8 | Security testing in development and acceptance | No | Yes | 2 | In place | 0 | 24 Aug 2026 | 10121 | 24 Aug 2026 | 24 Nov 2026 | 24 Aug 2026 | 24.4 | No | |||
| A.8.30 | Annex A | A.8 | Outsourced development | No | No | Not applicable | 0 | 10122 | ||||||||||
| A.8.31 | Annex A | A.8 | Separation of development, test and production environments | No | Yes | 2 | In place | 0 | 20 Jul 2026 | 10123 | 20 Jul 2026 | 20 Oct 2026 | 20 Jul 2026 | 29.4 | No | |||
| A.8.32 | Annex A | A.8 | Change management | No | Yes | 3 | Operating | 0 | 5 May 2025 | 10124 | ||||||||
| A.8.33 | Annex A | A.8 | Test information | No | Yes | 1 | Planned | Head of Engineering | 2 | 10125 | 9 Dec 2026 | 9 Mar 2027 | 9 Dec 2026 | 9.1 | No | |||
| A.8.34 | Annex A | A.8 | Protection of information systems during audit testing | No | Yes | 2 | In place | 0 | 6 Jul 2026 | 10126 | 6 Jul 2026 | 6 Oct 2026 | 6 Jul 2026 | 31.4 | No |
Summary & Estimate
Summary and estimate
Readiness as 'x of y at Operating', the blockers, the estimated earliest Stage 2 date worked out step by step, and the items that decide it. Everything here is calculated.
EXAMPLE: results for the example organisation, as at 2026-09-30. Choose 'My answers' on the Settings sheet to see your own.
Readiness by clause and Annex A theme
| Area | Title | Assessed | Operating | In place | Planned | Not started | Not answered | Result: at Operating |
|---|---|---|---|---|---|---|---|---|
| Clause 4 | Context of the organization | 4 | 3 | 1 | 0 | 0 | 0 | 3 of 4 at Operating |
| Clause 5 | Leadership | 3 | 2 | 1 | 0 | 0 | 0 | 2 of 3 at Operating |
| Clause 6 | Planning | 5 | 1 | 2 | 2 | 0 | 0 | 1 of 5 at Operating |
| Clause 7 | Support | 7 | 2 | 4 | 1 | 0 | 0 | 2 of 7 at Operating |
| Clause 8 | Operation | 3 | 0 | 2 | 1 | 0 | 0 | 0 of 3 at Operating |
| Clause 9 | Performance evaluation | 6 | 0 | 0 | 6 | 0 | 0 | 0 of 6 at Operating |
| Clause 10 | Improvement | 2 | 0 | 0 | 2 | 0 | 0 | 0 of 2 at Operating |
| Annex A 5 | Organizational controls | 37 | 8 | 16 | 12 | 1 | 0 | 8 of 37 at Operating |
| Annex A 6 | People controls | 8 | 3 | 4 | 1 | 0 | 0 | 3 of 8 at Operating |
| Annex A 7 | Physical controls | 14 | 2 | 9 | 3 | 0 | 0 | 2 of 14 at Operating |
| Annex A 8 | Technological controls | 33 | 5 | 17 | 9 | 2 | 0 | 5 of 33 at Operating |
| All clause requirements | 30 | 8 | 10 | 12 | 0 | 0 | 8 of 30 at Operating | |
| All applicable Annex A controls | 92 | 18 | 46 | 25 | 3 | 0 | 18 of 92 at Operating | |
| Everything assessed | 122 | 26 | 56 | 37 | 3 | 0 | 26 of 122 at Operating | |
| Read the counts, not a percentage: a requirement at In place is working but has not yet produced the 3 months of records an auditor samples. 0 Not started · 1 Planned · 2 In place · 3 Operating. | ||||||||
Headline measures
| ID | Measure | Result | Target | |||||
|---|---|---|---|---|---|---|---|---|
| ISM-01 | Blocking items operating | 3 of 8 blockers at Operating | All, before the Stage 2 date | |||||
| ISM-02 | Requirements operating | 26 of 122 requirements at Operating | Rising monthly | |||||
| ISM-03 | Gaps overdue | Kept in the ISMS Gap & Remediation Tracker, which holds the agreed dates. | Zero on the critical path | |||||
| ISM-04 | Weeks to certification | 20 weeks to the earliest Stage 2 date (planned: 22 weeks) | On or before the planned date | |||||
The 8 blockers — each must be at Operating before Stage 2
| Clause | Title | Score | Level | Forecast In place | Forecast Operating | Float (weeks) | Critical path? | Owner |
|---|---|---|---|---|---|---|---|---|
| 4.3 | Determining the scope of the information security management system | 3 | Operating | |||||
| 5.2 | Policy | 3 | Operating | |||||
| 6.1.2 | Information security risk assessment | 3 | Operating | |||||
| 6.1.3 | Information security risk treatment | 2 | In place | 24 Aug 2026 | 24 Nov 2026 | 11.3 | No | |
| 6.2 | Information security objectives and planning to achieve them | 1 | Planned | 21 Oct 2026 | 21 Jan 2027 | 3.0 | No | Head of Information Security |
| 9.2.2 | Internal audit programme | 1 | Planned | 28 Oct 2026 | 28 Jan 2027 | 2.0 | Yes | Head of Information Security |
| 9.3.3 | Management review results | 1 | Planned | 7 Oct 2026 | 7 Jan 2027 | 5.0 | No | Chief Operating Officer |
| 10.2 | Nonconformity and corrective action | 1 | Planned | 11 Nov 2026 | 11 Feb 2027 | 0.0 | Yes | Head of Information Security |
Estimated earliest Stage 2 date, step by step
| Step | What it measures | Date | Working | |||||
|---|---|---|---|---|---|---|---|---|
| (a) | Remaining work: every item In place | 3 Feb 2027 | The last item to be put in place is A.5.7 (Head of Information Security), at the end of that owner's queue of 18 weeks of work. | |||||
| (b) | IS-05: 3 months of operation after the last blocker is In place | 11 Feb 2027 | The last blocker to be In place is 10.2 on 2026-11-11, plus 3 months of records. | |||||
| (c) | IS-06: internal audit and management review done | 6 Jan 2027 | Earliest end of the Check phase 2026-11-25 (audit programme In place 2026-10-28 + 4 weeks); planned audit end 2026-12-09; planned management review 2027-01-06. | |||||
| Estimated earliest Stage 2 date | 11 Feb 2027 | The latest of (a), (b) and (c): set by (b), the months of operation after the last blocker (IS-05). | ||||||
| Planned Stage 2 date | 1 Mar 2027 | From the Settings sheet. | ||||||
| Verdict | On track: 2.6 weeks to spare before the planned Stage 2 date. | |||||||
|---|---|---|---|---|---|---|---|---|
The blocking items, in the order to work on them
| No. | Requirement | Level | Forecast In place | Forecast Operating | Float (weeks) | Why it blocks | Row | Owner |
|---|---|---|---|---|---|---|---|---|
| 1 | 10.2 Nonconformity and corrective action | Planned | 11 Nov 2026 | 11 Feb 2027 | 0.0 | Blocker; critical path | 30 | Head of Information Security |
| 2 | A.5.7 Threat intelligence | Planned | 3 Feb 2027 | 3 May 2027 | 1.1 | Critical path | 37 | Head of Information Security |
| 3 | 9.2.2 Internal audit programme | Planned | 28 Oct 2026 | 28 Jan 2027 | 2.0 | Blocker; critical path | 25 | Head of Information Security |
| 4 | 6.2 Information security objectives and planning to achieve them | Planned | 21 Oct 2026 | 21 Jan 2027 | 3.0 | Blocker | 11 | Head of Information Security |
| 5 | 9.3.3 Management review results | Planned | 7 Oct 2026 | 7 Jan 2027 | 5.0 | Blocker | 28 | Chief Operating Officer |
| 6 | 6.1.3 Information security risk treatment | In place | 24 Aug 2026 | 24 Nov 2026 | 11.3 | Blocker | 10 |
7
8
9
10
11
12
13
14
15
Order: smallest float first — the items whose slip would move the Stage 2 date soonest — then by position in the standard. A blocker below Operating is always listed. The grey Row column is the item's position in the Results by Requirement table. Put every item in the ISMS Gap & Remediation Tracker with its agreed date.
Limitations
This is a self-assessment: it is as accurate as the scores and the weeks of work entered. Evidence notes, and a second person checking the scores of the blockers, are the best defence against optimism.
The estimate assumes each owner works on one item at a time, in the order shown, from the as-at date, and that the dates you entered for the internal audit and management review hold. It does not include the certification body's lead time: book the Stage 1 and Stage 2 dates early.
A certification body decides on the evidence it samples. Every requirement at Operating makes a pass likely, not certain; a requirement at In place may still pass if it has enough records, and may not.
It does not judge whether your controls are the right ones for your risks (IS-03): that is the risk assessment and the Statement of Applicability.
Lists
| AnswerMode | ReadinessScore | LevelName | YesNo | Blockers |
|---|---|---|---|---|
| Example organisation | 0 | Not started | Yes | 4.3 |
| My answers | 1 | Planned | No | 5.2 |
| 2 | In place | 6.1.2 | ||
| 3 | Operating | 6.1.3 |
6.2
9.2.2
9.3.3
10.2
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Requirement | A clause requirement (the 30 subclauses of clauses 4 to 10 that carry requirements) or an Annex A control. Shown by number and title only: read the standard for what each requires. |
| 0 — Not started | Nothing exists yet. |
| 1 — Planned | Owner and approach agreed; not yet in place. |
| 2 — In place | Documented and working, but little or no record yet. |
| 3 — Operating | Working, with records covering at least [[3]] months, and an auditor could sample it. |
| Blocker | One of the 8 clause requirements without which a Stage 2 audit cannot pass. All must be at Operating before the Stage 2 date. |
| Owner queue | The items below In place that one owner must put in place, taken one after another: blockers first, then in the standard's order. |
| Forecast In place | The date an item is expected to reach In place: its In place date if already there, otherwise the as-at date plus the weeks of the owner's queue up to and including it. |
| Float | How many weeks an item could slip before the estimated Stage 2 date moves. Zero means it decides the date. |
| Critical path | The items with float at or below the Settings value: the ones to protect. |
| Stage 1 and Stage 2 audits | The two parts of a certification audit: Stage 1 reviews the ISMS design and documents and readiness; Stage 2 tests whether it operates as designed. |
| Statement of Applicability (SoA) | The document that lists every Annex A control, whether it is applied and why (clause 6.1.3): see the Statement of Applicability Template. |
| EXAMPLE | Values for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Replace them with your own. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.2 — Internal audit | Whole workbook: a readiness check before, not instead of, the internal audit (IS-06) |
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | Results by Requirement and Summary & Estimate: readiness measured and evaluated monthly (IS-10) |
| ISO/IEC 27001:2022 | Clause 10.1 — Continual improvement | Blocking items: where improvement is needed first |
| NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Summary & Estimate: improvements identified from the assessment |
| NIST CSF 2.0 | GV.OV-01 — “Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction” | Verdict and headline measures: outcomes reviewed to adjust the plan |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0