Free · No signup
How ready are you for ISO 27001?
Certification has a reputation for being enormous, expensive and out of reach. In practice it's a sequence of ordinary steps, and most organisations are further along than they think. This self-assessment walks you through the six areas an auditor actually looks at, teaches a little as you go, and gives you an honest starting point — not a verdict.
There are no wrong answers here and nothing to fail. Wherever you land, you'll leave with one clear next move.
Your answers stay in your browser. Nothing is sent to us unless you ask for a summary by email at the end.
What the assessment covers
Twenty-four questions, four in each of the six domains an ISO 27001auditor works through. Every question uses the same four-point maturity scale, from “not started” to “embedded”, and each one is followed by a short note on what auditors actually look for.
Leadership & Governance
Everything else hangs off leadership commitment — a defined scope, named owners and a policy people can actually find.
Risk Management
The engine room of the standard: a living risk register, a consistent method, tracked treatments and a Statement of Applicability.
People & Awareness
Screening, joiners and leavers, regular awareness and an acknowledged acceptable use policy — the human side auditors probe hardest.
Technology Controls
Unique accounts and MFA, a patching rhythm you can evidence, backups you have actually restored, and logs someone would notice.
Suppliers & Third Parties
Knowing who holds your information, what they commit to, how you assess them before adopting, and reviewing it periodically.
Incidents & Continuity
A one-page plan that answers who is in charge, an exercise that found gaps, your breach obligations, and continuity for critical systems.
The assessment runs entirely in your browser. Your answers are never sent to us or stored on a server — the only thing that ever leaves your device is the summary, and only if you choose to email it to yourself.
This tool is an educational self-assessment, not a certification audit or a compliance guarantee. CHAIOS does not provide licensed framework content — you'll need to purchase your own copy of the standard from the relevant standards body.
Keep reading
More practitioner guides in CHAIOS Insights.