Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
Advisory·ISO/IEC 27001
🔐Beta

ISO/IEC 27001 Readiness

Six-step path from the ISMS management-system requirements and Statement of Applicability through to an evidence-backed readiness package. Deterministic scoring, local analysis — no AI required for the free tiers.

Free to start
Before you start — what to have ready for ISO 27001

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

Every control in this framework is assessed, so there is no scope step to complete first. Have these decided before you begin so your answers describe one consistent thing.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What ISO 27001 is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Information Security Policy (approved and dated)
  • Statement of Applicability (SoA)
  • Risk assessment and risk treatment plan
  • Access control policy and a recent user access review
  • Asset inventory
  • Incident response and business continuity procedures
  • Supplier / third-party security agreements
  • Internal audit report and management review minutes

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Access reviews and asset inventories often list employee names, emails and system credentials. Mask staff personal contact details and any live secrets (passwords, API keys) before uploading.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). It defines 93 Annex A controls across four themes — Organisational, People, Physical, and Technological — and is among the certifications most often requested of SaaS companies, cloud vendors, fintech, and enterprise suppliers.

Certification requires an independent audit. This platform gives you a structured readiness assessment, gap register, and evidence library to prepare for that audit — without an expensive consulting retainer.

What you get
  • Maturity level across all 4 Annex A themes
  • Control-by-control status (Ready / Partial / Gap)
  • Evidence quality scoring per control
  • Full gap register with severity classification
  • Prioritised remediation roadmap
  • Evidence map (what you have vs what's missing)
  • Print-to-PDF at every step

The Discovery path

1
ISMS Requirements (Clauses 4–10)25 minFree

27 management-system requirements — scope, policy, risk assessment and treatment, Statement of Applicability, internal audit, management review. Flags the gaps that typically raise a major nonconformity.

2
Statement of Applicability60 minFree

All 93 Annex A controls, each included or excluded with a justification, inclusion source, implementation status and risk reference. Flags the 11 controls new in the 2022 revision.

3
Risk Register and Treatment30 minFree

Risk owners, inherent and residual risk, treatment decisions, acceptance and control references for Clauses 6.1.2–6.1.3.

4
Snapshot Assessment5 minFree

12 questions across the 4 ISO 27001 Annex A themes. Instant maturity score and top 3 risks. No sign-in, no data stored.

5
Full Readiness Report30 minFree

36 questions, domain scores, complete gap register, control matrix, and a prioritised remediation roadmap.

6
Evidence-Based Self-Assessment20 minFree

20 questions asking for evidence references across network, infrastructure, change management, and access. Answers without evidence are capped.

7
Evidence LibraryOngoingFrom ₹4,999 / $49

Upload PDFs, screenshots, exports, and logs against each control. The platform reads content and returns a structured, auditor-style verdict — fully local, no AI required.