🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
ISO 27001CR-ISO-10

Internal Audit Dry Run

A full rehearsal of your ISO 27001 Clause 9.2 internal audit, without the audit status. We test every applicable Annex A control against your evidence the way an auditor would, and tell you what would have been raised. Non-certifying.

Quick Answer

Internal Audit Dry Run by Optimum Web is a fixed-price compliance service that tests an organisation's ISMS evidence against ISO 27001:2022 requirements before its Clause 9.2 internal audit. It costs €539 with 10 business days delivery by senior security engineers. The dry run is not an audit and does not satisfy Clause 9.2 on its own. 14-day warranty included.

Internal Audit Dry Run by Optimum Web is a fixed-price compliance service covering ISO 27001 Clauses 4–10 and Annex A — evidence verification ahead of the internal audit. It costs €539 with 10 business days delivery by senior security engineers. Coverage matrix — Clauses 4–10 and every Annex A control applicable under your SoA, each marked evidenced / partial / missing. 14-day warranty included.

Covers: ISO 27001 Clauses 4–10 and Annex A — evidence verification ahead of the internal audit

€539
Fixed price, VAT excluded
10 business daysSenior only
Coverage matrix — Clauses 4–10 and every Annex A control applicable under your SoA, each marked evidenced / partial / missing
Evidence test results — what we asked for, what was produced, and whether it would stand up
Control walkthrough notes — access reviews, joiner/mover/leaver, MFA, backup and restore testing, logging, change management, supplier management
Findings list — each gap classified by the severity it would carry if raised in a real audit, with the clause or control reference
Corrective action plan — recommendation, priority, effort estimate and suggested owner for each finding
Debrief call with the person who will run your Clause 9.2 audit
🛡️
14-Day Money-Back Guarantee
Issue recurs? We fix it free or refund in full. No questions asked.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-ISO-10

This Service Covers

ISO 27001Clauses 4–10 and Annex A — evidence verification ahead of the internal audit

What You Get

A rehearsal of the audit before the audit. We work through your Statement of Applicability control by control and your ISMS clause by clause, request the same evidence a competent auditor would request, review what comes back, and walk through the controls that cannot be judged from documents alone. You receive a coverage matrix showing exactly where you stand, a findings list written in the language an auditor would use, and a prioritised plan to close each gap. This is deliberately not an audit. It carries no audit status, produces no audit opinion, and does not satisfy ISO 27001 Clause 9.2 on its own — that audit must be conducted by someone independent within your organisation or an auditor you appoint. What the dry run does is make sure that when they do it, there are no surprises.

Optimum Web provides audit preparation, documentation and technical verification. We are not a certification body, we do not employ auditors, and we do not perform internal or certification audits. The Clause 9.2 internal audit is conducted by a person independent of the area audited within your organisation, or by an auditor you appoint; the certification audit is conducted by an accredited certification body. Our role is to make sure you are ready for both.

Who Needs This

  • Companies whose Clause 9.2 audit or certification audit is 4–8 weeks away
  • Certified companies preparing for a surveillance audit who want an outside read on their evidence
  • Organisations whose internal auditor is independent but inexperienced, and who want the ground tested first
  • Teams that have built an ISMS quickly and are not confident the evidence matches the documentation

ONGOING COMPLIANCE

Don't Want to Think About Compliance Every Quarter?

Compliance-as-a-Service: €729/month. Quarterly reviews, scans, documentation, and security questionnaire support — as an extension of your team, not a replacement for your compliance owner.

Start CaaS — €729/month

Ready to Start?

€539 · 10 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Want ongoing compliance? Compliance-as-a-Service — €729/month

Learn more

Frequently Asked Questions

Does this count as our Clause 9.2 internal audit?+
No. Clause 9.2 requires an audit conducted by a person independent of the area being audited, appointed by you, whose report goes into your ISMS records. The dry run is preparation for that. We are not auditors and we do not issue audit reports.
Then what is the value if we still have to do the audit?+
The dry run finds the problems while there is still time to fix them, and it does it against the full applicable control set rather than the parts your team thinks to check. Gaps we identify cost nothing to close. The same gaps surfacing for the first time at Stage 2 — where an auditor may raise them as nonconformities — cost a corrective action cycle and a delayed certification.
How is this different from the Preparation Pack (CR-ISO-07)?+
The Preparation Pack produces the documents — programme, plan, checklist, evidence map, templates. The dry run tests reality against them. Most clients order the pack first and the dry run four to six weeks before the audit. Either can be ordered alone.
How is this different from a readiness assessment?+
The readiness assessment (CR-ISO-01) looks at whether your ISMS is broadly on track. The dry run is narrow and evidential: every applicable control, evidence requested and reviewed, findings written as an auditor would write them.
When should we schedule it?+
Four to six weeks before the internal audit or certification audit. That leaves room to close what we find.
Do you fix what you find?+
Not as part of this service. Remediation is available separately — documentation, technical controls implementation, or individual compliance services depending on the gap.
What do you need from us?+
Your Statement of Applicability, ISMS documentation, and access to control owners for short walkthrough sessions. Everything is done remotely.

Secured by PayPal · 256-bit SSL encryption

or order without payment