🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
ISO 27001NIS2CR-ISO-01

ISO 27001 Readiness Assessment

Full ISO 27001:2022 gap assessment: all clauses + 93 Annex A controls evaluated. Traffic-light maturity, gap analysis, certification roadmap with timeline. €539.

ISO 27001 Readiness Assessment by Optimum Web is a fixed-price compliance service covering ISO 27001 — Full standard assessment (Clauses 4-10 + Annex A). It costs €539 with 7–10 business days delivery by senior security engineers. Gap assessment against ISO 27001:2022 (Clauses 4-10 + 93 Annex A controls). 14-day warranty included.

Covers: ISO 27001 — Full standard assessment (Clauses 4-10 + Annex A)

4 clients served this month
4.8·172 projects·27 yrs

"Senior engineers who actually deliver what they promise. Rare."

Thomas K., IT Manager · Austria

€539
Fixed price, VAT excluded
7–10 business daysSenior only
Gap assessment against ISO 27001:2022 (Clauses 4-10 + 93 Annex A controls)
Traffic-light maturity assessment (red/amber/green per control)
Prioritized roadmap to certification with effort estimates
Executive summary with estimated timeline and budget for certification
🛡️
14-Day Money-Back Guarantee
Issue recurs? We fix it free or refund in full. No questions asked.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-ISO-01

This Service Covers

ISO 27001Clauses 4-10 and Annex A — Full standard assessment
NIS2Article 21 — Cybersecurity risk-management measures

What You Get

Comprehensive gap assessment against the full ISO 27001:2022 standard. We evaluate your current security posture against all requirements: Clauses 4-10 (context, leadership, planning, support, operation, evaluation, improvement) and all 93 Annex A controls grouped into 4 categories (organizational, people, physical, technological). Result: traffic-light maturity assessment, compliance gap analysis, prioritized roadmap to certification, and estimated effort and timeline.

Who Needs This

  • Companies considering ISO 27001 certification but unsure of their readiness
  • Organizations whose clients or partners require ISO 27001 proof
  • Businesses wanting to understand the gap between current state and certification
  • Companies that need a certification roadmap and budget for management approval

Who Buys This Service?

You should choose this service if…

  • Your enterprise customer requires ISO 27001 certification before awarding a contract
  • You're in regulated financial services and need a framework for your ISMS
  • Your Series-A investors asked about information security certifications
  • You've been told you failed a vendor security review due to lack of ISO 27001
  • You want to begin the ISO 27001:2022 certification journey but don't know where to start
  • You're preparing for a SOC 2 audit and ISO 27001 alignment makes sense

Common triggering events

Enterprise contract requirement

Large enterprise customers increasingly list ISO 27001 certification (or at minimum evidence of ISO 27001 alignment) in their vendor selection criteria.

Cyber insurance application

ISO 27001 alignment reduces cyber insurance premiums by 15–35% with most major underwriters. Our readiness assessment is the first step.

Expansion into EU regulated sector

Financial services, healthcare, and government supply chains in the EU increasingly require ISO 27001. NIS2 Article 21 is satisfied by ISO 27001:2022 alignment.

Internal security maturity programme

CTOs and CISOs use the gap analysis to benchmark current state and build a realistic roadmap to certification.

What buyers typically search for

Buyers who choose our ISO 27001 Readiness Assessment (€539) often first search: "ISO 27001 preparation" (1,900/mo), "ISO 27001 gap analysis" (1,300/mo), "ISO 27001 readiness assessment" (590/mo), "how to get ISO 27001 certified" (880/mo), "ISO 27001 cost small business" (480/mo).

Our readiness assessment covers all 93 controls of ISO 27001:2022 Annex A and the 10 management clauses. We produce a gap analysis report with a prioritised remediation roadmap, estimated effort for each control, and a realistic timeline to Stage 1 and Stage 2 audit.

We assess against ISO 27001:2022 (not the 2013 version). All companies should now be moving to the 2022 version as the 2013 standard was withdrawn in October 2025.

How this compares to alternatives

ApproachCostDepth / Timeline
Optimum ISO 27001 Readiness Assessment€539Full 93-control gap analysis, 5–7 days
DIY self-assessment checklistFreeSuperficial; misses contextual interpretation
ISMS.online / Vanta platform£500–2,000/monthOngoing tool; still needs expert review
Big-4 ISO 27001 pre-assessment£8,000–25,000Comprehensive, 4–6 weeks
Accredited certification body gap assessment£3,000–8,000Official, used to book Stage 1

Frequently asked questions

How long does it take to get ISO 27001 certified after the assessment?

Typically 3–6 months for a mid-size company, depending on gap size. The assessment gives you a realistic timeline based on your specific situation.

Do you perform the actual certification audit?

No. Certification audits must be performed by an accredited certification body (TÜV, BSI, Bureau Veritas). We prepare you for the audit and ensure you'll pass.

Is this against ISO 27001:2022 or 2013?

We assess against ISO 27001:2022 (93 controls, 4 Annex A categories). The 2013 standard was formally withdrawn in October 2025; all certifications must now be against the 2022 version.

Can this also satisfy NIS2 Article 21?

Yes. ISO 27001:2022 alignment satisfies most NIS2 Article 21 risk management requirements. We include a NIS2 mapping section in the assessment.

We're not ready for certification yet — is the assessment still useful?

That's exactly what it's for. The roadmap prioritises quick wins and critical gaps so you can make steady progress. Most companies aren't ready on first assessment.

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup (€449) to incident response (€359). No surprises.

Browse Fix Services

Ready to Start?

€539 · 7–10 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Ready to implement? Browse individual fix services

Learn more
CLIENT REVIEWS

What Our Clients Say

4.8 / 5·172 projects · 27+ years

"Senior engineers who actually deliver what they promise. Fixed price, fixed timeline, thorough documentation. Rare combination."

T
Thomas K.
IT Manager · Manufacturing company · Austria

"Worked with 4 agencies before finding Optimum Web. First team that delivered exactly what the scope said, on time."

S
Sophie V.
Operations Manager · Logistics company · Belgium

"The 14-day warranty is real. Had a small follow-up question and it was handled same day, no extra charge."

M
Mikael B.
CTO · B2B SaaS · Germany
Read all reviews on Clutch →

Frequently Asked Questions

How much does ISO 27001 certification cost?+
The certification audit itself costs £3,000–15,000 depending on the certification body (TÜV, BSI, Bureau Veritas) and your company size. Our readiness assessment (€539) + remediation services typically run €3k–12k depending on gap size. Total budget for certification: €6k–30k. Our assessment gives you a realistic estimate for your specific situation.
How long does ISO 27001 certification take?+
Typically 3–6 months after our readiness assessment for a mid-size company with existing security practices. Companies starting from scratch: 6–12 months. The assessment provides a realistic timeline based on your gap size.
What are ISO 27001:2022 Annex A controls?+
ISO 27001:2022 has 93 controls in 4 categories: organizational (37 controls — policies, roles, threat intelligence, cloud security), people (8 controls — screening, training, disciplinary process), physical (14 controls — physical security), and technological (34 controls — endpoint protection, encryption, logging, vulnerability management, network security). 11 new controls were added in 2022 including threat intelligence, web filtering, data masking, and configuration management.
How to prepare for ISO 27001 Stage 1 audit?+
Stage 1 checks that your ISMS documentation exists and is suitable. You need: ISMS scope document, information security policy, risk assessment methodology, Statement of Applicability (SoA), treatment plan, and internal audit evidence. Our readiness assessment identifies exactly what's missing and our ISMS Policy Pack (€449) provides the key documents.
Which certification body should I choose?+
For UK clients: BSI, LRQA, or Bureau Veritas. For EU clients: TÜV SÜD, TÜV Rheinland, or DNV. For cost-conscious companies: LRQA and Bureau Veritas tend to be more competitively priced. Choose a body accredited by UKAS (UK) or DAkkS (Germany). We're vendor-neutral and can recommend based on your sector and geography.
Do I need penetration testing for ISO 27001?+
ISO 27001:2022 Annex A.8.29 requires 'security testing in development and acceptance'. Most auditors interpret this as requiring penetration testing or at minimum vulnerability assessment. Our Focused Pentest (€1,800) or VA (€539) produces an Attestation Letter specifically referencing ISO 27001 A.8.8 and A.8.29.
What's the difference between ISO 27001:2013 and ISO 27001:2022?+
The 2022 version reorganized Annex A from 114 controls in 14 domains to 93 controls in 4 categories (organizational, people, physical, technological). 11 new controls added: threat intelligence, cloud security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. The 2013 standard was formally withdrawn in October 2025; all certifications must now be against 2022.
Can we do ISO 27001 without a consultant?+
Yes, but it's slow and risky. The main challenges are interpreting Annex A controls for your specific context, writing an acceptable Statement of Applicability, and understanding what auditors actually look for. Our readiness assessment gives you the gap analysis; you can do the remediation yourselves using our deliverables as templates. We can also execute specific remediation tasks for you (€319–€639 per service).
How to combine ISO 27001 and SOC 2?+
ISO 27001 and SOC 2 share significant control overlap. Companies pursuing both typically do ISO 27001 readiness first (our €539 assessment maps both), implement shared controls once, then run SOC 2 Type I observation period during ISO 27001 stage audits. Our Multi-Framework Assessment (€639) covers both simultaneously.
What's included in the €539 readiness assessment?+
You get: gap assessment against all 93 ISO 27001:2022 Annex A controls and clauses 4–10, traffic-light maturity chart (red/amber/green per control), prioritized remediation roadmap with effort estimates, executive summary with certification timeline and budget, and NIS2 Article 21 mapping. Delivered in 7–10 business days.

Secured by PayPal · 256-bit SSL encryption

or order without payment