Optimum Web
ISO 27001NIS2SOC 2DORACR-ISO-04

Risk Assessment & Treatment Plan

Formal ISO 27005 risk assessment with treatment plan and Statement of Applicability. Ready for ISO 27001 Stage 1 audit. Also covers NIS2, SOC 2, DORA. $490.

Risk Assessment & Treatment Plan by Optimum Web is a fixed-price compliance service covering ISO 27001 Clause 6.1.2 — Information security risk assessment. It costs $490 with 5–7 business days delivery by senior security engineers. Risk assessment report (ISO 27005 methodology, 5×5 matrix). 14-day warranty included.

Covers: ISO 27001 Clause 6.1.2 — Information security risk assessment

$490
Fixed price, VAT excluded
5–7 business daysSenior only
Risk assessment report (ISO 27005 methodology, 5×5 matrix)
Risk treatment plan with mitigate/accept/transfer/avoid for each risk
Statement of Applicability (SoA) mapping controls to Annex A
Asset register linking assets to risks and controls

PayPal failed to load. Please refresh or contact us directly.

Email Us to Order
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-ISO-04

This Service Covers

ISO 27001Clause 6.1.2 — Information security risk assessment
NIS2Article 21(2)(a) — Risk analysis
SOC 2CC3.1–3.2 — Risk assessment and risk mitigation
DORAChapter II — ICT risk management

What You Get

ISO 27001-aligned risk assessment following the ISO 27005 methodology. We identify information assets, evaluate threats and vulnerabilities, assess risk levels using a 5×5 likelihood-impact matrix, and produce a formal Risk Treatment Plan with four options for each risk: mitigate, accept, transfer, or avoid. The Statement of Applicability (SoA) maps selected controls to Annex A. Ready for ISO 27001 Stage 1 audit.

How It Works

STEP 01
Asset Identification

Catalogue information assets, classify by confidentiality/integrity/availability

STEP 02
Threat & Vulnerability

Identify threats and vulnerabilities for each asset

STEP 03
Risk Evaluation

Calculate risk scores (5×5 matrix), rank and prioritize

STEP 04
Treatment Plan

Define treatment for each risk, map controls to SoA, deliver report

Who Needs This

  • Companies pursuing ISO 27001 certification (Clause 6.1.2 is mandatory)
  • Organizations that need a formal risk treatment plan for board presentation
  • Businesses preparing for SOC 2 Type II needing CC3.1-3.2 evidence
  • Companies that had an incident and need a structured risk reassessment

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup ($490) to incident response ($390). No surprises.

Browse Fix Services

Ready to Start?

$490 · 5–7 business days · 14-day warranty

PayPal failed to load. Please refresh or contact us directly.

Email Us to Order
+373 22 843569

Ready to implement? Browse individual fix services

Learn more

Frequently Asked Questions

What is the Statement of Applicability (SoA)?+
The SoA is a required ISO 27001 document that lists all 93 Annex A controls and states whether each is applicable to your organization, with justification. It links your risk assessment to the controls you implement.
Can I use this for ISO 27001 Stage 1 audit?+
Yes. The risk assessment and SoA are the two most critical documents for Stage 1. Auditors check that risks are identified, assessed, and linked to controls via the SoA. This service produces both.
How many assets do you typically assess?+
For a mid-size company: 20-50 information assets (servers, databases, SaaS services, network segments, physical locations). For larger scope, we may need additional time.
Do you use qualitative or quantitative risk assessment?+
Qualitative (5×5 matrix). This is what ISO 27001 auditors expect and what most organizations can maintain. Quantitative (financial) is available on request but requires more input data.
How does this relate to the Risk Analysis service (CR-NIS2-03)?+
CR-NIS2-03 focuses on NIS2 requirements and includes the Information Security Policy. This service (CR-ISO-04) is ISO 27001-specific with the SoA. If pursuing both ISO and NIS2, we recommend both — they share 60% of the work.

PayPal failed to load. Please refresh or contact us directly.

Email Us to Order
+373 22 843569