ISO 27001 readiness: what it means
Readiness is not a phase you buy. It is a state you are either in or not, and there are about eight tests for it that an auditor will apply on the first morning of stage 2.
You are ready for ISO 27001 certification when your management system has been running long enough to have produced records, not when the documents are finished. That single distinction is what separates companies that pass stage 2 from companies that pass stage 1 and then spend four months closing findings. Auditors do not read your policies to decide whether you are ready. They ask for the last three access reviews and see whether they exist.
The word readiness gets used for two different things, and confusing them is expensive. It means the state of being ready to be audited, and it is also the name vendors give to the consulting work that gets you there. This page covers the first: what ready looks like, how to test for it honestly, and what to do about the gaps.
The eight things an auditor checks first
Stage 1 exists precisely to answer the readiness question, and a good auditor decides it in the first two hours from a short list. If any of the following is missing, the stage 2 date moves regardless of how complete your policy set is.
| What must exist | Where it comes from | Common failure |
|---|---|---|
| A written scope statement | Clause 4.3 | Scope described by department rather than by systems, locations and services |
| A risk assessment with named risk owners | Clause 6.1.2 | A generic risk register bought as a template, with no owner and no date |
| A risk treatment plan tied to that assessment | Clause 6.1.3 | Treatments listed but never linked back to a specific risk |
| A Statement of Applicability covering all 93 Annex A controls | Clause 6.1.3 d) | Exclusions with no justification, or controls marked applicable that nobody operates |
| Security objectives with owners and measures | Clause 6.2 | Aspirations rather than something you can report a number against |
| A completed internal audit of the whole management system | Clause 9.2 | Done by the person who built the system, which is not independent |
| A management review meeting with minutes | Clause 9.3 | Held, but missing the required inputs such as audit results and risk changes |
| Records from the controls actually running | Clause 8 and Annex A | The system went live three weeks ago, so there is nothing to sample |
The last row is the one that moves dates. Everything above it can be written in a fortnight by someone who knows what they are doing. Operating records cannot be, because they take calendar time to accumulate. Three months of a running management system is the practical floor, and most auditors want to see one full cycle of the periodic activities: an access review, a supplier review, a backup restore test, an incident logged and closed even if it was minor.
The one thing that cannot be accelerated
You can buy your way past a documentation gap. You cannot buy your way past a records gap, because backdating evidence is fraud and auditors are good at spotting it. If a customer deadline is three months away and your controls went live last week, the honest options are to move the certification date or to give the customer a letter from the certification body confirming the engagement is under way. Both are better than a failed stage 2, which is visible to everyone you then have to explain it to.
Testing your own readiness before you pay anyone
Before commissioning a readiness assessment, run the cheap version. Pick five Annex A controls you believe are operating and ask the person responsible for each to produce, within the hour, the evidence that it ran in the last quarter. Not the policy. The record. If four of the five come back, you are close. If two do, you have a control implementation problem rather than a documentation problem, and buying policy templates will not touch it.
The Annex A self-assessment walks the same logic across the control themes and scores where you sit, and the gap assessment page covers the paid version and what a good findings report contains.
What readiness support costs in Canada
All figures are Canadian dollars. Readiness support is priced on how much of the work the firm does rather than on your headcount, which is why quotes for the same company vary by a factor of three.
| What you buy | Range (CAD) | Typical duration |
|---|---|---|
| Readiness assessment against the checkpoints above | $8,000 to $20,000 | 2 to 4 weeks |
| Documentation set built to your operation | $12,000 to $30,000 | 4 to 8 weeks |
| Guided implementation to stage 2 | $25,000 to $50,000 | 4 to 8 months |
| Full implementation, consultant led | $45,000 to $90,000 | 6 to 10 months |
| Pre-audit or mock stage 2 | $5,000 to $12,000 | 2 to 4 days |
The pre-audit is the most underrated line in that table. Two days of someone who audits for a living walking your evidence the way an auditor will, six weeks before stage 2, costs less than a tenth of the project and routinely finds the two things that would have become major nonconformities. Buy it if you are certifying for the first time.
When you do not need readiness support
Not every company should buy this. Skip it if you already hold SOC 2 Type 2 and have been operating those controls for a year, because the evidence discipline is the hard part and you have it already: what you need is the management system layer on top, which is a smaller and more specific piece of work. Skip it if you have someone internal who has taken an organization through certification before and has the time. Skip it if nobody has asked you for the certificate yet, because a management system with no external driver tends not to survive contact with a busy quarter.
Buy it if a signed deal is holding on a date, if nobody internally has read the standard, or if your last attempt stalled. Those are the three situations where outside help is cheaper than the delay it prevents.
A sequence that works
Roughly nine to fifteen months from a standing start, and the ordering matters more than the speed. Scope first, because everything downstream is priced off it. Then the risk assessment, because the Statement of Applicability is derived from it and writing the two the other way round produces a control set nobody can justify. Then implementation and the run-in period. Internal audit and management review before you book stage 2, not after.
The full version of that sequence, with what happens in each phase and who needs to be in the room, is on the implementation page. If you are still deciding whether ISO 27001 is the right standard at all, the comparison with SOC 2 is the place to start, and a North American buyer asking for a report rather than a certificate almost always means SOC 2.
Get a readiness assessment quoted
Tell us your scope, headcount and whether anything is running yet, and we will match you with Canadian firms that do readiness work.
Get matchedCommon questions
How do I know if we are ready for a stage 2 audit?
Ask whether your controls have produced records over a period an auditor can sample, typically at least three months, and whether an independent internal audit and a management review have both happened with minutes. If the answer to either is no, you are not ready, and no amount of documentation changes that. The eight checkpoints on this page are the list a stage 1 auditor works through.
What is the difference between readiness and a gap assessment?
A gap assessment measures the distance between where you are and what the standard requires, and produces a findings report. Readiness is the state of being fit for audit, which is what you reach at the end of closing those gaps and running the system for a while. In practice firms sell both under either name, so ask what the deliverable is rather than what it is called.
How long does readiness take for a company with nothing in place?
Nine to fifteen months to a certificate for most Canadian companies starting from no management system. The documentation is not the constraint. The constraint is running the controls long enough to have evidence, plus the internal audit and management review that have to sit before stage 2.
Can a compliance platform make us ready on its own?
No. Platforms collect evidence and monitor technical controls well, and they do not write your scope, run your risk assessment, hold your management review or make decisions about applicability. Those are judgement calls a person has to make and defend to an auditor. A platform below roughly thirty people with one cloud environment is often not worth the subscription in year one.