ISO27K

ISO 27001 readiness: what it means

Readiness is not a phase you buy. It is a state you are either in or not, and there are about eight tests for it that an auditor will apply on the first morning of stage 2.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

You are ready for ISO 27001 certification when your management system has been running long enough to have produced records, not when the documents are finished. That single distinction is what separates companies that pass stage 2 from companies that pass stage 1 and then spend four months closing findings. Auditors do not read your policies to decide whether you are ready. They ask for the last three access reviews and see whether they exist.

The word readiness gets used for two different things, and confusing them is expensive. It means the state of being ready to be audited, and it is also the name vendors give to the consulting work that gets you there. This page covers the first: what ready looks like, how to test for it honestly, and what to do about the gaps.

The eight things an auditor checks first

Stage 1 exists precisely to answer the readiness question, and a good auditor decides it in the first two hours from a short list. If any of the following is missing, the stage 2 date moves regardless of how complete your policy set is.

Readiness checkpoints and the clause behind each
What must existWhere it comes fromCommon failure
A written scope statementClause 4.3Scope described by department rather than by systems, locations and services
A risk assessment with named risk ownersClause 6.1.2A generic risk register bought as a template, with no owner and no date
A risk treatment plan tied to that assessmentClause 6.1.3Treatments listed but never linked back to a specific risk
A Statement of Applicability covering all 93 Annex A controlsClause 6.1.3 d)Exclusions with no justification, or controls marked applicable that nobody operates
Security objectives with owners and measuresClause 6.2Aspirations rather than something you can report a number against
A completed internal audit of the whole management systemClause 9.2Done by the person who built the system, which is not independent
A management review meeting with minutesClause 9.3Held, but missing the required inputs such as audit results and risk changes
Records from the controls actually runningClause 8 and Annex AThe system went live three weeks ago, so there is nothing to sample

The last row is the one that moves dates. Everything above it can be written in a fortnight by someone who knows what they are doing. Operating records cannot be, because they take calendar time to accumulate. Three months of a running management system is the practical floor, and most auditors want to see one full cycle of the periodic activities: an access review, a supplier review, a backup restore test, an incident logged and closed even if it was minor.

The one thing that cannot be accelerated

You can buy your way past a documentation gap. You cannot buy your way past a records gap, because backdating evidence is fraud and auditors are good at spotting it. If a customer deadline is three months away and your controls went live last week, the honest options are to move the certification date or to give the customer a letter from the certification body confirming the engagement is under way. Both are better than a failed stage 2, which is visible to everyone you then have to explain it to.

Testing your own readiness before you pay anyone

Before commissioning a readiness assessment, run the cheap version. Pick five Annex A controls you believe are operating and ask the person responsible for each to produce, within the hour, the evidence that it ran in the last quarter. Not the policy. The record. If four of the five come back, you are close. If two do, you have a control implementation problem rather than a documentation problem, and buying policy templates will not touch it.

The Annex A self-assessment walks the same logic across the control themes and scores where you sit, and the gap assessment page covers the paid version and what a good findings report contains.

What readiness support costs in Canada

All figures are Canadian dollars. Readiness support is priced on how much of the work the firm does rather than on your headcount, which is why quotes for the same company vary by a factor of three.

Readiness support, Canadian market, CAD
What you buyRange (CAD)Typical duration
Readiness assessment against the checkpoints above$8,000 to $20,0002 to 4 weeks
Documentation set built to your operation$12,000 to $30,0004 to 8 weeks
Guided implementation to stage 2$25,000 to $50,0004 to 8 months
Full implementation, consultant led$45,000 to $90,0006 to 10 months
Pre-audit or mock stage 2$5,000 to $12,0002 to 4 days

The pre-audit is the most underrated line in that table. Two days of someone who audits for a living walking your evidence the way an auditor will, six weeks before stage 2, costs less than a tenth of the project and routinely finds the two things that would have become major nonconformities. Buy it if you are certifying for the first time.

When you do not need readiness support

Not every company should buy this. Skip it if you already hold SOC 2 Type 2 and have been operating those controls for a year, because the evidence discipline is the hard part and you have it already: what you need is the management system layer on top, which is a smaller and more specific piece of work. Skip it if you have someone internal who has taken an organization through certification before and has the time. Skip it if nobody has asked you for the certificate yet, because a management system with no external driver tends not to survive contact with a busy quarter.

Buy it if a signed deal is holding on a date, if nobody internally has read the standard, or if your last attempt stalled. Those are the three situations where outside help is cheaper than the delay it prevents.

A sequence that works

Roughly nine to fifteen months from a standing start, and the ordering matters more than the speed. Scope first, because everything downstream is priced off it. Then the risk assessment, because the Statement of Applicability is derived from it and writing the two the other way round produces a control set nobody can justify. Then implementation and the run-in period. Internal audit and management review before you book stage 2, not after.

The full version of that sequence, with what happens in each phase and who needs to be in the room, is on the implementation page. If you are still deciding whether ISO 27001 is the right standard at all, the comparison with SOC 2 is the place to start, and a North American buyer asking for a report rather than a certificate almost always means SOC 2.

Get a readiness assessment quoted

Tell us your scope, headcount and whether anything is running yet, and we will match you with Canadian firms that do readiness work.

Get matched

Common questions

How do I know if we are ready for a stage 2 audit?

Ask whether your controls have produced records over a period an auditor can sample, typically at least three months, and whether an independent internal audit and a management review have both happened with minutes. If the answer to either is no, you are not ready, and no amount of documentation changes that. The eight checkpoints on this page are the list a stage 1 auditor works through.

What is the difference between readiness and a gap assessment?

A gap assessment measures the distance between where you are and what the standard requires, and produces a findings report. Readiness is the state of being fit for audit, which is what you reach at the end of closing those gaps and running the system for a while. In practice firms sell both under either name, so ask what the deliverable is rather than what it is called.

How long does readiness take for a company with nothing in place?

Nine to fifteen months to a certificate for most Canadian companies starting from no management system. The documentation is not the constraint. The constraint is running the controls long enough to have evidence, plus the internal audit and management review that have to sit before stage 2.

Can a compliance platform make us ready on its own?

No. Platforms collect evidence and monitor technical controls well, and they do not write your scope, run your risk assessment, hold your management review or make decisions about applicability. Those are judgement calls a person has to make and defend to an auditor. A platform below roughly thirty people with one cloud environment is often not worth the subscription in year one.