Aerospace & DefenseFree Interactive Tool

ISO 27001 Readiness Checklist: Are You Ready for Stage 1?

This free ISO 27001 readiness checklist walks through the six areas an auditor and certification body actually evaluate: ISMS foundations, risk treatment, Annex A control implementation, documentation, internal audit, and certification body engagement. It is built for IT directors, CISOs, and quality managers at manufacturers and defense contractors preparing for ISO 27001 certification, often driven by customer contractual requirements or as a complement to CMMC compliance work. Work through each group, flag critical items honestly, and use the result to scope a realistic timeline before engaging a certification body.

0%

0 of 32 items complete

12 critical items still open - these are the highest-risk gaps.

ISMS Foundations

Risk Assessment and Treatment

Annex A Controls Implementation

Documentation and Evidence

Internal Audit and Management Review

Certification Body Engagement

Score one point per checked item and divide by total items for a percentage. Below 60 percent overall, or any unresolved critical item, means you are not ready to engage a certification body; expect a 3 to 6 month closure sprint focused on critical items before scheduling a Stage 1 audit.

Get your ISO 27001 gap analysis

We will email you a detailed gap report against your checklist responses, mapped to a realistic certification timeline, and a Netray compliance specialist will follow up with a 30-minute review.

No spam. Your results stay private. Unsubscribe anytime.

Why ISO 27001 matters beyond the certificate

ISO 27001 certification is increasingly a contractual requirement from enterprise customers and prime contractors, not just a voluntary best practice. For manufacturers serving aerospace, defense, and regulated industries, ISO 27001 frequently sits alongside CMMC and customer-specific security questionnaires as a baseline expectation before a contract is even discussed. Beyond the certificate itself, the risk assessment and Annex A control work required to achieve it materially reduces real operational risk if implemented substantively rather than as a documentation exercise.

  • ISO 27001 certification is increasingly a prerequisite in enterprise vendor security questionnaires.
  • The 2022 revision restructured Annex A into 93 controls across 4 themes; confirm your SoA maps to the current version.
  • Certification typically takes 6 to 12 months from a standing start to Stage 2 audit for a mid-size organization.

The most common Stage 1 findings

Stage 1 audits (documentation review) most commonly flag an incomplete or inconsistent Statement of Applicability, a risk treatment plan that does not map cleanly to implemented controls, and insufficient operational evidence for controls that were only recently implemented. Auditors want to see that controls have been operating long enough to generate real evidence, typically a minimum of three months, not just that a policy document exists.

  • An SoA that excludes controls without documented justification is a near-universal Stage 1 finding.
  • Controls implemented less than 3 months before Stage 2 rarely have enough evidence to pass sampling.
  • Risk treatment plans without assigned owners and deadlines are treated as incomplete, not just weak.

Budgeting realistically for certification

Certification body audit fees for a mid-size organization typically run $15,000 to $40,000 across Stage 1 and Stage 2 combined, plus annual surveillance audit fees of $8,000 to $20,000. The larger cost is internal: gap remediation, policy development, and the operational time to actually run controls for long enough to generate audit evidence, which is why most organizations underestimate total first-year cost by 2 to 3x if they only budget for the audit fee itself.

How Netray supports ISO 27001 readiness

Netray helps aerospace, defense, and manufacturing clients build ISMS documentation, risk treatment plans, and Annex A control implementations that satisfy both ISO 27001 and overlapping CMMC requirements in a single coordinated effort, avoiding duplicate work across two compliance programs.

Frequently Asked Questions

How long does ISO 27001 certification take?

For an organization starting with no formal ISMS, a realistic timeline is 6 to 12 months from initial gap analysis to Stage 2 certification audit, including at least 3 months of operating history for implemented controls before Stage 2 can be scheduled. Organizations with existing security programs and documentation can sometimes compress this to 4 to 6 months.

How much does ISO 27001 certification cost?

Certification body audit fees for a mid-size organization (roughly 100 to 500 employees) typically run $15,000 to $40,000 for combined Stage 1 and Stage 2 audits, plus $8,000 to $20,000 annually for surveillance audits across the 3-year certification cycle. Internal remediation cost (consulting, tooling, staff time) is usually the larger expense and varies significantly based on starting security maturity.

What is the difference between Stage 1 and Stage 2 ISO 27001 audits?

Stage 1 is a documentation review confirming your ISMS scope, policy, Statement of Applicability, and risk treatment plan are complete and internally consistent. Stage 2 is an operational audit where the certification body samples actual evidence that controls are operating as documented, interviews staff, and reviews records like access reviews and incident tickets. Both must pass before certification is granted.

What is a Statement of Applicability?

The Statement of Applicability (SoA) is a mandatory ISO 27001 document listing all Annex A controls, whether each is implemented or excluded, and the justification for any exclusion. It is the single document auditors reference most heavily during both Stage 1 and Stage 2, and an incomplete or poorly justified SoA is the most common reason organizations fail or delay a Stage 1 audit.

Can ISO 27001 and CMMC compliance work overlap?

Yes, substantially. Both frameworks require formal risk assessment, access control, encryption, incident response, and continuous monitoring, though CMMC (built on NIST SP 800-171) has more prescriptive technical requirements for defense contractors handling controlled unclassified information. Organizations pursuing both should map controls once against a combined control set to avoid duplicating documentation and evidence-gathering effort.

Get a gap analysis against your completed checklist and a realistic path to Stage 1 audit.