ISO 27001 Readiness Checklist: Are You Ready for Stage 1?
This free ISO 27001 readiness checklist walks through the six areas an auditor and certification body actually evaluate: ISMS foundations, risk treatment, Annex A control implementation, documentation, internal audit, and certification body engagement. It is built for IT directors, CISOs, and quality managers at manufacturers and defense contractors preparing for ISO 27001 certification, often driven by customer contractual requirements or as a complement to CMMC compliance work. Work through each group, flag critical items honestly, and use the result to scope a realistic timeline before engaging a certification body.
0 of 32 items complete
12 critical items still open - these are the highest-risk gaps.
ISMS Foundations
Risk Assessment and Treatment
Annex A Controls Implementation
Documentation and Evidence
Internal Audit and Management Review
Certification Body Engagement
Score one point per checked item and divide by total items for a percentage. Below 60 percent overall, or any unresolved critical item, means you are not ready to engage a certification body; expect a 3 to 6 month closure sprint focused on critical items before scheduling a Stage 1 audit.
Get your ISO 27001 gap analysis
We will email you a detailed gap report against your checklist responses, mapped to a realistic certification timeline, and a Netray compliance specialist will follow up with a 30-minute review.
No spam. Your results stay private. Unsubscribe anytime.
Why ISO 27001 matters beyond the certificate
ISO 27001 certification is increasingly a contractual requirement from enterprise customers and prime contractors, not just a voluntary best practice. For manufacturers serving aerospace, defense, and regulated industries, ISO 27001 frequently sits alongside CMMC and customer-specific security questionnaires as a baseline expectation before a contract is even discussed. Beyond the certificate itself, the risk assessment and Annex A control work required to achieve it materially reduces real operational risk if implemented substantively rather than as a documentation exercise.
- ISO 27001 certification is increasingly a prerequisite in enterprise vendor security questionnaires.
- The 2022 revision restructured Annex A into 93 controls across 4 themes; confirm your SoA maps to the current version.
- Certification typically takes 6 to 12 months from a standing start to Stage 2 audit for a mid-size organization.
The most common Stage 1 findings
Stage 1 audits (documentation review) most commonly flag an incomplete or inconsistent Statement of Applicability, a risk treatment plan that does not map cleanly to implemented controls, and insufficient operational evidence for controls that were only recently implemented. Auditors want to see that controls have been operating long enough to generate real evidence, typically a minimum of three months, not just that a policy document exists.
- An SoA that excludes controls without documented justification is a near-universal Stage 1 finding.
- Controls implemented less than 3 months before Stage 2 rarely have enough evidence to pass sampling.
- Risk treatment plans without assigned owners and deadlines are treated as incomplete, not just weak.
Budgeting realistically for certification
Certification body audit fees for a mid-size organization typically run $15,000 to $40,000 across Stage 1 and Stage 2 combined, plus annual surveillance audit fees of $8,000 to $20,000. The larger cost is internal: gap remediation, policy development, and the operational time to actually run controls for long enough to generate audit evidence, which is why most organizations underestimate total first-year cost by 2 to 3x if they only budget for the audit fee itself.
How Netray supports ISO 27001 readiness
Netray helps aerospace, defense, and manufacturing clients build ISMS documentation, risk treatment plans, and Annex A control implementations that satisfy both ISO 27001 and overlapping CMMC requirements in a single coordinated effort, avoiding duplicate work across two compliance programs.
Frequently Asked Questions
How long does ISO 27001 certification take?
For an organization starting with no formal ISMS, a realistic timeline is 6 to 12 months from initial gap analysis to Stage 2 certification audit, including at least 3 months of operating history for implemented controls before Stage 2 can be scheduled. Organizations with existing security programs and documentation can sometimes compress this to 4 to 6 months.
How much does ISO 27001 certification cost?
Certification body audit fees for a mid-size organization (roughly 100 to 500 employees) typically run $15,000 to $40,000 for combined Stage 1 and Stage 2 audits, plus $8,000 to $20,000 annually for surveillance audits across the 3-year certification cycle. Internal remediation cost (consulting, tooling, staff time) is usually the larger expense and varies significantly based on starting security maturity.
What is the difference between Stage 1 and Stage 2 ISO 27001 audits?
Stage 1 is a documentation review confirming your ISMS scope, policy, Statement of Applicability, and risk treatment plan are complete and internally consistent. Stage 2 is an operational audit where the certification body samples actual evidence that controls are operating as documented, interviews staff, and reviews records like access reviews and incident tickets. Both must pass before certification is granted.
What is a Statement of Applicability?
The Statement of Applicability (SoA) is a mandatory ISO 27001 document listing all Annex A controls, whether each is implemented or excluded, and the justification for any exclusion. It is the single document auditors reference most heavily during both Stage 1 and Stage 2, and an incomplete or poorly justified SoA is the most common reason organizations fail or delay a Stage 1 audit.
Can ISO 27001 and CMMC compliance work overlap?
Yes, substantially. Both frameworks require formal risk assessment, access control, encryption, incident response, and continuous monitoring, though CMMC (built on NIST SP 800-171) has more prescriptive technical requirements for defense contractors handling controlled unclassified information. Organizations pursuing both should map controls once against a combined control set to avoid duplicating documentation and evidence-gathering effort.
Get a gap analysis against your completed checklist and a realistic path to Stage 1 audit.
Related Tools
SOC 2 Readiness Assessment
Answer 7 questions on policies, access control, monitoring, and evidence retention to get a scored SOC 2 readiness band with specific next steps before engaging an auditor.
Aerospace & DefenseZero Trust Readiness Assessment
Answer 8 questions on identity, device posture, segmentation, and access policy to get a scored zero trust maturity band with a specific remediation roadmap.
ERP OperationsVulnerability Remediation SLA Calculator
Estimate how many weeks it will take to burn down your priority vulnerability backlog given current findings volume, engineer capacity, and new findings arriving each week.
Go Deeper
Audit Trails for AI Decisions: A Compliance Guide
Build audit trails for AI decisions that satisfy internal and external auditors: what to log, how long to retain it, and how to prove provenance.
ITAR and CMMC Handling of AI Workloads
How ITAR and CMMC apply to AI workloads: technical data boundaries, CUI handling, assessed environments, and where on-prem AI is the only option.
ERP Cloud Compliance and Regulatory Guide
Ensure ERP cloud compliance with SOX, GDPR, HIPAA, and industry regulations. Covers data residency, audit trails, encryption, and compliance automation strategies.