{ "@context": "https://schema.org", "@graph": [ { "@type": "Service", "name": "ISO 27001 Risk Assessment & ISMS Readiness", "serviceType": "Penetration Testing", "provider": { "@type": "Organization", "name": "Affordable Pentesting", "url": "https://affordablepentesting.com" }, "areaServed": "US", "url": "https://affordablepentesting.com/compliance/iso-27001" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://affordablepentesting.com/" }, { "@type": "ListItem", "position": 2, "name": "ISO 27001 Risk Assessment & ISMS Readiness", "item": "https://affordablepentesting.com/compliance/iso-27001" } ] } ] }
Compliance Assessment

ISO 27001 Risk Assessment & ISMS Readiness

Gap analysis against Trust Services Criteria before your auditor finds the gaps. Audit-ready evidence packages delivered fast, priced for real budgets.

ISO 27001 compliance icon
Why Us

Built for teams that need results, not retainers

OSCP, CEH & CREST Certified

Our assessors hold the certifications your auditors and assessors recognize — OSCP, CEH, and CREST. No junior analysts running checklists.

Fixed-Rate Pricing

You get a fixed price before we start. No hourly billing, no scope creep surprises, no invoice that looks nothing like the quote.

5–10 Day Turnaround

Most assessments are delivered in five to ten business days from kickoff. Built for real audit deadlines, not enterprise consulting timelines.

Auditor-Ready Deliverables

Reports are structured so your auditor, QSA, C3PAO, or certification body can evaluate evidence directly. No translation layer required.

What is ISO 27001 Certification?

ISO/IEC 27001 is the international standard for an Information Security Management System. Certification means an accredited certification body has examined your ISMS and confirmed it meets the standard. It is not a report on your controls the way SOC 2 is — it is a pass or fail certificate covering your management system as a whole.

That distinction shapes everything about how you prepare. Auditors are not only asking whether a control exists. They are asking whether your organization has a working system for identifying risk, deciding what to do about it, implementing that decision, and reviewing whether it worked. A strong control set with no management system behind it still fails.

ISO 27002 is the companion standard people frequently confuse with it. 27001 states the requirements you are certified against; 27002 is implementation guidance for the Annex A controls. You certify to 27001. You use 27002 to figure out how.

Clauses 4 Through 10 and the 93 Annex A Controls

The mandatory requirements live in Clauses 4 through 10: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. These are non-negotiable and they are where most first-time nonconformities are raised.

Annex A contains 93 controls across four themes — organizational, people, physical, and technological. You are not required to implement all 93. You are required to consider each one, decide whether it applies, and document that decision in your Statement of Applicability. Excluding a control is allowed. Excluding it without a justification your auditor accepts is not.

The 2022 revision restructured Annex A from 114 controls into 93 and introduced eleven new ones, including threat intelligence, data masking, data leakage prevention, and web filtering. Organizations that transitioned from the 2013 version without revisiting their SoA routinely carry gaps against those new controls.

Clause 6.1.2: The Risk Assessment Everything Else Rests On

Clause 6.1.2 requires a defined, repeatable information security risk assessment process — not a one-time spreadsheet. You need documented risk criteria, a consistent method for identifying and analyzing risk, and results that can be reproduced. Your risk treatment plan and your Statement of Applicability both trace back to it.

This is the first artifact most certification body auditors ask for, and a weak one undermines everything downstream. If your SoA justifications do not map cleanly to identified risks, the auditor has found a systemic problem rather than an isolated gap.

Stage 1 and Stage 2: How the Certification Audit Works

Stage 1 is a documentation and readiness review. The auditor confirms your ISMS is defined, your mandatory documentation exists, and you are ready to be audited. Findings here are usually about completeness.

Stage 2 is the full certification audit. The auditor tests whether your controls actually operate, interviews your people, and samples evidence. Major nonconformities at Stage 2 must be closed before a certificate is issued. After certification, surveillance audits follow annually, with a full recertification at the three-year mark.

Our walkthrough of the ISO 27001 certification process covers what happens in each stage and how to prepare for the interviews.

What Our ISO 27001 Risk Assessment Covers

  • Clause 6.1.2 risk assessment documentation built to a repeatable method, forming the foundation of your entire ISMS
  • Full gap analysis against every mandatory clause and all 93 Annex A controls, with clear findings and remediation guidance for each
  • Statement of Applicability created or reviewed so it is ready for your certification body auditor without back-and-forth
  • 2022 revision coverage — the newer controls organizations miss when transitioning from the 2013 version
  • Technical validation of Annex A.8.8 and A.8.29 controls through penetration testing evidence rather than policy review alone
  • Prioritized remediation roadmap and evidence checklist organized around your certification timeline

How Long Does ISO 27001 Certification Take?

From initial gap assessment to Stage 2, most organizations need six to eighteen months. The floor is set by something you cannot compress: auditors need to see your ISMS operating, which means internal audits, a management review, and a period of running records. Even a well-prepared organization rarely certifies in under six months.

Starting maturity is the main variable. A company with existing SOC 2 controls and documented processes moves considerably faster than one starting from a blank page. Our ISO 27001 certification timeline breaks the path into phases so you can plan against a real calendar.

What Does ISO 27001 Certification Cost?

Costs split into three buckets: implementation work to close gaps, tooling and control costs, and the certification body's audit fees. Consultancies commonly quote five and six figures for the implementation piece alone, and certification body fees scale with headcount and scope.

The bucket teams underestimate is internal time. Building an ISMS is organizational work, not a document you buy. Our ISO 27001 cost guide breaks down each line item, including what you can reasonably do in-house.

ISO 27001 Resources

Get Certification-Ready Without the Six-Figure Consulting Bill

A complete ISO 27001 gap assessment, Statement of Applicability, and Stage 2 evidence package structured for real certification timelines.

  • Gap analysis against all mandatory clauses and 93 Annex A controls with per-control findings and remediation steps
  • Clause 6.1.2 risk assessment documentation and Statement of Applicability that satisfies Stage 2 certification body auditors
  • Evidence checklist and remediation roadmap your team can execute without a full-time ISMS consultant on staff

ISO 27001 certification is achievable without a six-figure consulting engagement. Get your ISO 27001 technical risk assessment quote and find out exactly what stands between you and certification.

meet with a team member
48h
Average quote turnaround from form submission
5–10
Business days to a complete, deliverable assessment
0
Sales calls — quote first, conversation only if you want one
How It Works

From form to findings in three steps

1

Fill out the form

Tell us your framework, environment size, and audit deadline. Takes two minutes. No account required, no sales call triggered.

2

Get a scoped quote

We review your submission and send a fixed-price quote with scope, timeline, and what you’ll receive — usually within one business day.

3

Assessment delivered

Once you approve, we kick off immediately. Gap report, remediation roadmap, and evidence package delivered in 5 to 10 business days.

Get a Quote

Get Certification-Ready Without the Six-Figure Consulting Bill

A complete ISO 27001 gap assessment, Statement of Applicability, and Stage 2 evidence package — structured for real certification timelines.

  • Gap analysis against all mandatory clauses and 93 Annex A controls with per-control findings and remediation steps
  • Clause 6.1.2 risk assessment documentation and Statement of Applicability that satisfies Stage 2 certification body auditors
  • Evidence checklist and remediation roadmap your team can execute without a full-time ISMS consultant on staff

No sales calls. Same-day response.

meet with a team member
Common Questions

Common ISO 27001 Assessment Questions

How long does it take to get ISO 27001 certified?

From initial gap assessment to Stage 2 certification, most organizations need six to eighteen months depending on starting maturity and scope. Our assessment tells you where you actually are on that timeline so you can plan realistically rather than optimistically.

Do I need a penetration test for ISO 27001?

The standard does not mandate a penetration test by name. Annex A.8.8 (management of technical vulnerabilities) and A.8.29 (security testing in development and acceptance) create practical requirements for active security testing, and certification bodies treat pentest evidence as the strongest available demonstration that those controls operate effectively.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 contains the requirements you are audited and certified against. ISO 27002 is guidance on how to implement the Annex A controls. You cannot be certified to 27002 — it is a reference document, not a certifiable standard.

Do I have to implement all 93 Annex A controls?

No. You must consider each one and document in your Statement of Applicability whether it applies, with justification. Exclusions are legitimate when your risk assessment supports them. Unjustified exclusions are a common source of nonconformities.

Can ISO 27001 work reuse our SOC 2 evidence?

Substantially, yes. The control overlap is significant, particularly around access management, change management, and vendor risk. What SOC 2 does not give you is the management system layer — the risk assessment method, Statement of Applicability, internal audit programme, and management review that ISO requires.