Overview

The ISO 27001 Maturity Assessment provides a structured framework for evaluating your organisation's Information Security Management System (ISMS) against the ISO/IEC 27001:2022 standard. With 130 questions, this assessment is structured around both the management system requirements (Clauses 4–10) and the Annex A controls.

Through structured evaluation criteria, you will assess your organisation's security governance, risk management processes, operational controls, and continuous improvement practices against internationally recognised best practice.

The assessment employs a maturity-based scoring model to help you understand your current ISMS posture, identify control gaps, and develop a prioritised remediation roadmap for audit readiness or ongoing compliance.

Who It's For

This assessment is designed for:

  • Organisations preparing for an ISO 27001 certification audit
  • Certified organisations maintaining or improving their ISMS
  • Information Security Managers and ISMS owners
  • CISOs overseeing information security programmes
  • Internal audit teams conducting ISMS readiness reviews
  • GRC professionals managing ISO 27001 compliance

Typical Outcomes

Organisations using this assessment typically gain:

  • Clear understanding of current ISMS maturity against ISO 27001:2022
  • Identification of gaps in management system clauses and Annex A controls
  • Prioritised remediation plan to help you prepare for a certification audit
  • Documentation to support internal compliance reporting
  • Baseline for tracking ISMS improvements over time
  • Structured input ahead of certification or surveillance audits

Assessment Coverage

The assessment is structured across the ISO 27001:2022 areas below:

Management System Clauses:

  • Clause 4: Context of the Organisation — understanding internal/external issues, interested parties, and ISMS scope
  • Clause 5: Leadership — top management commitment, policy, and organisational roles
  • Clause 6: Planning — risk assessment, risk treatment, and information security objectives
  • Clause 7: Support — resources, competence, awareness, communication, and documented information
  • Clause 8: Operation — operational planning, risk assessment execution, and risk treatment implementation
  • Clause 9: Performance Evaluation — monitoring, measurement, internal audit, and management review
  • Clause 10: Improvement — nonconformity, corrective action, and continual improvement

Annex A Control Domains:

  • A.5: Organisational Controls — policies, asset management, access control, supplier relationships
  • A.6: People Controls — screening, employment terms, awareness, remote working
  • A.7: Physical Controls — security perimeters, equipment, clear desk, secure disposal
  • A.8: Technological Controls — endpoints, privileged access, malware, backup, logging, network security, cryptography, secure development

What You Receive

Executive Summary Report

Board-ready overview with maturity scores by clause and control domain, exportable to Word format for executive and auditor circulation.

Detailed Gap Register

Findings with risk ratings and evidence requirements mapped to specific ISO 27001 clauses and controls, exportable to Excel.

Maturity Visualisations

Charts and dashboards showing clause-by-clause and control domain maturity, suitable for management review and certification-audit preparation.

Prioritised Remediation Roadmap

Actionable recommendations ranked by risk and audit significance, designed for immediate use in ISMS improvement planning.

Consistent methodology enables quarterly or annual reassessment for trend analysis and continuous improvement tracking required by Clause 10.

Ready to Assess Your ISO 27001 Maturity?

Tell us a little about your organisation and we will walk you through what the ISO 27001 assessment covers and how access works.

Enquire about access

What this is

CyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.

On coverage

We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.

CyberAssure is not affiliated with, endorsed by, or accredited by ISO, IEC, or any accreditation or certification body.

Often Used Alongside

Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.

Cybersecurity Framework

NIST CSF v2.0 Assessment

Complement ISO 27001's management system focus with NIST CSF's outcome-based cybersecurity framework.

Learn more
Third-Party Risk

Supply Chain Security Assessment

Extend Annex A.5.19-5.22 supplier controls with detailed third-party risk management.

Learn more

Have questions about how our assessments work?

Read the Enterprise Assessment FAQ →

Also assessing payment security?

View PCI DSS Assessment →