Published
Summary: A quick check against ISO/IEC 27001:2022. Choose between 12 questions on the management system, clauses 4–10, and 32 questions, where 20 questions on the controls in Annex A are added, across the annex’s four themes. The quick check takes 5–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not an audit.
About this guide
- Who it is for
- Organisations considering certification, those for whom a customer requires ISO 27001, or those that want to know how close to the standard they already are.
- What you get
- A quick check with 12 questions on the ISMS, or 32 with Annex A, that takes 5–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.
The questions follow ISO/IEC 27001:2022. Answer yes only if you can show it, for example with a document, minutes or a procedure. “It should exist” counts as no. If you are reading without the buttons, count the yes answers in each area. Read more about the information security management system (ISO 27001).
Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.
Choose the scope
Area 1: Scope and leadership (clauses 4–5)
- Have you documented what the ISMS covers and why the boundary is where it is? (4.3)
- Have you mapped the interested parties’ requirements, including laws and contracts, and assessed whether climate change is a relevant issue for the ISMS? (4.1–4.2)
- Has management adopted an information security policy and assigned roles and responsibilities? (5.2–5.3)
Area 2: Risk (clauses 6 and 8)
- Do you have a risk method with decided criteria for when a risk is acceptable? (6.1.2)
- Is the risk assessment current, and is it repeated when something significant changes? (8.2)
- Is there a risk treatment plan and a Statement of Applicability with a justification for each control? (6.1.3)
Area 3: Support (clauses 6.2 and 7)
- Are there measurable security objectives with owners and a timeline? (6.2)
- Can you show that those with a role in the ISMS have the competence required? (7.2)
- Are policies and procedures version-controlled, approved and available to those who must follow them? (7.5)
Area 4: Evaluation and improvement (clauses 9–10)
- Is internal audit carried out under a programme, by someone who is not auditing their own work? (9.2)
- Does management review the ISMS at least once a year, and does the review lead to decisions? (9.3)
- Are nonconformities corrected with corrective actions that are followed up? (10.2)
Area 5: Annex A – policies, responsibilities and assets (A.5.1–5.18)
- Are there topic-specific policies, for example on access, suppliers and information classification, approved by management and reviewed regularly? (A.5.1)
- Are information security responsibilities assigned, and are duties that should not sit with the same person segregated? (A.5.2–5.3)
- Is there an inventory of information and other assets, with a named owner for each? (A.5.9)
- Is information classified by protection need, and labelled and handled accordingly? (A.5.12–5.14)
Area 6: Annex A – suppliers, incidents and continuity (A.5.19–5.30)
- Are security requirements set in contracts with suppliers, including cloud services, and followed up? (A.5.19–5.23)
- Is there a procedure for information security incidents, from report and assessment to lessons learned? (A.5.24–5.28)
- Is the ICT environment prepared for disruption, with continuity plans that have been tested? (A.5.29–5.30)
Area 7: Annex A – people and physical security (A.6–A.7)
- Is background screening done on hiring to the extent the risk requires, and are security responsibilities part of the terms of employment? (A.6.1–6.2)
- Do staff receive information security training when they start and regularly after that? (A.6.3)
- Is there a procedure for when someone leaves or changes role, with equipment returned and access rights removed? (A.6.5, A.5.11 and A.5.18)
- Is access to premises and areas with sensitive information limited to those who need it? (A.7.1–7.4)
- Are equipment and storage media protected, also off the premises and when disposed of or reused? (A.7.9–7.14)
Area 8: Annex A – access and protection (A.8.1–8.12)
- Are computers and mobile devices managed, with updates and protection against malware? (A.8.1 and A.8.7)
- Is privileged access restricted, and are access rights reviewed regularly? (A.8.2–8.3)
- Is multi-factor authentication used, at least for remote access and administrator accounts? (A.8.5)
- Are technical vulnerabilities managed with a procedure for patching and follow-up? (A.8.8)
Area 9: Annex A – operations and development (A.8.13–8.34)
- Are backups taken, and is restoration tested regularly? (A.8.13)
- Are important events logged, and monitored so that anomalies are detected? (A.8.15–8.16)
- Are there rules for encryption and key management, and are they followed? (A.8.24)
- Do development and changes follow secure procedures, with security requirements and testing before anything goes live? (A.8.25–8.32)
- Several of the basics of the ISMS are missing. Start with scope, policy, risk method and risk assessment.
- The foundation is partly there, but several parts are missing. Prioritise the areas with the lowest result.
- Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision, and a pre-audit shows what remains.
- The basics are in place. Keep the ISMS alive: risk assessment on change, internal audit and management review.
- ISO 27001 from gap analysis to certification An ISMS with a risk method, policies, a Statement of Applicability and internal audit, ready for audit.
- Pre-audit before certification An audit like the certification body’s, so you know what remains before the real one.
- Gap analysis against ISO 27001, NIS2 or DORA A documented current state, gaps per requirement and a prioritised action plan management can decide on.
- ISO 27001 internal audit An independent internal audit of the ISMS, with nonconformities and suggested improvements.
- Senior GRC advisory Ongoing support from a senior adviser on governance, risk and compliance, when and as much as you need.
- Supplier and third-party review Security requirements in contracts, risk-assessed suppliers and a follow-up procedure.
- Incident preparedness and tabletop exercise An incident procedure with roles and a reporting flow, exercised in a realistic scenario.
- Business continuity management and exercise Impact analysis, continuity plans and an exercise that shows the plans hold.
- Information classification A model for classifying information by protection need, and rules for handling it.
- Management cybersecurity training Training for management and the board that meets the Cybersecurity Act and DORA requirements, documented.
- Security maturity assessment An assessment of how well the security measures work in practice, with prioritised improvements.
- Backup and recovery verification We check that the backups exist, are protected and can actually be restored.
- Vulnerability assessment and penetration testing We look for the vulnerabilities before someone else does, with a prioritised list of fixes.
Would you like to go through the result with us?
Fill in your details and we will be in touch. The result in the box below is sent with the form, exactly as it reads there. We use the details only to contact you about the result and keep them for one year. Read more in our privacy notice.
Reading the result
- The management system, 12 questions: 11–12 yes is a solid foundation, 9–10 nearly there, 6–8 clear gaps, and 5 or fewer means the foundation is missing.
- With Annex A, 32 questions: 29–32 yes is a solid foundation, 23–28 nearly there, 16–22 clear gaps, and 15 or fewer means the foundation is missing.
- Solid foundation: The basics are in place. Keep the ISMS alive: risk assessment on change, internal audit and management review.
- Foundation missing: Several of the basics of the ISMS are missing. Start with scope, policy, risk method and risk assessment.
Per area: all yes is a solid foundation, one no nearly there, two no clear gaps, and more means the foundation is missing.
The quick check is an indication. It shows whether the basics seem to be there, not that you would pass a certification audit. A gap analysis or pre-audit assesses each requirement with evidence. If you answer no or don’t know to the questions on the risk method, the Statement of Applicability, internal audit or management review, it should be looked into whatever the total, because a certification auditor starts there.
What to do next
- Two or more areas with clear gaps: ISO 27001 from gap analysis to certification builds the ISMS with you.
- Close to the goal: a pre-audit shows what remains before the certification audit.
- No to internal audit or management review: an independent internal audit gives a first input to the review.
- If you only did the 12 questions: take the quick check again with Annex A, 20 more questions, to see the controls as well.
Would you like to go through the result with us? Read more about the information security management system (ISO 27001) or contact us.
Sources: ISO/IEC 27001:2022 with Amendment 1:2024, clauses 4–10 and Annex A; ISO/IEC 27002:2022. Fact-checked on 4 October 2026.
This text is general information and does not constitute legal advice in an individual case.

