How close to ISO 27001 are you? A quick check with or without Annex A

A quick check against ISO 27001: 12 questions on the ISMS, or 20 with Annex A. The result appears straight away, red to green, with suggested next steps.

Summary: A quick check against ISO/IEC 27001:2022. Choose between 12 questions on the management system, clauses 4–10, and 32 questions, where 20 questions on the controls in Annex A are added, across the annex’s four themes. The quick check takes 5–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not an audit.

About this guide

Who it is for
Organisations considering certification, those for whom a customer requires ISO 27001, or those that want to know how close to the standard they already are.
What you get
A quick check with 12 questions on the ISMS, or 32 with Annex A, that takes 5–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.

The questions follow ISO/IEC 27001:2022. Answer yes only if you can show it, for example with a document, minutes or a procedure. “It should exist” counts as no. If you are reading without the buttons, count the yes answers in each area. Read more about the information security management system (ISO 27001).

Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.

Area 1: Scope and leadership (clauses 4–5)

  1. Have you documented what the ISMS covers and why the boundary is where it is? (4.3)
  2. Have you mapped the interested parties’ requirements, including laws and contracts, and assessed whether climate change is a relevant issue for the ISMS? (4.1–4.2)
  3. Has management adopted an information security policy and assigned roles and responsibilities? (5.2–5.3)

Area 2: Risk (clauses 6 and 8)

  1. Do you have a risk method with decided criteria for when a risk is acceptable? (6.1.2)
  2. Is the risk assessment current, and is it repeated when something significant changes? (8.2)
  3. Is there a risk treatment plan and a Statement of Applicability with a justification for each control? (6.1.3)

Area 3: Support (clauses 6.2 and 7)

  1. Are there measurable security objectives with owners and a timeline? (6.2)
  2. Can you show that those with a role in the ISMS have the competence required? (7.2)
  3. Are policies and procedures version-controlled, approved and available to those who must follow them? (7.5)

Area 4: Evaluation and improvement (clauses 9–10)

  1. Is internal audit carried out under a programme, by someone who is not auditing their own work? (9.2)
  2. Does management review the ISMS at least once a year, and does the review lead to decisions? (9.3)
  3. Are nonconformities corrected with corrective actions that are followed up? (10.2)

Area 5: Annex A – policies, responsibilities and assets (A.5.1–5.18)

  1. Are there topic-specific policies, for example on access, suppliers and information classification, approved by management and reviewed regularly? (A.5.1)
  2. Are information security responsibilities assigned, and are duties that should not sit with the same person segregated? (A.5.2–5.3)
  3. Is there an inventory of information and other assets, with a named owner for each? (A.5.9)
  4. Is information classified by protection need, and labelled and handled accordingly? (A.5.12–5.14)

Area 6: Annex A – suppliers, incidents and continuity (A.5.19–5.30)

  1. Are security requirements set in contracts with suppliers, including cloud services, and followed up? (A.5.19–5.23)
  2. Is there a procedure for information security incidents, from report and assessment to lessons learned? (A.5.24–5.28)
  3. Is the ICT environment prepared for disruption, with continuity plans that have been tested? (A.5.29–5.30)

Area 7: Annex A – people and physical security (A.6–A.7)

  1. Is background screening done on hiring to the extent the risk requires, and are security responsibilities part of the terms of employment? (A.6.1–6.2)
  2. Do staff receive information security training when they start and regularly after that? (A.6.3)
  3. Is there a procedure for when someone leaves or changes role, with equipment returned and access rights removed? (A.6.5, A.5.11 and A.5.18)
  4. Is access to premises and areas with sensitive information limited to those who need it? (A.7.1–7.4)
  5. Are equipment and storage media protected, also off the premises and when disposed of or reused? (A.7.9–7.14)

Area 8: Annex A – access and protection (A.8.1–8.12)

  1. Are computers and mobile devices managed, with updates and protection against malware? (A.8.1 and A.8.7)
  2. Is privileged access restricted, and are access rights reviewed regularly? (A.8.2–8.3)
  3. Is multi-factor authentication used, at least for remote access and administrator accounts? (A.8.5)
  4. Are technical vulnerabilities managed with a procedure for patching and follow-up? (A.8.8)

Area 9: Annex A – operations and development (A.8.13–8.34)

  1. Are backups taken, and is restoration tested regularly? (A.8.13)
  2. Are important events logged, and monitored so that anomalies are detected? (A.8.15–8.16)
  3. Are there rules for encryption and key management, and are they followed? (A.8.24)
  4. Do development and changes follow secure procedures, with security requirements and testing before anything goes live? (A.8.25–8.32)

Reading the result

  • The management system, 12 questions: 11–12 yes is a solid foundation, 9–10 nearly there, 6–8 clear gaps, and 5 or fewer means the foundation is missing.
  • With Annex A, 32 questions: 29–32 yes is a solid foundation, 23–28 nearly there, 16–22 clear gaps, and 15 or fewer means the foundation is missing.
  • Solid foundation: The basics are in place. Keep the ISMS alive: risk assessment on change, internal audit and management review.
  • Foundation missing: Several of the basics of the ISMS are missing. Start with scope, policy, risk method and risk assessment.

Per area: all yes is a solid foundation, one no nearly there, two no clear gaps, and more means the foundation is missing.

The quick check is an indication. It shows whether the basics seem to be there, not that you would pass a certification audit. A gap analysis or pre-audit assesses each requirement with evidence. If you answer no or don’t know to the questions on the risk method, the Statement of Applicability, internal audit or management review, it should be looked into whatever the total, because a certification auditor starts there.

What to do next

  • Two or more areas with clear gaps: ISO 27001 from gap analysis to certification builds the ISMS with you.
  • Close to the goal: a pre-audit shows what remains before the certification audit.
  • No to internal audit or management review: an independent internal audit gives a first input to the review.
  • If you only did the 12 questions: take the quick check again with Annex A, 20 more questions, to see the controls as well.

Would you like to go through the result with us? Read more about the information security management system (ISO 27001) or contact us.

Sources: ISO/IEC 27001:2022 with Amendment 1:2024, clauses 4–10 and Annex A; ISO/IEC 27002:2022. Fact-checked on 4 October 2026.

This text is general information and does not constitute legal advice in an individual case.