ISO 27001 Readiness Check
Thirty-six yes/no questions that map your organisation against the mandatory clauses 4 to 10 of ISO/IEC 27001:2022, then the Annex A controls that most often become audit findings. Results per clause and next steps appear as soon as you finish.
- 36 questions
- ± 10 minutes
Frequently asked questions
Is ISO 27001 mandatory for companies in Indonesia?
Not in general, but it is frequently required: private-scope electronic system operators by Komdigi, banks and fintechs by OJK, government electronic systems by BSSN, and many state-owned or multinational tenders ask for an ISO/IEC 27001 certificate as a vendor requirement.
What is the difference between the mandatory clauses and Annex A in this questionnaire?
Clauses 4 to 10 are management system requirements every organisation must meet. Annex A lists 93 controls selected from the risk assessment and recorded in the Statement of Applicability; this questionnaire checks the controls from all four groups that most often become audit findings.
How long does ISO 27001 certification take after this result?
Organisations at Certification-ready are usually audit-ready within 1 to 3 months; Developing takes 3 to 6 months; Foundation Stage 6 to 12 months depending on scope size. See the GRC services page for stages and pricing.
Does the questionnaire follow ISO/IEC 27001:2022 or SNI ISO/IEC 27001?
The questions map to ISO/IEC 27001:2022 clauses 4 to 10 and the 2022 Annex A. SNI ISO/IEC 27001:2022 is an identical adoption, so the result applies to both; the only difference is which certification body you choose.
Who should complete this questionnaire?
The information security owner, head of IT, or the certification project owner. Answer based on what is actually documented today, not what is planned, so the recommendations are accurate.
Discuss this result with our consultants
We support you from gap analysis to certification audit, with a 100% first-audit pass rate.