The ISAREADY Toolkit
Build a structured, evidence-driven readiness program
Not thirty templates in a folder. A readiness system for turning requirements into implemented processes and traceable evidence — where the gap assessment feeds risk treatment, risk treatment feeds the implementation plan, implementation produces evidence, internal audit verifies it, and management review closes the loop.
Starter
Prepare
The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.
- Core information security policy set
- Quick start guide and readiness roadmap
- Evidence guidance by requirement theme
- Basic readiness assessment tools
Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.
Professional
Assess & Implement
Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.
- Structured gap assessment workbook
- Information security risk register and treatment plan
- Supplier and third-party assessment set
- Internal audit programme and management review pack
- ISO/IEC 27001 alignment layer with Statement of Applicability
- Prototype protection and data protection readiness
- ISA 6 to ISA2027 transition support
Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.
Enterprise
Govern & Scale
Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.
- Multi-site governance model and scope mapping
- CAPA tracker with ownership and verification
- KPI / KRI dashboard structure
- Third-party portfolio register
- Training and competence matrix
- Executive reporting pack
Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.
One-time price per tier. No subscription, no countdown, no artificial scarcity.
The problems this is built for
Scattered documentation
Policies in three places, none of them versioned, and nobody certain which copy is current.
Unclear ownership
Requirements everyone agrees are important and nobody is specifically accountable for.
Missing evidence
Controls that genuinely operate, with no record you could produce without a week of archaeology.
Unstructured gap assessments
A colour-coded spreadsheet that everyone agrees is accurate and nobody acts on.
Weak supplier follow-up
Questionnaires sent, returned, filed, and never followed through to closure.
Preparation under time pressure
A date in the calendar and four weeks of reconstruction ahead of you.
One system, six connected stages
- 1
Assess
Establish scope and an honest baseline. What is actually in place, not what the documents claim.
- 2
Identify Gaps
Convert the baseline into findings with an owner, a priority and a target date.
- 3
Implement
Do the work: processes, controls and the decisions that make them stick in daily operation.
- 4
Collect Evidence
Produce the record as the activity happens. Decided in advance, not reconstructed later.
- 5
Verify
Check yourself against your own rules through internal audit before anyone else does.
- 6
Improve
Close findings at root cause and feed the outcome back into risk, controls and awareness.
Assessment layer
Gap assessment workbook and maturity grading with consistent level definitions, so two passes are actually comparable.
Implementation layer
Policy set, risk register and treatment plan, supplier assessment, and the ownership model that keeps them moving.
Verification layer
Internal audit programme, findings log with root cause, management review pack, and the evidence map underneath all of it.
What is included in each tier
| Included | StarterPrepare | ProfessionalAssess & Implement | EnterpriseGovern & Scale |
|---|---|---|---|
| Foundation | |||
| Quick Start GuideHow to sequence preparation work in the first four weeks. | Included in Starter | Included in Professional | Included in Enterprise |
| Core PoliciesInformation security policy set with ownership and review cadence. | Included in Starter | Included in Professional | Included in Enterprise |
| Readiness RoadmapPhased plan from initial scoping to internal verification. | Included in Starter | Included in Professional | Included in Enterprise |
| Evidence GuidanceWhat each theme typically needs to demonstrate, and who should own it. | Included in Starter | Included in Professional | Included in Enterprise |
| Assess & implement | |||
| Gap AssessmentStructured maturity and gap review with owner and target date per finding. | Included at a basic scope in Starter | Included in Professional | Included in Enterprise |
| Risk ManagementRisk register, criteria, treatment plan and residual risk acceptance. | Not included in Starter | Included in Professional | Included in Enterprise |
| Supplier AssessmentThird-party security questionnaire and follow-up tracking. | Not included in Starter | Included in Professional | Included in Enterprise |
| Internal Audit ProgrammeAudit plan, checklists, findings log and closure verification. | Not included in Starter | Included in Professional | Included in Enterprise |
| Management ReviewAgenda, input pack and decision record aligned to management system practice. | Not included in Starter | Included in Professional | Included in Enterprise |
| Alignment & scope extensions | |||
| ISO/IEC 27001 Alignment LayerMapping view and Statement of Applicability structure. | Not included in Starter | Included in Professional | Included in Enterprise |
| Prototype Protection ReadinessReadiness structure for organisations with a prototype protection scope. | Not included in Starter | Included in Professional | Included in Enterprise |
| Data Protection ReadinessReadiness structure where a data protection scope applies. | Not included in Starter | Included in Professional | Included in Enterprise |
| ISA2027 Transition SupportChange-impact worksheet and transition planning structure. | Not included in Starter | Included in Professional | Included in Enterprise |
| Govern & scale | |||
| Multi-Site GovernanceScope map, site ownership model and consolidated oversight. | Not included in Starter | Not included in Professional | Included in Enterprise |
| CAPA TrackerCorrective and preventive actions with root cause and verification. | Not included in Starter | Not included in Professional | Included in Enterprise |
| KPI / KRI DashboardMeasurement structure for security performance and risk indicators. | Not included in Starter | Not included in Professional | Included in Enterprise |
| Third-Party PortfolioPortfolio register with criticality tiering and review cycle. | Not included in Starter | Not included in Professional | Included in Enterprise |
| Training MatrixRole-based competence and awareness tracking. | Not included in Starter | Not included in Professional | Included in Enterprise |
| Executive ReportingBoard-level readiness summary with trend view. | Not included in Starter | Not included in Professional | Included in Enterprise |
Foundation
Quick Start Guide
How to sequence preparation work in the first four weeks.
- Starter
- Included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Core Policies
Information security policy set with ownership and review cadence.
- Starter
- Included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Readiness Roadmap
Phased plan from initial scoping to internal verification.
- Starter
- Included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Evidence Guidance
What each theme typically needs to demonstrate, and who should own it.
- Starter
- Included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Assess & implement
Gap Assessment
Structured maturity and gap review with owner and target date per finding.
- Starter
- Included at a basic scope in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Risk Management
Risk register, criteria, treatment plan and residual risk acceptance.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Supplier Assessment
Third-party security questionnaire and follow-up tracking.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Internal Audit Programme
Audit plan, checklists, findings log and closure verification.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Management Review
Agenda, input pack and decision record aligned to management system practice.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Alignment & scope extensions
ISO/IEC 27001 Alignment Layer
Mapping view and Statement of Applicability structure.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Prototype Protection Readiness
Readiness structure for organisations with a prototype protection scope.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Data Protection Readiness
Readiness structure where a data protection scope applies.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
ISA2027 Transition Support
Change-impact worksheet and transition planning structure.
- Starter
- Not included in Starter
- Professional
- Included in Professional
- Enterprise
- Included in Enterprise
Govern & scale
Multi-Site Governance
Scope map, site ownership model and consolidated oversight.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
CAPA Tracker
Corrective and preventive actions with root cause and verification.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
KPI / KRI Dashboard
Measurement structure for security performance and risk indicators.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
Third-Party Portfolio
Portfolio register with criticality tiering and review cycle.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
Training Matrix
Role-based competence and awareness tracking.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
Executive Reporting
Board-level readiness summary with trend view.
- Starter
- Not included in Starter
- Professional
- Not included in Professional
- Enterprise
- Included in Enterprise
Before you buy
What format is the toolkit in?
Does buying the toolkit guarantee a successful assessment?
Which tier should we choose?
Is it aligned to a specific catalogue version?
Do you offer support or consulting?
Not sure which tier fits?
Take the free self-assessment. It ends with a recommendation based on your readiness indicator and organisation profile, along with the reasoning behind it.