Skip to content

The ISAREADY Toolkit

Build a structured, evidence-driven readiness program

Not thirty templates in a folder. A readiness system for turning requirements into implemented processes and traceable evidence — where the gap assessment feeds risk treatment, risk treatment feeds the implementation plan, implementation produces evidence, internal audit verifies it, and management review closes the loop.

Starter

Prepare

$49one-time

The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.

  • Core information security policy set
  • Quick start guide and readiness roadmap
  • Evidence guidance by requirement theme
  • Basic readiness assessment tools

Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.

Most popular

Professional

Assess & Implement

$119one-time

Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.

  • Structured gap assessment workbook
  • Information security risk register and treatment plan
  • Supplier and third-party assessment set
  • Internal audit programme and management review pack
  • ISO/IEC 27001 alignment layer with Statement of Applicability
  • Prototype protection and data protection readiness
  • ISA 6 to ISA2027 transition support

Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.

Enterprise

Govern & Scale

$249one-time

Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.

  • Multi-site governance model and scope mapping
  • CAPA tracker with ownership and verification
  • KPI / KRI dashboard structure
  • Third-party portfolio register
  • Training and competence matrix
  • Executive reporting pack

Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.

One-time price per tier. No subscription, no countdown, no artificial scarcity.

Why teams come to us

The problems this is built for

None of these are unusual. All of them are structural rather than technical, which is why more documents do not fix them.

Scattered documentation

Policies in three places, none of them versioned, and nobody certain which copy is current.

Unclear ownership

Requirements everyone agrees are important and nobody is specifically accountable for.

Missing evidence

Controls that genuinely operate, with no record you could produce without a week of archaeology.

Unstructured gap assessments

A colour-coded spreadsheet that everyone agrees is accurate and nobody acts on.

Weak supplier follow-up

Questionnaires sent, returned, filed, and never followed through to closure.

Preparation under time pressure

A date in the calendar and four weeks of reconstruction ahead of you.

How it fits together

One system, six connected stages

Each stage produces the input the next one needs. That connection is the difference between a toolkit and a folder.
  1. 1

    Assess

    Establish scope and an honest baseline. What is actually in place, not what the documents claim.

  2. 2

    Identify Gaps

    Convert the baseline into findings with an owner, a priority and a target date.

  3. 3

    Implement

    Do the work: processes, controls and the decisions that make them stick in daily operation.

  4. 4

    Collect Evidence

    Produce the record as the activity happens. Decided in advance, not reconstructed later.

  5. 5

    Verify

    Check yourself against your own rules through internal audit before anyone else does.

  6. 6

    Improve

    Close findings at root cause and feed the outcome back into risk, controls and awareness.

Assessment layer

Gap assessment workbook and maturity grading with consistent level definitions, so two passes are actually comparable.

Implementation layer

Policy set, risk register and treatment plan, supplier assessment, and the ownership model that keeps them moving.

Verification layer

Internal audit programme, findings log with root cause, management review pack, and the evidence map underneath all of it.

Compare

What is included in each tier

Foundation

  • Quick Start Guide

    How to sequence preparation work in the first four weeks.

    Starter
    Included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Core Policies

    Information security policy set with ownership and review cadence.

    Starter
    Included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Readiness Roadmap

    Phased plan from initial scoping to internal verification.

    Starter
    Included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Evidence Guidance

    What each theme typically needs to demonstrate, and who should own it.

    Starter
    Included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise

Assess & implement

  • Gap Assessment

    Structured maturity and gap review with owner and target date per finding.

    Starter
    Included at a basic scope in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Risk Management

    Risk register, criteria, treatment plan and residual risk acceptance.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Supplier Assessment

    Third-party security questionnaire and follow-up tracking.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Internal Audit Programme

    Audit plan, checklists, findings log and closure verification.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Management Review

    Agenda, input pack and decision record aligned to management system practice.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise

Alignment & scope extensions

  • ISO/IEC 27001 Alignment Layer

    Mapping view and Statement of Applicability structure.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Prototype Protection Readiness

    Readiness structure for organisations with a prototype protection scope.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • Data Protection Readiness

    Readiness structure where a data protection scope applies.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise
  • ISA2027 Transition Support

    Change-impact worksheet and transition planning structure.

    Starter
    Not included in Starter
    Professional
    Included in Professional
    Enterprise
    Included in Enterprise

Govern & scale

  • Multi-Site Governance

    Scope map, site ownership model and consolidated oversight.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise
  • CAPA Tracker

    Corrective and preventive actions with root cause and verification.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise
  • KPI / KRI Dashboard

    Measurement structure for security performance and risk indicators.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise
  • Third-Party Portfolio

    Portfolio register with criticality tiering and review cycle.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise
  • Training Matrix

    Role-based competence and awareness tracking.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise
  • Executive Reporting

    Board-level readiness summary with trend view.

    Starter
    Not included in Starter
    Professional
    Not included in Professional
    Enterprise
    Included in Enterprise

Before you buy

What format is the toolkit in?
Working documents and workbooks you can edit and adopt — policies, registers, programmes, workbooks and reporting structures. It is designed to be used and modified inside your organisation, not read once.
Does buying the toolkit guarantee a successful assessment?
No. No toolkit can guarantee a TISAX assessment result, a TISAX label, an ISO certification or regulatory compliance, and you should treat any vendor who claims otherwise with suspicion. What it provides is the structure — the work of implementing it remains yours.
Which tier should we choose?
If you have no documented baseline yet, Starter. If you have a baseline and now need to run a gap assessment, treat risks, assess suppliers and audit yourself, Professional — that covers most preparation teams. If you are consolidating several sites or entities and have to report readiness upward, Enterprise. The free self-assessment ends with a recommendation based on your answers.
Is it aligned to a specific catalogue version?
It is organised around themes and activities rather than around catalogue question numbers, which is deliberate: a catalogue version change then costs you a mapping update rather than a rebuild. The Professional tier includes a transition worksheet for exactly that.
Do you offer support or consulting?
The toolkits are self-service. If you have questions about scope, tiers or a multi-site rollout, get in touch and we will answer them directly.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

Not sure which tier fits?

Take the free self-assessment. It ends with a recommendation based on your readiness indicator and organisation profile, along with the reasoning behind it.