Skip to content

EnterpriseGovern & Scale

Run readiness as one programme across several sites, and report it upward

At a certain size the constraint stops being implementation and becomes consistency. Enterprise adds the governance layer: a scope and ownership map across sites, corrective actions tracked to verified closure, a small set of indicators management will actually read, and a reporting pack that turns all of it into a defensible view.

Who this is for

  • Groups operating several sites or legal entities in scope
  • Organisations with a formal obligation to report security posture upward
  • Teams consolidating readiness that currently varies site by site
  • Programmes that need corrective action tracked with verified closure rather than assertion
  • Organisations planning to add sites or entities within the next year

Enterprise

Govern & Scale

$249one-time

Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.

  • Multi-site governance model and scope mapping
  • CAPA tracker with ownership and verification
  • KPI / KRI dashboard structure
  • Third-party portfolio register
  • Training and competence matrix
  • Executive reporting pack

Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.

What changes

The outcomes this tier is built for

Deliberately phrased as outcomes rather than document counts. A folder of files is not a result.

One scope map across sites

Which site owns which part of the scope, and where the boundaries actually sit. The prerequisite for any consolidated view.

Corrective action with verified closure

A CAPA tracker with root cause, owner, verification and evidence — so a finding is closed because someone checked, not because someone said so.

Measurement management will read

A KPI and KRI structure built around a small number of indicators. Four measures reviewed seriously beat twenty collected mechanically.

A third-party portfolio view

Criticality tiering and review cycle across the whole portfolio rather than assessment by assessment.

Competence you can evidence

A training and awareness matrix by role, which is also the fastest way to answer a question about who was trained on what.

Executive reporting

A board-level readiness summary with a trend view, so the conversation is about direction rather than about a snapshot.

What is included

  • Quick Start Guide

    How to sequence preparation work in the first four weeks.

  • Core Policies

    Information security policy set with ownership and review cadence.

  • Readiness Roadmap

    Phased plan from initial scoping to internal verification.

  • Evidence Guidance

    What each theme typically needs to demonstrate, and who should own it.

  • Gap Assessment

    Structured maturity and gap review with owner and target date per finding.

  • Risk Management

    Risk register, criteria, treatment plan and residual risk acceptance.

  • Supplier Assessment

    Third-party security questionnaire and follow-up tracking.

  • Internal Audit Programme

    Audit plan, checklists, findings log and closure verification.

  • Management Review

    Agenda, input pack and decision record aligned to management system practice.

  • ISO/IEC 27001 Alignment Layer

    Mapping view and Statement of Applicability structure.

  • Prototype Protection Readiness

    Readiness structure for organisations with a prototype protection scope.

  • Data Protection Readiness

    Readiness structure where a data protection scope applies.

  • ISA2027 Transition Support

    Change-impact worksheet and transition planning structure.

  • Multi-Site Governance

    Scope map, site ownership model and consolidated oversight.

  • CAPA Tracker

    Corrective and preventive actions with root cause and verification.

  • KPI / KRI Dashboard

    Measurement structure for security performance and risk indicators.

  • Third-Party Portfolio

    Portfolio register with criticality tiering and review cycle.

  • Training Matrix

    Role-based competence and awareness tracking.

  • Executive Reporting

    Board-level readiness summary with trend view.

What is not included

Stated plainly, because finding out after purchase is a bad experience.

Everything in the comparison matrix is included in this tier.

  • Consulting, implementation services, or a managed programme
  • Software licensing — the materials are working documents you own and adapt
  • Any guarantee of an assessment result, label or certification

Questions about this tier

Do we need Professional as well?
No. Enterprise contains the Professional layer in full — gap assessment, risk, supplier assessment, internal audit, management review and the alignment layer — plus the governance additions.
How many sites does this realistically handle?
The structure is designed around a scope map rather than a fixed number, so it scales with the number of rows rather than breaking at a threshold. Groups managing a handful to a few dozen sites are the intended case.
Is this a software platform?
No. These are working documents and structures you own and adapt inside your own environment. A hosted platform is on our roadmap; when it exists, it will be a separate product with its own pricing rather than a change to this one.
Can we discuss a multi-site rollout first?
Yes — that is a sensible conversation to have before purchase rather than after. Use the contact form and select Enterprise as the topic.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

Not sure this is the right tier?

The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.