Skip to content

ProfessionalAssess & Implement

The tier that moves an organisation from documents to demonstrable operation

Professional is where preparation becomes a programme. Gap assessment produces owned findings; findings feed risk treatment; treatment produces implementation; implementation produces evidence; internal audit verifies it; management review closes the loop. This is the tier most preparation teams actually need.

Who this is for

  • Teams with a policy baseline who now need to close gaps systematically
  • Organisations with an assessment date in the calendar
  • Suppliers who must assess their own third parties and follow findings to closure
  • Teams aligning an existing ISO/IEC 27001 management system with automotive expectations
  • Anyone planning for an ISA catalogue transition
Most popular

Professional

Assess & Implement

$119one-time

Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.

  • Structured gap assessment workbook
  • Information security risk register and treatment plan
  • Supplier and third-party assessment set
  • Internal audit programme and management review pack
  • ISO/IEC 27001 alignment layer with Statement of Applicability
  • Prototype protection and data protection readiness
  • ISA 6 to ISA2027 transition support

Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.

What changes

The outcomes this tier is built for

Deliberately phrased as outcomes rather than document counts. A folder of files is not a result.

A gap assessment that produces action

Findings with an owner, a priority, a target date and the evidence that would close them — not a colour-coded spreadsheet.

A risk register that leads to decisions

Documented method, owners, treatment plans, and residual risk formally accepted by someone with the authority to accept it.

Supplier assessment with follow-through

A third-party register with criticality tiering, an assessment set, and a follow-up log that shows closure rather than dispatch.

An internal audit programme

Plan, checklists, findings log with root cause and verified closure. The cheapest way to find what an external party would find.

Management review that produces a record

Agenda, structured input pack and a decision record — the artefact a verbal update never generates.

ISO/IEC 27001 alignment

A mapping view and Statement of Applicability structure so one management system serves both purposes instead of two disagreeing with each other.

Scope extensions where they apply

Prototype protection and data protection readiness structures, used only if those scopes apply to you.

Transition readiness

An ISA2027 change-impact worksheet built around activity-to-reference mapping, so a catalogue change is a mapping update rather than a rebuild.

What is included

  • Quick Start Guide

    How to sequence preparation work in the first four weeks.

  • Core Policies

    Information security policy set with ownership and review cadence.

  • Readiness Roadmap

    Phased plan from initial scoping to internal verification.

  • Evidence Guidance

    What each theme typically needs to demonstrate, and who should own it.

  • Gap Assessment

    Structured maturity and gap review with owner and target date per finding.

  • Risk Management

    Risk register, criteria, treatment plan and residual risk acceptance.

  • Supplier Assessment

    Third-party security questionnaire and follow-up tracking.

  • Internal Audit Programme

    Audit plan, checklists, findings log and closure verification.

  • Management Review

    Agenda, input pack and decision record aligned to management system practice.

  • ISO/IEC 27001 Alignment Layer

    Mapping view and Statement of Applicability structure.

  • Prototype Protection Readiness

    Readiness structure for organisations with a prototype protection scope.

  • Data Protection Readiness

    Readiness structure where a data protection scope applies.

  • ISA2027 Transition Support

    Change-impact worksheet and transition planning structure.

What is not included

Stated plainly, because finding out after purchase is a bad experience.

  • Multi-Site Governance
  • CAPA Tracker
  • KPI / KRI Dashboard
  • Third-Party Portfolio
  • Training Matrix
  • Executive Reporting
  • Consulting, document review, or attendance at your assessment
  • Any guarantee of an assessment result, label or certification

Need what is missing above?

Enterprise adds it. Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.

Compare Enterprise

Questions about this tier

Do we need Starter as well?
No. Professional contains the Starter foundation — policy set, quick start guide, roadmap and evidence guidance — so buying both would duplicate it.
We are one site. Is Enterprise overkill?
For a single site with centralised governance, almost certainly. Enterprise exists for consolidating several sites or entities and for formal reporting obligations. If neither applies to you, Professional is the right tier.
How long does it take to work through?
The materials themselves are a matter of days to absorb and adapt. The programme they describe runs over months, because evidence has to accumulate over time rather than be produced in a sitting. Anyone promising you a faster answer is selling something else.
Does it cover prototype protection?
It includes a prototype protection readiness structure for organisations where that scope applies. It does not reproduce official catalogue content, and it is not a substitute for the official documentation.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

Not sure this is the right tier?

The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.