Professional — Assess & Implement
The tier that moves an organisation from documents to demonstrable operation
Professional is where preparation becomes a programme. Gap assessment produces owned findings; findings feed risk treatment; treatment produces implementation; implementation produces evidence; internal audit verifies it; management review closes the loop. This is the tier most preparation teams actually need.
Who this is for
- Teams with a policy baseline who now need to close gaps systematically
- Organisations with an assessment date in the calendar
- Suppliers who must assess their own third parties and follow findings to closure
- Teams aligning an existing ISO/IEC 27001 management system with automotive expectations
- Anyone planning for an ISA catalogue transition
Professional
Assess & Implement
Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.
- Structured gap assessment workbook
- Information security risk register and treatment plan
- Supplier and third-party assessment set
- Internal audit programme and management review pack
- ISO/IEC 27001 alignment layer with Statement of Applicability
- Prototype protection and data protection readiness
- ISA 6 to ISA2027 transition support
Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.
The outcomes this tier is built for
A gap assessment that produces action
Findings with an owner, a priority, a target date and the evidence that would close them — not a colour-coded spreadsheet.
A risk register that leads to decisions
Documented method, owners, treatment plans, and residual risk formally accepted by someone with the authority to accept it.
Supplier assessment with follow-through
A third-party register with criticality tiering, an assessment set, and a follow-up log that shows closure rather than dispatch.
An internal audit programme
Plan, checklists, findings log with root cause and verified closure. The cheapest way to find what an external party would find.
Management review that produces a record
Agenda, structured input pack and a decision record — the artefact a verbal update never generates.
ISO/IEC 27001 alignment
A mapping view and Statement of Applicability structure so one management system serves both purposes instead of two disagreeing with each other.
Scope extensions where they apply
Prototype protection and data protection readiness structures, used only if those scopes apply to you.
Transition readiness
An ISA2027 change-impact worksheet built around activity-to-reference mapping, so a catalogue change is a mapping update rather than a rebuild.
What is included
Quick Start Guide
How to sequence preparation work in the first four weeks.
Core Policies
Information security policy set with ownership and review cadence.
Readiness Roadmap
Phased plan from initial scoping to internal verification.
Evidence Guidance
What each theme typically needs to demonstrate, and who should own it.
Gap Assessment
Structured maturity and gap review with owner and target date per finding.
Risk Management
Risk register, criteria, treatment plan and residual risk acceptance.
Supplier Assessment
Third-party security questionnaire and follow-up tracking.
Internal Audit Programme
Audit plan, checklists, findings log and closure verification.
Management Review
Agenda, input pack and decision record aligned to management system practice.
ISO/IEC 27001 Alignment Layer
Mapping view and Statement of Applicability structure.
Prototype Protection Readiness
Readiness structure for organisations with a prototype protection scope.
Data Protection Readiness
Readiness structure where a data protection scope applies.
ISA2027 Transition Support
Change-impact worksheet and transition planning structure.
What is not included
Stated plainly, because finding out after purchase is a bad experience.
- Multi-Site Governance
- CAPA Tracker
- KPI / KRI Dashboard
- Third-Party Portfolio
- Training Matrix
- Executive Reporting
- Consulting, document review, or attendance at your assessment
- Any guarantee of an assessment result, label or certification
Need what is missing above?
Enterprise adds it. Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.
Compare Enterprise →Questions about this tier
Do we need Starter as well?
We are one site. Is Enterprise overkill?
How long does it take to work through?
Does it cover prototype protection?
Not sure this is the right tier?
The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.