Starter — Prepare
Build a defensible baseline before you build anything else
Starter is the foundation layer: an approved policy set with ownership, a roadmap that sequences the first phase of work, and — the part most starter packages omit — guidance on what record each theme should produce. It is what we would put in place in the first month.
Who this is for
- Smaller suppliers beginning preparation for the first time
- Teams with security practices in place but nothing documented
- Organisations that need a policy baseline approved before a wider programme is funded
- Anyone who wants to understand the shape of the work before committing to it
Starter
Prepare
The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.
- Core information security policy set
- Quick start guide and readiness roadmap
- Evidence guidance by requirement theme
- Basic readiness assessment tools
Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.
The outcomes this tier is built for
A policy set someone owns
Each policy has a named owner, an approval and a review date. That alone resolves the most common finding in a first review.
A written scope
Sites, entities, systems and information types. Without this, nothing downstream can be bounded or finished.
A sequenced roadmap
What to do in what order, so the first quarter is not spent on whichever theme feels most urgent that week.
Evidence guidance by theme
What record normally demonstrates each activity, decided before the activities start rather than after.
A basic readiness view
A light self-review so you know where the biggest gaps are before spending money closing the wrong ones.
A defensible starting position
Enough structure that a customer question about your security posture has a documented answer.
What is included
Quick Start Guide
How to sequence preparation work in the first four weeks.
Core Policies
Information security policy set with ownership and review cadence.
Readiness Roadmap
Phased plan from initial scoping to internal verification.
Evidence Guidance
What each theme typically needs to demonstrate, and who should own it.
Gap AssessmentBasic scope
Structured maturity and gap review with owner and target date per finding.
What is not included
Stated plainly, because finding out after purchase is a bad experience.
- Risk Management
- Supplier Assessment
- Internal Audit Programme
- Management Review
- ISO/IEC 27001 Alignment Layer
- Prototype Protection Readiness
- Data Protection Readiness
- ISA2027 Transition Support
- Multi-Site Governance
- CAPA Tracker
- KPI / KRI Dashboard
- Third-Party Portfolio
- Training Matrix
- Executive Reporting
- Consulting, review of your documents, or assessment support
- Any guarantee of an assessment result, label or certification
Need what is missing above?
Professional adds it. Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.
Compare Professional →Questions about this tier
Is Starter enough to prepare for an assessment?
We have some policies already. Is this still useful?
Can we upgrade later?
Not sure this is the right tier?
The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.