Skip to content

StarterPrepare

Build a defensible baseline before you build anything else

Starter is the foundation layer: an approved policy set with ownership, a roadmap that sequences the first phase of work, and — the part most starter packages omit — guidance on what record each theme should produce. It is what we would put in place in the first month.

Who this is for

  • Smaller suppliers beginning preparation for the first time
  • Teams with security practices in place but nothing documented
  • Organisations that need a policy baseline approved before a wider programme is funded
  • Anyone who wants to understand the shape of the work before committing to it

Starter

Prepare

$49one-time

The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.

  • Core information security policy set
  • Quick start guide and readiness roadmap
  • Evidence guidance by requirement theme
  • Basic readiness assessment tools

Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.

What changes

The outcomes this tier is built for

Deliberately phrased as outcomes rather than document counts. A folder of files is not a result.

A policy set someone owns

Each policy has a named owner, an approval and a review date. That alone resolves the most common finding in a first review.

A written scope

Sites, entities, systems and information types. Without this, nothing downstream can be bounded or finished.

A sequenced roadmap

What to do in what order, so the first quarter is not spent on whichever theme feels most urgent that week.

Evidence guidance by theme

What record normally demonstrates each activity, decided before the activities start rather than after.

A basic readiness view

A light self-review so you know where the biggest gaps are before spending money closing the wrong ones.

A defensible starting position

Enough structure that a customer question about your security posture has a documented answer.

What is included

  • Quick Start Guide

    How to sequence preparation work in the first four weeks.

  • Core Policies

    Information security policy set with ownership and review cadence.

  • Readiness Roadmap

    Phased plan from initial scoping to internal verification.

  • Evidence Guidance

    What each theme typically needs to demonstrate, and who should own it.

  • Gap AssessmentBasic scope

    Structured maturity and gap review with owner and target date per finding.

What is not included

Stated plainly, because finding out after purchase is a bad experience.

  • Risk Management
  • Supplier Assessment
  • Internal Audit Programme
  • Management Review
  • ISO/IEC 27001 Alignment Layer
  • Prototype Protection Readiness
  • Data Protection Readiness
  • ISA2027 Transition Support
  • Multi-Site Governance
  • CAPA Tracker
  • KPI / KRI Dashboard
  • Third-Party Portfolio
  • Training Matrix
  • Executive Reporting
  • Consulting, review of your documents, or assessment support
  • Any guarantee of an assessment result, label or certification

Need what is missing above?

Professional adds it. Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.

Compare Professional

Questions about this tier

Is Starter enough to prepare for an assessment?
For most organisations, no — and we would rather say so. Starter gives you the baseline. Preparation also requires a structured gap assessment, risk treatment, supplier assessment, internal audit and management review, which is what Professional adds. If you already have an assessment date, start with Professional.
We have some policies already. Is this still useful?
Usually yes, for two reasons: the ownership and review structure is what is normally missing rather than the policy text, and the evidence guidance applies regardless of who wrote the documents.
Can we upgrade later?
Yes. The tiers are cumulative in structure — Professional contains the Starter foundation, so nothing you do at this level is discarded.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

Not sure this is the right tier?

The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.