ISO 27001 Self-Assessment
FREE DOWNLOAD · ISO/IEC 27001:2022

Know exactly where your information security really stands.

A free, no-nonsense Excel self-assessment for ISO/IEC 27001:2022, the information security management system. Rate your organisation against every requirement, see the gaps on a live dashboard, and build your path to certification.

Microsoft Excel
Auditor questions built in
Result grading
Audit dashboard
The standard

What is ISO/IEC 27001?

First published in 2005 and last revised in 2022, ISO/IEC 27001 is the world’s best known standard for an Information Security Management System, or ISMS. It gives organisations a risk-based way to protect information.

At its heart is a simple idea. You manage information security through a continual cycle of risk assessment and risk treatment, rather than a fixed checklist. You decide which risks matter, then select the controls that treat them.

The 2022 edition follows the harmonised structure of Clauses 4 to 10, and its Annex A sets out 93 reference controls grouped into four themes: organisational, people, physical and technological. These align with ISO/IEC 27002:2022.

It applies to any organisation that handles information worth protecting, from cloud providers to hospitals to professional firms. Certification is often a contractual or tender requirement, and it underpins trust with customers and regulators.

2022

Current edition, the third

93

Annex A reference controls

4

Control themes

7

Clauses, numbered 4 to 10

  • Protects information across confidentiality, integrity and availability.
  • Wins business where certification is a tender or contract condition.
  • Manages risk through a continual assess-and-treat cycle.
The free tool

A complete health check, in one spreadsheet.

This workbook turns the whole standard into a working self-assessment. No consultants required to get started. Open it, answer honestly, and watch your position take shape on the dashboard.

Two lenses, not one

Score each requirement twice, once for compliance and once for maturity. See where you conform on paper and where the practice is genuinely embedded.

Every requirement covered

All of Clauses 4 to 10 plus all 93 Annex A controls across the four themes, each with plain-English guidance.

Live dashboard

Compliance, average maturity, progress and a red, amber, green view by section. It updates itself as you type.

Gap and action tracker

Capture the gap, the action, an owner and a target date next to every requirement, so the assessment doubles as your improvement plan.

Certification ready

Built around the exact structure a certification body audits, so your results point straight at what to fix before a review.

Zero setup

Standard Excel, no macros and nothing to install. Rate items with simple drop-downs. Works on the desktop app and in the browser.

Compliance

Are you meeting the requirement today? Rate it Fully, Largely, Partially or Non-conformant, backed by evidence.

Overall compliance 88%

Maturity

How embedded and repeatable is the approach, regardless of today's compliance? Rate it from 0, not started, to 4, optimised.

Average maturity 3.5 / 4
Inside the workbook

Five tabs that do the work for you.

A branded front page with document control and the copyright and IP terms.

How to complete it, plus the compliance scale and the maturity scale.

Your live scorecard: KPI tiles, results by section, and distributions.

The 30 management-system requirements, each with what to look for and space for evidence.

All 93 reference controls, with an applicability column that works like a Statement of Applicability.

Dashboard — updates automatically
How it works

From download to action plan in an afternoon.

STEP 01

Download

Grab the Excel file. No sign-up wall, no macros, nothing to install.

STEP 02

Rate each item

Pick a compliance status and a maturity level from the drop-downs, and note your evidence.

STEP 03

Read the dashboard

See your overall position and the exact requirements that need attention.

STEP 04

Close the gaps

Assign owners and target dates, then track progress to certification readiness.

Who it is for

Built for the people who run the system.

CISOs and security leads
Risk and compliance managers
IT and cloud teams
Privacy and legal counsel
Consultants and internal auditors
Go further

Ready To Implement, Not Just Assess?

The free tool shows where you stand. When you are ready to build the ISMS, these paid resources from Risk Professionals get you there faster.

Document Toolkit

Skip The Blank Page

A complete, editable ISO 27001 document kit, mapped to the standard and ready to implement, so you never start from a blank page.

Training & Certification

Upskill the team

Accredited ISO 27001 training for your team, from foundation through lead implementer and lead auditor.

Advisory & virtual services

Bring in the Experts

Hands-on help, from a gap assessment to a virtual executive who helps run the system with you.

Not sure what certification will cost? Try the free ISO 27001 cost calculator.

FAQs

Yes. The tool is offered free for your organisation’s own internal use, with no sign-up wall and no macros. You may use and reproduce it internally, but not sell, rebrand or redistribute it for commercial gain. Full terms are on the Cover sheet.

ISO 14001:2026, the fourth edition. This edition adds a separate risks and opportunities requirement and planning of changes, so the tool is built to the 2026 structure, not the 2015 one.

The tool includes plain-English guidance so you can start straight away. For a formal implementation or certification you should still obtain the official standard from ISO or an authorised reseller. The tool summarises the requirements and is not a substitute for the standard.

Compliance asks whether you meet the requirement today. Maturity asks how embedded, documented and repeatable the approach is. They are rated separately, because you can be compliant on paper yet immature in practice, or maturing but not yet compliant. Rating both gives a truer picture.

No. This self-assessment helps you understand your position and prioritise improvements. Certification can only be granted by an accredited certification body after a formal audit.