ZENTARA
A Zentara assessor working through evidence review
Information Security Assessment · ISO 27001:2022

Find your gaps. Before the auditor does.

Independent ISMS assessment by certified Lead Auditors — with a penetration test built in.

Certification audits reward preparation. This is the rehearsal on your own clock — your ISMS read like an auditor reads it, your controls tested like an adversary tests them, ending in a verdict you can plan against.

93

Annex A controls, evidence-sampled

2

Lenses — Lead Auditor review + penetration test

4–6 wks

From kickoff to a readiness verdict

We hold the certificates we prepare you for

BSSN — Badan Siber dan Sandi NegaraISO/IEC 27001 CertifiedISO/IEC 42001:2023 CertifiedAICPA SOC 2 Type 2
Verify at our trust centre

The gap

The audit is a test. Most teams sit it unrehearsed.

Certification audits reward preparation. Walking in without an independent assessment means finding your gaps on the auditor's clock.

A failed Stage 2 doesn't just cost the audit fee. It costs the re-audit, the quarter you lose to unplanned remediation, and the enterprise deal that was waiting on the certificate. Preparation is cheaper — and it's schedulable.

What the auditor will ask for

  • 01The ISMS scope and Statement of Applicability
  • 02The risk register — and proof it drives decisions
  • 03Evidence samples across Annex A controls
  • 04Management review minutes and internal audit results
  • 05Proof the controls run — not just that they're written

Have the answers before it's their clock.

The difference

Read like an auditor. Tested like an adversary.

Most readiness assessments stop at the paperwork. Ours runs two lenses over the same scope — because certificates are won on evidence, and lost on controls that only exist in writing.

Lens one

The auditor's lens

Certified ISO 27001 and 27701 Lead Auditors read your ISMS the way the certification body will — scope, Statement of Applicability, risk register, policy corpus — then sample evidence across Annex A the way Stage 2 does: interviews, records, and proof of operation.

ISMS document reviewSoA & risk registerEvidence samplingControl interviews

Lens two

The adversary's lens

A web application penetration test against in-scope systems, run by Zentara's certified offensive bench. Where the paper says a control exists, the test asks whether it holds. A policy that fails a pentest isn't a control — it's a document.

WAPT in scopeControl-bypass attemptsOSCP · GPEN testersFindings mapped to Annex A

And we've sat on your side of the table: Zentara holds ISO 27001:2022, ISO 27701, ISO 42001, and SOC 2 Type 2 for its own operations — prepared and defended with the same discipline we bring to yours.

Verify at our trust centre

What you get

A verdict, not a maybe.

Four artifacts, built for the decision the audit forces — go now, or close these first.

Zentara_ISMS_Assessment_[CLIENT]_2026.pdf — sampleConfidential

Annex A control map · ISO 27001:2022

Prepared for: · Fieldwork 2–20 Jun 2026

A.5 · Organizational

5.1 – 5.37 · 37 controls

A.6 · People

6.1 – 6.8 · 8 controls

A.7 · Physical

7.1 – 7.14 · 14 controls

A.8 · Technological

8.1 – 8.34 · 34 controls

Conformant Minor gap Major gap Not applicable Evidence sampled
Assessor LA-027 · Evidence items: 214 · Method ZTR-ISA v2.4Page 14 of 63
Zentara_ISMS_Assessment_[CLIENT]_2026.pdf — verdictConfidential

§ 6 · Certification readiness verdict

Conditionally ready

Ready for Stage 1 after closure of 3 major findings. Estimated remediation to audit-ready: 10 weeks.

72

Conformant

16

Minor

3

Major

2

N/A

Major nonconformities

  • NC-01A.5.23Cloud services security — supplier exit and data-return clauses absent
  • NC-02A.8.16Monitoring activities — logging gaps across two core systems
  • NC-03A.8.28Secure coding — no enforced review gate before production release

Lead Auditor · ISO/IEC 27001 LA

27 Jun 2026

Findings register — Annex A clause · owner · effortPage 41 of 63
01

ISMS gap assessment

Clause-by-clause and control-by-control findings, each traceable to a document, an interview, or a test result — audit-grade evidence discipline.

02

Technical validation report

The penetration test findings, mapped back to the Annex A controls they contradict — where the paper and the practice disagree.

03

Annex A remediation plan

Every gap with an owner, an effort estimate, and a sequence — majors first, quick wins flagged, dependencies drawn.

04

Certification readiness verdict

A straight answer: ready, conditionally ready, or not yet — and exactly what stands between you and Stage 1.

The journey

Where this sits on the road to certified

Zentara prepares you. An accredited certification body certifies you. That separation is deliberate — it's what keeps the certificate worth holding.

01You are here

Readiness assessment

This engagement — gaps found on your clock, not the auditor's.

02

Remediation

Your team, your integrators, or Zentara — the plan names capabilities, not brands.

03

Stage 1 audit

The certification body reviews your ISMS documentation.

04

Stage 2 audit

Implementation audited in depth. This is where preparation pays.

05

Certified

Surveillance audits in years one and two; recertification at year three.

What brings teams here —Enterprise procurement demands the certificateISO 27001:2013 → 2022 transition still openUU PDP points to an ISO 27701 privacy extensionRegulator or parent company expects an ISMSSurveillance audit approaching

Certification ahead?

Rehearse the audit on your own clock.

Four to six weeks to a verdict: what's conformant, what isn't, and exactly what stands between you and Stage 1 — with the remediation plan attached.

How it runs

Six weeks. Two lenses. One verdict.

01Week 1

Scope & documents

ISMS scope, Statement of Applicability, risk register, and policy corpus reviewed. The assessment plan lands before the first interview.

02Weeks 2–3

Controls & evidence

Annex A controls assessed through interviews and evidence sampling — records, configurations, and proof of operation, the way Stage 2 will ask.

03Weeks 3–4

Technical validation

Web application penetration testing against in-scope systems. Findings are mapped to the controls they contradict.

04Weeks 5–6

Verdict & plan

The readiness verdict, the prioritized Annex A remediation plan, and a briefing for management — with a re-check window agreed before we leave.

The evidence rule —Every finding traceable to a document, an interview, or a test result

Track record

Delivered for listed power-generation companies and critical infrastructure operators.

Assessed by a firm that holds ISO 27001:2022, ISO 27701, ISO 42001, and SOC 2 Type 2 for its own operations — and prepares for its own audits the same way.

Verify at our trust centre

FAQ

Common questions

Straight answers. If yours isn't here, ask us directly.

No — and be wary of anyone who offers both. Certification is issued by accredited certification bodies; Zentara prepares you for them. That separation is deliberate and protects the certificate's value. What we deliver is the rehearsal: the same evidence discipline, on your clock, with a remediation plan attached — and we can stand beside your team during the real audit.

Walk into Stage 1 knowing the verdict.

Ninety-three controls, two lenses, one straight answer — and the remediation plan to act on it. Scope the assessment before the auditor's clock starts.