
Find your gaps. Before the auditor does.
Independent ISMS assessment by certified Lead Auditors — with a penetration test built in.
Certification audits reward preparation. This is the rehearsal on your own clock — your ISMS read like an auditor reads it, your controls tested like an adversary tests them, ending in a verdict you can plan against.
93
Annex A controls, evidence-sampled
2
Lenses — Lead Auditor review + penetration test
4–6 wks
From kickoff to a readiness verdict
The gap
The audit is a test. Most teams sit it unrehearsed.
Certification audits reward preparation. Walking in without an independent assessment means finding your gaps on the auditor's clock.
A failed Stage 2 doesn't just cost the audit fee. It costs the re-audit, the quarter you lose to unplanned remediation, and the enterprise deal that was waiting on the certificate. Preparation is cheaper — and it's schedulable.
What the auditor will ask for
- 01The ISMS scope and Statement of Applicability
- 02The risk register — and proof it drives decisions
- 03Evidence samples across Annex A controls
- 04Management review minutes and internal audit results
- 05Proof the controls run — not just that they're written
Have the answers before it's their clock.
The difference
Read like an auditor. Tested like an adversary.
Most readiness assessments stop at the paperwork. Ours runs two lenses over the same scope — because certificates are won on evidence, and lost on controls that only exist in writing.
Lens one
The auditor's lens
Certified ISO 27001 and 27701 Lead Auditors read your ISMS the way the certification body will — scope, Statement of Applicability, risk register, policy corpus — then sample evidence across Annex A the way Stage 2 does: interviews, records, and proof of operation.
Lens two
The adversary's lens
A web application penetration test against in-scope systems, run by Zentara's certified offensive bench. Where the paper says a control exists, the test asks whether it holds. A policy that fails a pentest isn't a control — it's a document.
And we've sat on your side of the table: Zentara holds ISO 27001:2022, ISO 27701, ISO 42001, and SOC 2 Type 2 for its own operations — prepared and defended with the same discipline we bring to yours.
Verify at our trust centreWhat you get
A verdict, not a maybe.
Four artifacts, built for the decision the audit forces — go now, or close these first.
Annex A control map · ISO 27001:2022
Prepared for: · Fieldwork 2–20 Jun 2026
A.5 · Organizational
5.1 – 5.37 · 37 controls
A.6 · People
6.1 – 6.8 · 8 controls
A.7 · Physical
7.1 – 7.14 · 14 controls
A.8 · Technological
8.1 – 8.34 · 34 controls
§ 6 · Certification readiness verdict
Conditionally ready
Ready for Stage 1 after closure of 3 major findings. Estimated remediation to audit-ready: 10 weeks.
72
Conformant
16
Minor
3
Major
2
N/A
Major nonconformities
- NC-01A.5.23Cloud services security — supplier exit and data-return clauses absent
- NC-02A.8.16Monitoring activities — logging gaps across two core systems
- NC-03A.8.28Secure coding — no enforced review gate before production release
Lead Auditor · ISO/IEC 27001 LA
27 Jun 2026
ISMS gap assessment
Clause-by-clause and control-by-control findings, each traceable to a document, an interview, or a test result — audit-grade evidence discipline.
Technical validation report
The penetration test findings, mapped back to the Annex A controls they contradict — where the paper and the practice disagree.
Annex A remediation plan
Every gap with an owner, an effort estimate, and a sequence — majors first, quick wins flagged, dependencies drawn.
Certification readiness verdict
A straight answer: ready, conditionally ready, or not yet — and exactly what stands between you and Stage 1.
The journey
Where this sits on the road to certified
Zentara prepares you. An accredited certification body certifies you. That separation is deliberate — it's what keeps the certificate worth holding.
Readiness assessment
This engagement — gaps found on your clock, not the auditor's.
Remediation
Your team, your integrators, or Zentara — the plan names capabilities, not brands.
Stage 1 audit
The certification body reviews your ISMS documentation.
Stage 2 audit
Implementation audited in depth. This is where preparation pays.
Certified
Surveillance audits in years one and two; recertification at year three.
Certification ahead?
Rehearse the audit on your own clock.
Four to six weeks to a verdict: what's conformant, what isn't, and exactly what stands between you and Stage 1 — with the remediation plan attached.
How it runs
Six weeks. Two lenses. One verdict.
Scope & documents
ISMS scope, Statement of Applicability, risk register, and policy corpus reviewed. The assessment plan lands before the first interview.
Controls & evidence
Annex A controls assessed through interviews and evidence sampling — records, configurations, and proof of operation, the way Stage 2 will ask.
Technical validation
Web application penetration testing against in-scope systems. Findings are mapped to the controls they contradict.
Verdict & plan
The readiness verdict, the prioritized Annex A remediation plan, and a briefing for management — with a re-check window agreed before we leave.
Track record
Delivered for listed power-generation companies and critical infrastructure operators.
Assessed by a firm that holds ISO 27001:2022, ISO 27701, ISO 42001, and SOC 2 Type 2 for its own operations — and prepares for its own audits the same way.
Verify at our trust centreBuild the program
Pairs well with
vCISO — Virtual CISO
Certification isn't a one-off. A named vCISO owns the ISMS after the audit — standing maintenance, surveillance prep, and the recertification three years out.
Data Governance Implementation
Under UU PDP, the natural next step is extending the ISMS to privacy — ISO 27701 PIMS alignment on the same governance spine.
VAPT — Vulnerability Assessment & Penetration Testing
The in-scope WAPT is the audit lens. The full offensive catalog goes deeper — infrastructure, mobile, cloud, and red team, on the same evidence discipline.
FAQ
Common questions
Straight answers. If yours isn't here, ask us directly.
No — and be wary of anyone who offers both. Certification is issued by accredited certification bodies; Zentara prepares you for them. That separation is deliberate and protects the certificate's value. What we deliver is the rehearsal: the same evidence discipline, on your clock, with a remediation plan attached — and we can stand beside your team during the real audit.
Related
More in Advisory & Compliance
Walk into Stage 1 knowing the verdict.
Ninety-three controls, two lenses, one straight answer — and the remediation plan to act on it. Scope the assessment before the auditor's clock starts.