First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/ISO 27001 Assessment in Preparation Before the External Audit
Security and Protection

ISO 27001 Assessment — Pre-Audit ISMS Gap Review

IT Partner’s ISO 27001 pre-audit assessment service helps organizations with an existing Information Security Management System prepare for an external ISO 27001 audit by reviewing the ISMS against ISO 27001 standards, identifying gaps, and providing a detailed report with actionable improvement recommendations. Service details: SKU ITPWW200SECOT, price $4000 per project, duration 30 days, manager Roman Sotnik.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

ISO 27001 is an internationally recognized standard for information security management systems. This service assesses an organization’s existing ISMS before an external ISO 27001 audit. IT Partner reviews the ISMS, validates established controls and processes, identifies gaps against ISO 27001 standards, and provides a detailed report with recommendations so the organization can take corrective action before the formal audit.

Success criteria

01The organization's ISMS is fully assessed against ISO 27001 standards.
02Gaps and areas of non-compliance are identified and addressed.
03A detailed report with improvement recommendations is provided.
04The organization is well-prepared to undertake the external ISO 27001 audit with confidence.

What you receive

Initial discovery meeting to understand the organization's ISMS setup and audit expectations.
Thorough review of the organization's ISMS to validate the effectiveness of the established controls and processes.
Identification of gaps in the ISMS against ISO 27001 standards.
Detailed report documenting findings and actionable recommendations for improvement.
Final meeting to discuss the report, explain findings, and provide guidance on implementing recommendations.

How the work unfolds

Initial meeting

Scope the project and understand the organization's ISMS setup (Day 1).

Assessment

Conduct an in-depth review of the ISMS and documentation (Day 2-5).

Reporting

Document findings, gaps, and recommendations (Day 6-7).

Final meeting

Discuss the report, explain findings, and guide on next steps (Day 8).

Prerequisites

An existing ISMS that can be reviewed and audited.
Availability of the organization's team members for discussions and meetings.
Necessary permissions and accesses for IT partner to conduct the review.

Who does what

IT Partner

  • Conduct an initial discovery meeting to understand the organization's ISMS setup and audit expectations.
  • Perform a thorough review of the organization's ISMS to validate the effectiveness of the established controls and processes.
  • Identify any gaps in the ISMS against ISO 27001 standards.
  • Document findings and provide a detailed report with actionable recommendations for improvement.
  • Conduct a final meeting to discuss the report, explain findings, and provide guidance on implementing recommendations.

Your team

  • Provide all necessary access to the ISMS, related documentation, and personnel for the assessment.
  • Review the findings and recommendations from IT partner.
  • Implement recommended actions to close identified gaps and enhance the ISMS.
  • Organize for the external audit based on the assessment report.

What's not included

External ISO 27001 certification audit services, certification decisions, or issuance of certificates by an accredited certification body.
Guarantee that the organization will pass the external ISO 27001 audit.
Full ISMS design, implementation, or rebuild where an ISMS does not already exist.
Hands-on remediation of identified gaps, such as writing policies, implementing technical controls, configuring Microsoft 365/Azure security features, or changing operational processes, unless separately scoped.
Legal, regulatory, or formal risk acceptance advice; the client remains responsible for compliance decisions and risk ownership.
Penetration testing, vulnerability scanning, incident response, forensic investigation, or security monitoring services unless separately contracted.
Audit of suppliers, third parties, multiple business units, additional locations, or entities outside the agreed assessment scope unless separately included.
Translation, extensive document reformatting, or creation of complete evidence packs beyond the assessment report and stated recommendations.

Frequently asked questions

What is IT Partner’s ISO 27001 pre-audit assessment service?

IT Partner’s ISO 27001 pre-audit assessment service helps organizations with an existing Information Security Management System prepare for an external ISO 27001 audit. IT Partner reviews the ISMS against ISO 27001 standards, validates established controls and processes, identifies gaps, and provides a detailed report with actionable improvement recommendations.

Who is this ISO 27001 assessment service designed for?

This service is designed for organizations that already have an Information Security Management System in place and want to prepare before an external ISO 27001 audit. It is not described as an ISMS implementation service, because the stated prerequisite is an existing ISMS that can be reviewed and audited.

What is included in the ISO 27001 pre-audit assessment?

The service includes an initial discovery meeting, a thorough review of the organization’s ISMS, validation of established controls and processes, identification of gaps against ISO 27001 standards, and a detailed report with actionable recommendations. It also includes a final meeting to discuss the findings, explain the report, and provide guidance on recommended next steps.

What deliverables will we receive from IT Partner?

You will receive a detailed report documenting findings, identified gaps, and actionable recommendations for improvement. The engagement also includes discovery and final review meetings, because IT Partner needs to understand your ISMS setup at the start and explain the assessment results at the end.

Does this service include ISO 27001 certification?

No, this service is a preparation assessment before an external ISO 27001 audit, not the external certification audit itself. IT Partner assesses your ISMS, identifies gaps, and provides recommendations so your organization can take corrective action before the formal audit.

Will IT Partner guarantee that we pass the external ISO 27001 audit?

No pass guarantee is stated for this service. The intended outcome is that your ISMS is assessed, gaps are identified, recommendations are provided, and your organization is better prepared to undertake the external ISO 27001 audit with confidence.

How long does the ISO 27001 pre-audit assessment take?

The service duration is listed as 30 days. The implementation plan outlines key assessment activities over Days 1–8, including the initial meeting, ISMS review, reporting, and final meeting, so calendar scheduling and any remaining time should be confirmed with IT Partner.

What happens during the initial discovery meeting?

During the initial discovery meeting, IT Partner scopes the project and learns about your organization’s ISMS setup and audit expectations. This step is important because the assessment needs to be aligned to your existing ISMS and the external audit you are preparing for.

What does IT Partner review during the assessment phase?

IT Partner conducts an in-depth review of the ISMS and related documentation to validate the effectiveness of established controls and processes. The review is performed against ISO 27001 standards to identify gaps, weaknesses, or areas of non-compliance before the external audit.

What is the implementation plan for this service?

The implementation plan starts with an initial meeting on Day 1, followed by the ISMS and documentation assessment on Days 2–5. IT Partner then documents findings and recommendations on Days 6–7 and holds a final meeting on Day 8 to discuss the report and next steps.

What are the prerequisites for starting the assessment?

Your organization must have an existing ISMS that can be reviewed and audited. You also need to make relevant team members available for discussions and provide the necessary permissions and access for IT Partner to conduct the review.

What access does IT Partner need for the ISO 27001 assessment?

IT Partner needs access to the ISMS, related documentation, and relevant personnel involved in the management and operation of the ISMS. The service depends on this access because IT Partner must validate controls, review processes, and identify gaps against ISO 27001 standards.

What are IT Partner’s responsibilities during the engagement?

IT Partner is responsible for conducting the discovery meeting, reviewing the ISMS, validating controls and processes, identifying gaps against ISO 27001 standards, and documenting findings in a detailed report. IT Partner also conducts the final meeting to explain findings and provide guidance on implementing recommendations.

What are the client’s responsibilities during the engagement?

The client is responsible for providing access to the ISMS, related documentation, and personnel needed for the assessment. The client must also review IT Partner’s findings, implement recommended actions to close identified gaps, and organize the external audit based on the assessment report.

Does the service include remediation of identified ISO 27001 gaps?

The stated scope includes identifying gaps and providing actionable recommendations, but it does not state that IT Partner implements remediation actions. The client is responsible for implementing recommended actions, so any hands-on remediation support should be confirmed separately with IT Partner.

What is not included in this ISO 27001 assessment service?

The provided service description does not specify out-of-scope items or additional-cost items. Based on the stated scope, the service focuses on assessment, gap identification, reporting, and guidance; confirm with IT Partner if you need implementation support, certification audit services, or other activities beyond the assessment.

Will this assessment cause downtime or business disruption?

The service description does not indicate planned downtime, because the engagement is focused on reviewing the existing ISMS, documentation, controls, processes, and audit readiness. Some business impact should be expected in the form of meetings, document access, and staff participation during discussions.

How much does IT Partner’s ISO 27001 pre-audit assessment cost?

The service price is $4,000 per project under SKU ITPWW200SECOT. If your organization has unusual scope, additional locations, or needs beyond the stated assessment deliverables, you should confirm whether any changes affect pricing.

Who manages the ISO 27001 pre-audit assessment project?

The listed manager for this service is Roman Sotnik. The engagement includes structured milestones and meetings, so the manager helps coordinate the assessment process and completion of the stated deliverables.

What should we do after the assessment is completed?

After completion, your organization should review the detailed report, prioritize the identified gaps, and implement the recommended actions to improve the ISMS. The client is also responsible for organizing the external audit based on the assessment report, because this service prepares you for the audit but does not replace it.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4000 per project
30 days
Book a meeting