ISO 27001 Self-Assessment, Free and Online
Find out how ready your organization really is. Work through the full ISO/IEC 27001:2022 control set, get an instant security score with domain breakdown, and see exactly which gaps to fix first.
No credit card required · Save progress anytime · ~30–60 minutes
What Is an ISO 27001 Self-Assessment?
An ISO 27001 self-assessment is a structured review of how well your organization manages information security, based on the ISO/IEC 27001:2022 standard and its Annex A control set — 93 controls across four domains.
Unlike a certification audit, a self-assessment is something you can run yourself, today, without hiring external auditors. It answers one question clearly: where does our security posture stand, and what should we improve first?
It is also the most practical preparation step before a formal certification project: every gap you find now is one that won't surprise you during an audit later.
Assessment vs. Certification
- Self-assessment: done by your team, free, identifies gaps and priorities
- Certification audit: performed by an accredited certification body, required for the certificate itself
- EvaluationCat prepares you for certification — it does not issue one
Your Result Preview
74/100
Good · ISO 27001 Readiness 68%
Example result. Every control is scored on a five-level maturity scale, weighted by importance — see scoring methodology.
The 93 Controls, in Four Domains
Every Annex A control is covered — nothing skipped, nothing simplified into a checkbox quiz.
Organizational Controls
Policies, roles, asset management, supplier relationships, and incident planning — the management layer of your ISMS.
People Controls
Screening, security awareness, remote working, and disciplinary processes that govern how people handle information.
Physical Controls
Secure areas, equipment protection, clear desk rules, and monitoring of physical premises.
Technological Controls
Access control, cryptography, logging, network security, secure development, and vulnerability management.
How the Assessment Works
Four steps from sign-up to an actionable improvement plan
Create your workspace
Sign up and add basic company information.
Answer guided questions
Complete control questions based on your reality.
Review your report
Get scores, gaps, and risk insights instantly.
Plan and track improvements
Follow recommendations and re-assess regularly.
What You Get
Not just a score — a complete path from assessment to remediation
Security Score
Weighted score across all four domains with ISO 27001 readiness percentage.
Gap Analysis
Every missing or partial control listed with severity and framework mapping.
AI Remediation
Concrete fix guidance per gap — steps, tools, cost, effort — not generic advice.
30/90/180-Day Plan
A prioritized roadmap telling you what to fix first, next, and long-term.
Free tier: the full 93-control assessment, instant scoring, gap summary, and basic PDF report are free. Upgrade to Pro ($49 one-time) only if you want the AI remediation plan and implementation roadmap. See pricing.
Related Pages
ISO 27001 Gap Analysis
Already assessed? See missing controls ranked by severity with fixes.
What Is a Security Questionnaire?
Why enterprise buyers send them and how to answer well.
Frameworks Explained
How ISO 27001, CAIQ, and AI-CAIQ compare and fit together.
Scoring Methodology
How the security score and readiness percentage are calculated.
Know Your ISO 27001 Readiness Today
Free, structured, and mapped to the real standard. Start now, finish whenever you're ready.
Start Free Assessment