ISO/IEC 27001:2022 · 93 Annex A Controls

ISO 27001 Self-Assessment, Free and Online

Find out how ready your organization really is. Work through the full ISO/IEC 27001:2022 control set, get an instant security score with domain breakdown, and see exactly which gaps to fix first.

No credit card required · Save progress anytime · ~30–60 minutes

What Is an ISO 27001 Self-Assessment?

An ISO 27001 self-assessment is a structured review of how well your organization manages information security, based on the ISO/IEC 27001:2022 standard and its Annex A control set — 93 controls across four domains.

Unlike a certification audit, a self-assessment is something you can run yourself, today, without hiring external auditors. It answers one question clearly: where does our security posture stand, and what should we improve first?

It is also the most practical preparation step before a formal certification project: every gap you find now is one that won't surprise you during an audit later.

Assessment vs. Certification

  • Self-assessment: done by your team, free, identifies gaps and priorities
  • Certification audit: performed by an accredited certification body, required for the certificate itself
  • EvaluationCat prepares you for certification — it does not issue one

Your Result Preview

74/100

Good · ISO 27001 Readiness 68%

Organizational Controls82%
People Controls75%
Physical Controls68%
Technological Controls85%

Example result. Every control is scored on a five-level maturity scale, weighted by importance — see scoring methodology.

The 93 Controls, in Four Domains

Every Annex A control is covered — nothing skipped, nothing simplified into a checkbox quiz.

37

Organizational Controls

Policies, roles, asset management, supplier relationships, and incident planning — the management layer of your ISMS.

8

People Controls

Screening, security awareness, remote working, and disciplinary processes that govern how people handle information.

14

Physical Controls

Secure areas, equipment protection, clear desk rules, and monitoring of physical premises.

34

Technological Controls

Access control, cryptography, logging, network security, secure development, and vulnerability management.

How the Assessment Works

Four steps from sign-up to an actionable improvement plan

01

Create your workspace

Sign up and add basic company information.

02

Answer guided questions

Complete control questions based on your reality.

03

Review your report

Get scores, gaps, and risk insights instantly.

04

Plan and track improvements

Follow recommendations and re-assess regularly.

What You Get

Not just a score — a complete path from assessment to remediation

Security Score

Weighted score across all four domains with ISO 27001 readiness percentage.

Gap Analysis

Every missing or partial control listed with severity and framework mapping.

AI Remediation

Concrete fix guidance per gap — steps, tools, cost, effort — not generic advice.

30/90/180-Day Plan

A prioritized roadmap telling you what to fix first, next, and long-term.

Free tier: the full 93-control assessment, instant scoring, gap summary, and basic PDF report are free. Upgrade to Pro ($49 one-time) only if you want the AI remediation plan and implementation roadmap. See pricing.

Know Your ISO 27001 Readiness Today

Free, structured, and mapped to the real standard. Start now, finish whenever you're ready.

Start Free Assessment
    Feedback
    Back to Top