Assessment 08
ISO/IEC 27001 Annex A Readiness
A readiness and gap self-assessment across the four Annex A:2022 control themes of ISO/IEC 27001. It shows your reported coverage and highlights possible links to NIS2, IEC 62443 and CRA requirements. Each link and its supporting evidence need separate review before being treated as covered.
- Length
- 12–16 minutes
- Questions
- 36 questions
What it covers
- Annex A.5 organizational controls (policy, supplier, incident, continuity)
- Annex A.6 people controls (screening, awareness, remote working)
- Annex A.7 physical controls (perimeter, equipment, media)
- Annex A.8 technological controls (access, crypto, logging, backup)
- The foundational controls that cap the readiness band
- Crosswalk to NIS2 Article 21(2) management measures
- Crosswalk to IEC 62443-4-1 and CRA technical obligations
Built for
Information security managers, ISMS owners, compliance leads, and manufacturers facing customer 27001 requirements
What you get back
A readiness score with a per-theme profile, a prioritised gap list linked to Annex A:2022 controls, a flag where a foundational control caps the band, and a crosswalk pointing to NIS2, IEC 62443 and CRA requirements where the same evidence may be relevant. Each link needs review before it can support a compliance claim.
Complete the questionnaire
Answer based on the controls operating within your organisation’s ISMS scope today, not those you plan to introduce. A realistic baseline makes the gap list useful.
No email address. No registration. No account.
You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.
ISO/IEC 27001:2022 Annex A Readiness Assessment
Thirty-six questions sampled across the four Annex A:2022 control themes — Organizational, People, Physical, and Technological. You get a readiness score per theme, a prioritised gap list keyed to the Annex A controls, and a crosswalk to related NIS2, IEC 62443 and CRA requirements for separate review.
Your answers are kept in this browser tab while you work, so a reload will not lose them. Closing the tab clears them.
Other assessments
Assessment 01
Product Classification Check
A short triage questionnaire that gives an initial indication of whether your product may fall within the CRA and, if so, which product category may apply. Check the indication against your product details and the regulation before choosing a conformity assessment route.
OpenAssessment 02
CRA Readiness Assessment
A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the Article 14 reporting obligations that apply from 11 September 2026 and the Annex I Part II vulnerability-handling requirements that apply from 11 December 2027.
OpenAssessment 03
SBOM Readiness Assessment
A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.
OpenAssessment 04
IEC 62443-4-1 Gap Assessment
A practice-by-practice self-assessment against the eight practices of IEC 62443-4-1. Based on your answers, it provides an indicative maturity profile and highlights areas where evidence needs closer review before an audit.
OpenAssessment 05
IEC 62443-4-2 Component Gap Assessment
The technical counterpart to the 62443-4-1 process assessment: a self-assessment against the shared component requirements of IEC 62443-4-2. Based on your answers, it shows an indicative capability security level (SL-C 1–4) for each of the seven foundational requirements; these results have not been independently verified.
OpenAssessment 06
NIS2 Scoping Check
A preliminary scoping check for operators, not a maturity score. It uses your answers on sector, size, and exceptions to indicate whether your organisation may fall within NIS2 and whether it may be an essential or important entity. Confirm the result under the applicable national law.
OpenAssessment 07
RED Cybersecurity Readiness
A readiness assessment against the cybersecurity requirements the Radio Equipment Directive makes mandatory, as harmonised by EN 18031. It scores the network-protection, personal-data, and fraud-prevention objectives of RED Article 3.3 (d), (e) and (f) that apply to internet-connected radio equipment — much of the same connected hardware the CRA already reaches.
Open