Close
Before They Tell You
You have policy documents. You have security measures. What you don’t have is a straight answer to the question your customer, your regulator, or your certification body will eventually ask: is this actually good enough?
Take the 10-minute Management System Maturity Quiz and get a clear picture of where you stand against ISO 27001, NIS2, and AI Act requirements, before an auditor tells you the hard way.
10 minutes · Free · Results immediately
25+ years
Running certification programs and conducting ISO 27001 and ISO 9001 audits
3 frameworks
ISO 27001, NIS2 and the AI Act covered in one assessment
10 minutes
To a directional maturity score and your first priority areas
The real problem
Here’s a pattern that shows up in almost every mid-sized company facing a compliance deadline: someone in IT or security wrote a stack of policy documents, filled out a generic gap-assessment tool, and declared the job mostly done.
Then the tender requires ISO 27001 certification. Or NIS2 applies and nobody’s sure what “appropriate technical and organizational measures” actually means in practice. Or a customer’s due diligence questionnaire asks for evidence, not intentions.
Where it surfaces
A tender requires ISO 27001 certification.
NIS2 applies and “appropriate technical and organizational measures” stays undefined in practice.
A customer’s due diligence questionnaire asks for evidence, not intentions.
Suddenly the documents don’t matter. What matters is whether your management system produces evidence an auditor will accept. Most companies find out they don’t know the difference between having a policy and being audit-ready until it’s too late to fix it before the deadline.
Inside the assessment
This isn’t a lead-gen form disguised as a quiz. It’s a structured maturity assessment built from 25+ years running certification programs and conducting ISO 27001 and ISO 9001 audits.
You’ll answer questions covering:
Do you have defined roles, ownership and management review, or just a policy that says you should?
Is your risk assessment methodology something an auditor can trace, or a spreadsheet nobody updates?
Can you produce records on demand, or do you scramble when someone asks?
Are your controls operating consistently, or do they exist mostly on paper?
The return
01
Benchmarked against ISO 27001 and NIS2 expectations.
02
Showing exactly which areas will trip up an auditor first.
03
Of how far you are from certification, in months, not guesswork.
No credit card, no sales call required to see your results.
The cost of waiting
Waiting until an auditor or regulator points out the gap is the most expensive way to find out you have one.
€10M or 2%
NIS2 penalties reach €10M or 2% of global turnover.
Shortlists
ISO 27001 certification increasingly decides who gets shortlisted for tenders and who doesn’t.
€300K
One client unlocked €300K in additional business in a single market simply by getting certified before a competitor did.
Before you decide
Maybe. Writing a manual and passing an audit are different skills. Certification bodies aren’t grading your documentation effort, they’re grading whether your management system actually operates the way your documents claim. The quiz shows you where that gap sits before it costs you a finding.
The quiz is free and takes 10 minutes. You’ll have the maturity data ready before budget conversations even start, which makes the business case easier to build, not harder.
Questions before you start
Yes. No credit card, no sales call required to see your results.
No. It gives you a directional maturity score and priority areas. A formal gap assessment goes deeper and produces a certification-ready roadmap.
About 10 minutes.
You get your results immediately, plus the option to book a short call to walk through what the score means for your specific deadline.
Yes. The quiz maps to both frameworks, since the underlying management system requirements overlap significantly.
Stop guessing what “audit-ready” means. Get your maturity score and find out exactly where the gaps are, before a customer, regulator, or certification body finds them for you.
Free · 10 minutes · Immediate results