
The most expensive moment to discover a gap in your ISO 27001 preparation is during a formal pre-assessment or certification audit.
This session exists to find those gaps first.
Bring your current documentation — scope definition, risk register, policy suite, evidence records — and I'll give you an honest, experienced assessment of where you stand and what an auditor will likely flag.
As an ISO/IEC 27001:2022 Lead Auditor, I know exactly what certification auditors look for — and what commonly documented programs miss at the evidence stage.
What we'll cover:
→ Review of your scope definition and whether it reflects real risk
→ Assessment of your risk register — is it asset-based or generic?
→ Evidence readiness check — proof that processes are followed, not just documented
→ Management review status — one of the most commonly failed clauses
→ Supplier and third-party control gaps
→ A frank assessment: are you 30 days from certification or 6 months?
You'll walk away with:
✔ A clear list of what to fix before your formal audit
✔ Priority-ordered actions by urgency and effort
✔ An honest timeline based on your actual current state
Available in Arabic and English.
Suitable for: IT Managers, CISOs, and GRC professionals preparing for ISO 27001 certification