01
Describe your organization and what's in scope
Tell the tool what you build, the stack you run on, the data you hold, and which teams, products, and systems belong inside your ISMS. The scope statement an auditor reads first is only as good as this input, so be concrete about inclusions and exclusions.
02
List your assets and the controls you already have
Paste a quick inventory of key systems and data stores, then describe what you already do for security — SSO, MFA, backups, access reviews, on-call. Honesty here matters: the assessment is more useful when it knows what's informal or missing.
03
Get a structured readiness package
In under a minute you receive a drafted ISMS scope, a risk register mapped to Annex A, an applicability assessment across all four control themes, a readiness score, and a prioritized remediation plan you can hand straight to your team.