Free ISO 27001 checklist for website owners

30 questions. Ten minutes. How fortified is your website, really?

Tick each statement that's true for your site today. Be honest: nobody sees your answers unless you choose to send us your score.

The checklist

Built on ISO/IEC 27001:2022 and ISO 9001:2015, written in plain English for the people who own websites, not for auditors. Three questions for each of the ten areas of the Hacker Fortified Standard.

Scope and ownership
Risk assessment
Access and passwords
Patching and configuration
Application security
Data protection and privacy
Suppliers and plugins
Backups and monitoring
Incident response
Sound operations
0 / 30

Tick each statement that is true for your site.

Send my score for a free review

Questions

About the checklist.

Is this an official ISO 27001 checklist?

No. It is our own plain-English checklist for website owners, based on the requirements of ISO/IEC 27001:2022 and ISO 9001:2015 that apply to a website. It doesn't reproduce the standard, and a score here isn't a certification, but it shows you quickly where the biggest gaps are.

What is a good score?

Thirty out of thirty is the goal, and very few sites get there on their own. Most sites we see land somewhere in the middle. The items you can't tick are your to-do list, and the ones in access, patching and application security are usually the most urgent.

What happens if I send you my score?

A person reads it, takes a quick look at your site from the outside, and replies in writing within one business day with the three risks we'd fix first. It's free, and there are no sales calls.