Resources
Fillable Excel workbooks and Word documents your team actually uses - not static PDFs. The same templates we run on live engagements across ISO 27001, SOC 2, DORA, NIS2, GDPR, CMMC, NIST CSF and ISO 42001. Filter by framework, tell us where to send it, and it is yours.
A structured self-check across scope, risk, SoA, evidence, access, suppliers, incidents and governance - score each item Yes / Partly / No and see where an auditor will dig.
What's inside
See what's inside, then get the .xlsx by email.
Readiness against the AICPA Trust Services Criteria: the mandatory Common Criteria (Security) plus optional Availability, Confidentiality, Processing Integrity and Privacy. Covers Type I vs Type II and the operating-over-time evidence a service auditor actually tests.
What's inside
See what's inside, then get the .xlsx by email.
For financial entities in scope of DORA (applied 17 January 2025): ICT risk, incident classification and reporting, the Register of Information, resilience testing and third-party risk - the evidence a supervisor asks for.
What's inside
See what's inside, then get the .xlsx by email.
Find out if NIS2 is even yours before you build anything. The two gates - the size threshold and the Article 6(30) cloud test - worked through step by step, with the reporting duties if you are in.
What's inside
See what's inside, then get the .xlsx by email.
A defensible record of subject requests plus a retention schedule - the audit trail a regulator and an ISO auditor both want when you handle sensitive personal data.
What's inside
See what's inside, then get the .xlsx by email.
For US defense supply-chain organisations handling FCI or CUI: CMMC Level 1 (FAR 52.204-21) and Level 2 (the 110 NIST SP 800-171 requirements), with SSP and POA&M. Score each item and see where a C3PAO assessor will push.
What's inside
See what's inside, then get the .xlsx by email.
Map your existing evidence to the six CSF 2.0 functions - Govern, Identify, Protect, Detect, Respond, Recover. NIST CSF is voluntary and not certifiable; this shows coverage and gaps in the vocabulary a US buyer uses.
What's inside
See what's inside, then get the .xlsx by email.
Structured to ISO 42001's Annex A (38 controls, 9 groups). Covers the AI impact assessment (clauses 6.1.4 / 8.4) that sets 42001 apart from ISO 27001 - impact on third parties and society, not just risk to you.
What's inside
See what's inside, then get the .xlsx by email.
One source of truth so every team answers consistently. Canonical answer, evidence reference and owner per question - so the next questionnaire gets faster, not harder.
What's inside
See what's inside, then get the .xlsx by email.
The single artifact that decides most audits: control by control, what evidence proves it, who owns it, its quality and what is missing. The exact structure we use on real work.
What's inside
See what's inside, then get the .xlsx by email.
The Article 30 record at the backbone of a privacy programme and an ISO 27701 PIMS: activity, purpose, lawful basis, categories, recipients, transfers and retention - with worked example rows.
What's inside
See what's inside, then get the .xlsx by email.
For already-certified teams: what to confirm before the surveillance auditor arrives - prior findings, evidence freshness, drift since certification and governance.
What's inside
See what's inside, then get the .xlsx by email.
Built around a broker's real stack - MT4/MT5, IB and affiliate portals, PSPs, KYC, withdrawals and vendor access. Name the evidence an auditor will ask for, and the gap.
What's inside
See what's inside, then get the .xlsx by email.
If you already run PCI DSS, most evidence carries over. Map each PCI area to ISO 27001 Annex A, mark what is reusable, and focus on the genuine ISO-specific gaps.
What's inside
See what's inside, then get the .xlsx by email.
A working clause 9.3 template that turns the management review from a formality into a record of real decisions - the required inputs, an agenda, and a decisions table.
What's inside
See what's inside, then get the .docx by email.
A template for a defensible internal audit (clause 9.2), with an independence statement, a findings table and a conclusion - the audit that must happen before Stage 2.
What's inside
See what's inside, then get the .docx by email.
A readiness report, evidence map, gap tracker, control mapping, management review pack and a 30/60/90 roadmap - illustrative and anonymized, with real structure.
Go deeper
Each hub explains where the standard applies, what readiness involves and how Kellwick prepares you.
Take the free readiness self-assessment for an indicative score and next step in two minutes - or tell us which audit, regulator or customer raised the bar and see how we help.