Annual Company Questionnaire
Please complete as part of your maintenance for Certification
Company Name
*
Audit Type
*
Please Select
Surveillance Audit
Recertification
Change in Scope
Name
*
First Name
Last Name
Email address
*
example@example.com
Phone Number
*
-
Country Code
-
Area Code
Phone Number
Virtual Workforce
*
Yes
No
Changes Requested
No Changes
Changes Requested
Current Certification(s)
ISO/IEC 27001:2022
ISO/IEC 27017:2022
ISO/IEC 27018:2019
ISO/IEC 27018:2025
ISO/IEC 27701:2019
ISO/IEC 42001:2023
Have any of the following changed:
Registered address
Business Name
Business Ownership
Scope Statement
Number of Workers
Location Details
Business services, complexity, outsourcing, technology & etc.
Other (explain below)
Update Address for Certificate
*
Street
Street 2
City
State / Province
Postal / Zip Code
Please Select
Afghanistan
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antigua and Barbuda
Argentina
Armenia
Aruba
Australia
Austria
Azerbaijan
The Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bermuda
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Brazil
Brunei
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Canada
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Congo
Cook Islands
Costa Rica
Cote d'Ivoire
Croatia
Cuba
Curaçao
Cyprus
Czech Republic
Democratic Republic of the Congo
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands
Faroe Islands
Fiji
Finland
France
French Polynesia
Gabon
The Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Honduras
Hong Kong
Hungary
Iceland
India
Indonesia
Iran
Iraq
Ireland
Israel
Italy
Jamaica
Japan
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
North Korea
South Korea
Kosovo
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia
Moldova
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Nagorno-Karabakh
Namibia
Nauru
Nepal
Netherlands
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Turkish Republic of Northern Cyprus
Northern Mariana
Norway
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn Islands
Poland
Portugal
Puerto Rico
Qatar
Republic of the Congo
Romania
Russia
Rwanda
Saint Barthelemy
Saint Helena
Saint Kitts and Nevis
Saint Lucia
Saint Martin
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
Somaliland
South Africa
South Ossetia
South Sudan
Spain
Sri Lanka
Sudan
Suriname
Svalbard
eSwatini
Sweden
Switzerland
Syria
Taiwan
Tajikistan
Tanzania
Thailand
Timor-Leste
Togo
Tokelau
Tonga
Transnistria Pridnestrovie
Trinidad and Tobago
Tristan da Cunha
Tunisia
Turkey
Turkmenistan
Turks and Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United Kingdom
United States
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
British Virgin Islands
Isle of Man
US Virgin Islands
Wallis and Futuna
Western Sahara
Yemen
Zambia
Zimbabwe
Other
Country
Please Provide the New Business Name and Reason for the Change
Please Details for the Changes in Ownership
Update Scope Statement
Update Number of Locations in Scope
*
If you have indicated a virtual workforce, this should be 1 indicating the address used on the certificate.
Update Workers in Scope
*
We need to know the number of workers in scope of the certification to determine the appropriate number of days (this might not be all workers in the organization).
Update Site Details - please explain in the comments (new, expanded, closed)
Changes in Complexity
*
Please Select
No Changes
Low sensitivity, confidentiality, and availability requirements
Moderate sensitivity, confidentiality, and availability requirements
High sensitivity, confidentiality, and availability requirements
Business and Customer information
*
Please Select
No Changes
Has customers in critical business sectors
Works in critical business sectors
Works in non-critical business sectors
Critical business sectors include financial, public services/utilities or medical services. This is used to determine the impact and risks associated with your information security program.
Changes in Technology Used
*
Please Select
No Changes
Industry standard technologies used cloud-based services
Industry standard technologies with combination of on-premise and cloud-based services
Complex/proprietary technologies with diverse processes and on-premise platform
This is used to ensure we have qualified auditors who understand the technologies in place.
Changes in Outsourced Services Used
*
Please Select
No Changes
No outsourcing for in-scope services
Some outsourcing arrangements for key business functions
High dependency on outsourcing or suppliers with large impact on important business activities
Please indicate the outsourcing arrangements used to deliver services in the scope of the ISMS
Changes in Development Activities
*
Please Select
No Changes
None or very little internal development
Some internal development or highly customizable software used
Extensive internal software development activities
Please let us know the extend of your development activities in scope.
Changes in Availability Requirements
*
Please Select
No Changes
Low availability requirements - System availability is not critical
Moderate requirements achieved through redundancy or similar technology
High availability requirements with redundancy across geographical locations
Please let us know the availability requirements your system is working under.
Have you received any of the following:
Regulatory notices and correspondence, including communications with government authorities or regulatory bodies regarding ISMS compliance and notifications related to legal changes impacting security policies
Vendor and supplier agreements, such as security-related contracts or service-level agreements (SLAs) with third-party providers and risk assessment reports from external audits conducted by vendors
Incident reports and notifications, including breach reports submitted to authorities or affected parties and internal and external security incident notifications and responses
Customer and stakeholder requests, such as information security queries, complaints, or risk disclosures from customers and compliance inquiries regarding data protection and security certifications
Audit and certification communications, including exchanges with certification bodies regarding audit requirements, findings, or corrective actions and formal submissions of documentation required for certification reviews
Describe additional changes to the certification
Attachment(s)
Browse Files
Drag and drop files here
Choose a file
Cancel
of
Submit
Should be Empty: