ISO 27001

ISO 27001 gap analysis: how to run one, with a checklist

2 October 2026 · 9 min read · CertAssist

The checklist, the scoring scale, the five steps and what the finished ISO 27001 gap analysis report should contain.

An ISO 27001 gap analysis compares how your organisation handles information security today with every requirement of ISO/IEC 27001:2022, then lists what is missing. It covers the mandatory management clauses 4 to 10 and all 93 Annex A controls, scores each one, and turns the gaps into a prioritised plan. For a small organisation of 5 to 50 people, one person who knows the business can run an ISO 27001 gap analysis in about five to eight working days, without a consultant.

Chart of what an ISO 27001 gap analysis must cover: the 7 mandatory clauses 4 to 10, then the 93 Annex A controls split into 37 organisational, 8 people, 14 physical and 34 technological controls

What is an ISO 27001 gap analysis?

An ISO 27001 gap analysis is a one-off assessment, done before you start implementing, that measures your current information security practice against ISO/IEC 27001:2022, the standard maintained by ISO/IEC JTC 1/SC 27. The output is a list of requirements you already meet, requirements you partly meet, and requirements you do not meet at all, each with the evidence behind the judgement.

ISO/IEC 27001 does not require a gap analysis, and no certification auditor will ask to see one. Teams run an ISO 27001 gap analysis because it is the cheapest way to answer two questions: how much work is there, and where do we start.

What does an ISO 27001 gap analysis checklist cover?

An ISO 27001 gap analysis checklist has two halves. The first is the management system, clauses 4 to 10 of ISO/IEC 27001:2022, which are mandatory in full. The second is Annex A, the reference list of 93 controls, which you assess for applicability as well as implementation.

AreaWhat the gap analysis checksRequirements
Clause 4, ContextInternal and external issues, interested parties, the ISMS scope4.1 to 4.4, all mandatory
Clause 5, LeadershipTop management commitment, the information security policy, roles5.1 to 5.3, all mandatory
Clause 6, PlanningRisk assessment and treatment method, objectives, planning of changes6.1 to 6.3, all mandatory
Clause 7, SupportResources, competence, awareness, communication, document control7.1 to 7.5, all mandatory
Clause 8, OperationRunning the risk assessment and treatment plan in practice8.1 to 8.3, all mandatory
Clause 9, Performance evaluationMonitoring and measurement, internal audit, management review9.1 to 9.3, all mandatory
Clause 10, ImprovementContinual improvement, nonconformity and corrective action10.1 to 10.2, all mandatory
Annex A theme 5, OrganisationalPolicies, asset inventory, supplier security, incident management37 controls
Annex A theme 6, PeopleScreening, terms of employment, awareness training, remote working8 controls
Annex A theme 7, PhysicalSecure areas, equipment, clear desk, secure disposal14 controls
Annex A theme 8, TechnologicalAccess, MFA, logging, backup, vulnerability and change management34 controls

Clauses 4 to 10 are where small organisations usually find the biggest ISO 27001 gaps. A ten-person software company often has MFA, backups and logging already. What it rarely has is a documented scope, a risk assessment method, measurable security objectives, an internal audit or a management review, and the certification auditor looks for every one. Since the 2024 amendment to ISO/IEC 27001, clauses 4.1 and 4.2 also ask whether climate change is a relevant issue, so include that line in the checklist.

How do you score an ISO 27001 gap analysis?

Score an ISO 27001 gap analysis on a four-point scale that maps directly to the work needed. Five-level maturity models invite long debates about whether something is a 2 or a 3, and a certification auditor does not grade maturity. The auditor asks whether the requirement is met and whether you can show it.

ScoreMeaningTypical action
0, Not in placeNo practice and no evidenceDesign and implement, then generate evidence
1, PartialHappens informally, or documented but not followedWrite it down or start doing it consistently
2, In placeDocumented, followed, and evidence existsKeep the evidence current
N/A, Not applicableAnnex A control excluded, with a reasonRecord the justification in the Statement of Applicability

N/A is only valid for Annex A controls, because every requirement in clauses 4 to 10 applies to every organisation seeking certification. Each Annex A exclusion needs a written justification, which later goes straight into your Statement of Applicability.

How to perform an ISO 27001 gap analysis, step by step

Run an ISO 27001 gap analysis in five steps, in this order, because the scope decides which Annex A controls apply.

Bar chart of the estimated effort for each step of an ISO 27001 gap analysis in a small organisation: scope 0.5 days, clauses 4 to 10 for 1 to 2 days, Annex A controls for 2 to 3 days, evidence review for 1 to 1.5 days, and the prioritised report for 0.5 to 1 day, 5 to 8 working days in total

The effort figures below are planning estimates for one owner in a small organisation, not measured averages. A larger scope takes longer.

StepOutputEstimated effort, 5 to 50 people
1. ScopeDraft ISMS scope statement0.5 days
2. Clauses 4 to 10Score for every mandatory requirement1 to 2 days
3. Annex AApplicability and score for 93 controls2 to 3 days
4. Evidence reviewEvidence reference for each in-place score1 to 1.5 days
5. Report and planPrioritised remediation plan with owners0.5 to 1 day
Total 5 to 8 working days

What should an ISO 27001 gap analysis report include?

An ISO 27001 gap analysis report should be short enough for management to read and specific enough for the team to work from. It contains six things:

Put the clause 4 to 10 gaps at the top of the remediation plan. A certification body's stage 1 audit checks the management system documentation first, so a missing risk assessment, internal audit or management review can stop the audit before Annex A is examined in depth.

ISO 27001 gap analysis vs risk assessment vs internal audit

An ISO 27001 gap analysis is often confused with two activities the standard does require.

 Gap analysisRisk assessmentInternal audit
Required by ISO 27001?NoYes, clauses 6.1.2 and 8.2Yes, clause 9.2
WhenOnce, before implementationAt planned intervals and on significant changeAt planned intervals, and before the stage 2 audit
Question it answersWhat is missing against the standard?What could go wrong to our information?Does the ISMS conform and work?
Who can do itAnyone, including a consultantThe organisation, using a defined methodAn auditor independent of the work audited

In short, the ISO 27001 gap analysis tells you what to build, the risk assessment tells you which controls you need and why, and the internal audit checks that what you built works. A certification body can run a pre-assessment, but under ISO/IEC 17021-1 it cannot advise you how to close the gaps it finds.

How much does an ISO 27001 gap analysis cost?

An ISO 27001 gap analysis costs either staff time or a consultant's fee, and the effort is similar either way: about five to eight working days for a small organisation.

None of those figures includes the certification audit itself, which an accredited certification body charges for separately. What ISO 27001 certification costs breaks that down. You can check whether a certification body is accredited through the International Accreditation Forum.

Where CertAssist fits, and where it does not

CertAssist lays out the ISO 27001 management clauses and all 93 Annex A controls on one board, with documentation and evidence checklists for each control and editable policy templates, so the board becomes the gap analysis and then the remediation plan in the same place. CertAssist handles the Statement of Applicability, and the auditor gets read-only access when you are ready.

CertAssist does not connect to your systems, by design. That means nothing to breach, but it also means CertAssist will not scan your cloud accounts and find technical gaps for you. If you run hundreds of people across many cloud accounts and want continuous automated monitoring, an integrated platform or a consultant-led assessment is the better fit.

Run your ISO 27001 gap analysis on a board that is already built

CertAssist lays out every ISO 27001 clause and Annex A control with editable policy and evidence templates, for a flat $225 a month. No integrations, so nothing to connect.

See pricing Frameworks

Frequently asked questions about ISO 27001 gap analysis

What is an ISO 27001 gap analysis?
An ISO 27001 gap analysis is a structured comparison of how your organisation manages information security today against the requirements of ISO/IEC 27001:2022. It covers the mandatory clauses 4 to 10 and the 93 Annex A controls, scores each one, and produces a prioritised list of the work needed before a certification audit. The standard does not require one, but most first-time projects start with it.

How do you perform an ISO 27001 gap analysis?
To perform an ISO 27001 gap analysis, fix the scope first, then walk every requirement in clauses 4 to 10 and every Annex A control. For each one, record what exists today, the evidence that proves it, and a score: not in place, partial, in place or not applicable. Finish by ranking the gaps by audit impact and effort, and give each one an owner and a date.

What should an ISO 27001 gap analysis report include?
An ISO 27001 gap analysis report should include the scope assessed, the date and who carried it out, a score for every clause requirement and Annex A control, the evidence seen for each, and a summary count of gaps by area. Most importantly it needs a prioritised remediation plan with an owner and target date for each gap, because that plan becomes the project plan for certification.

How much does an ISO 27001 gap analysis cost?
An ISO 27001 gap analysis run in-house costs mainly staff time, typically five to eight working days for a small organisation with one owner who knows the business. A consultant-led ISO 27001 gap analysis costs the consultant's day rate multiplied by a similar number of days, so ask for a fixed quote. Free spreadsheets and tools exist, and CertAssist costs US$225 per month as of October 2026.

Is there an ISO 27001 gap analysis template or checklist?
Yes. The simplest ISO 27001 gap analysis template is a checklist with one row per requirement: the 7 mandatory clauses broken into their sub-clauses, then the 93 Annex A controls grouped into 37 organisational, 8 people, 14 physical and 34 technological controls. Add columns for current state, evidence, score, owner and target date. The checklist in this guide shows that structure.

← Back to the blog

Powerful in its simplicity.

Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.