The checklist, the scoring scale, the five steps and what the finished ISO 27001 gap analysis report should contain.
An ISO 27001 gap analysis compares how your organisation handles information security today with every requirement of ISO/IEC 27001:2022, then lists what is missing. It covers the mandatory management clauses 4 to 10 and all 93 Annex A controls, scores each one, and turns the gaps into a prioritised plan. For a small organisation of 5 to 50 people, one person who knows the business can run an ISO 27001 gap analysis in about five to eight working days, without a consultant.
An ISO 27001 gap analysis is a one-off assessment, done before you start implementing, that measures your current information security practice against ISO/IEC 27001:2022, the standard maintained by ISO/IEC JTC 1/SC 27. The output is a list of requirements you already meet, requirements you partly meet, and requirements you do not meet at all, each with the evidence behind the judgement.
ISO/IEC 27001 does not require a gap analysis, and no certification auditor will ask to see one. Teams run an ISO 27001 gap analysis because it is the cheapest way to answer two questions: how much work is there, and where do we start.
An ISO 27001 gap analysis checklist has two halves. The first is the management system, clauses 4 to 10 of ISO/IEC 27001:2022, which are mandatory in full. The second is Annex A, the reference list of 93 controls, which you assess for applicability as well as implementation.
| Area | What the gap analysis checks | Requirements |
|---|---|---|
| Clause 4, Context | Internal and external issues, interested parties, the ISMS scope | 4.1 to 4.4, all mandatory |
| Clause 5, Leadership | Top management commitment, the information security policy, roles | 5.1 to 5.3, all mandatory |
| Clause 6, Planning | Risk assessment and treatment method, objectives, planning of changes | 6.1 to 6.3, all mandatory |
| Clause 7, Support | Resources, competence, awareness, communication, document control | 7.1 to 7.5, all mandatory |
| Clause 8, Operation | Running the risk assessment and treatment plan in practice | 8.1 to 8.3, all mandatory |
| Clause 9, Performance evaluation | Monitoring and measurement, internal audit, management review | 9.1 to 9.3, all mandatory |
| Clause 10, Improvement | Continual improvement, nonconformity and corrective action | 10.1 to 10.2, all mandatory |
| Annex A theme 5, Organisational | Policies, asset inventory, supplier security, incident management | 37 controls |
| Annex A theme 6, People | Screening, terms of employment, awareness training, remote working | 8 controls |
| Annex A theme 7, Physical | Secure areas, equipment, clear desk, secure disposal | 14 controls |
| Annex A theme 8, Technological | Access, MFA, logging, backup, vulnerability and change management | 34 controls |
Clauses 4 to 10 are where small organisations usually find the biggest ISO 27001 gaps. A ten-person software company often has MFA, backups and logging already. What it rarely has is a documented scope, a risk assessment method, measurable security objectives, an internal audit or a management review, and the certification auditor looks for every one. Since the 2024 amendment to ISO/IEC 27001, clauses 4.1 and 4.2 also ask whether climate change is a relevant issue, so include that line in the checklist.
Score an ISO 27001 gap analysis on a four-point scale that maps directly to the work needed. Five-level maturity models invite long debates about whether something is a 2 or a 3, and a certification auditor does not grade maturity. The auditor asks whether the requirement is met and whether you can show it.
| Score | Meaning | Typical action |
|---|---|---|
| 0, Not in place | No practice and no evidence | Design and implement, then generate evidence |
| 1, Partial | Happens informally, or documented but not followed | Write it down or start doing it consistently |
| 2, In place | Documented, followed, and evidence exists | Keep the evidence current |
| N/A, Not applicable | Annex A control excluded, with a reason | Record the justification in the Statement of Applicability |
N/A is only valid for Annex A controls, because every requirement in clauses 4 to 10 applies to every organisation seeking certification. Each Annex A exclusion needs a written justification, which later goes straight into your Statement of Applicability.
Run an ISO 27001 gap analysis in five steps, in this order, because the scope decides which Annex A controls apply.
The effort figures below are planning estimates for one owner in a small organisation, not measured averages. A larger scope takes longer.
| Step | Output | Estimated effort, 5 to 50 people |
|---|---|---|
| 1. Scope | Draft ISMS scope statement | 0.5 days |
| 2. Clauses 4 to 10 | Score for every mandatory requirement | 1 to 2 days |
| 3. Annex A | Applicability and score for 93 controls | 2 to 3 days |
| 4. Evidence review | Evidence reference for each in-place score | 1 to 1.5 days |
| 5. Report and plan | Prioritised remediation plan with owners | 0.5 to 1 day |
| Total | 5 to 8 working days |
An ISO 27001 gap analysis report should be short enough for management to read and specific enough for the team to work from. It contains six things:
Put the clause 4 to 10 gaps at the top of the remediation plan. A certification body's stage 1 audit checks the management system documentation first, so a missing risk assessment, internal audit or management review can stop the audit before Annex A is examined in depth.
An ISO 27001 gap analysis is often confused with two activities the standard does require.
| Gap analysis | Risk assessment | Internal audit | |
|---|---|---|---|
| Required by ISO 27001? | No | Yes, clauses 6.1.2 and 8.2 | Yes, clause 9.2 |
| When | Once, before implementation | At planned intervals and on significant change | At planned intervals, and before the stage 2 audit |
| Question it answers | What is missing against the standard? | What could go wrong to our information? | Does the ISMS conform and work? |
| Who can do it | Anyone, including a consultant | The organisation, using a defined method | An auditor independent of the work audited |
In short, the ISO 27001 gap analysis tells you what to build, the risk assessment tells you which controls you need and why, and the internal audit checks that what you built works. A certification body can run a pre-assessment, but under ISO/IEC 17021-1 it cannot advise you how to close the gaps it finds.
An ISO 27001 gap analysis costs either staff time or a consultant's fee, and the effort is similar either way: about five to eight working days for a small organisation.
None of those figures includes the certification audit itself, which an accredited certification body charges for separately. What ISO 27001 certification costs breaks that down. You can check whether a certification body is accredited through the International Accreditation Forum.
CertAssist lays out the ISO 27001 management clauses and all 93 Annex A controls on one board, with documentation and evidence checklists for each control and editable policy templates, so the board becomes the gap analysis and then the remediation plan in the same place. CertAssist handles the Statement of Applicability, and the auditor gets read-only access when you are ready.
CertAssist does not connect to your systems, by design. That means nothing to breach, but it also means CertAssist will not scan your cloud accounts and find technical gaps for you. If you run hundreds of people across many cloud accounts and want continuous automated monitoring, an integrated platform or a consultant-led assessment is the better fit.
CertAssist lays out every ISO 27001 clause and Annex A control with editable policy and evidence templates, for a flat $225 a month. No integrations, so nothing to connect.
See pricing FrameworksWhat is an ISO 27001 gap analysis?
An ISO 27001 gap analysis is a structured comparison of how your organisation manages information security today against the requirements of ISO/IEC 27001:2022. It covers the mandatory clauses 4 to 10 and the 93 Annex A controls, scores each one, and produces a prioritised list of the work needed before a certification audit. The standard does not require one, but most first-time projects start with it.
How do you perform an ISO 27001 gap analysis?
To perform an ISO 27001 gap analysis, fix the scope first, then walk every requirement in clauses 4 to 10 and every Annex A control. For each one, record what exists today, the evidence that proves it, and a score: not in place, partial, in place or not applicable. Finish by ranking the gaps by audit impact and effort, and give each one an owner and a date.
What should an ISO 27001 gap analysis report include?
An ISO 27001 gap analysis report should include the scope assessed, the date and who carried it out, a score for every clause requirement and Annex A control, the evidence seen for each, and a summary count of gaps by area. Most importantly it needs a prioritised remediation plan with an owner and target date for each gap, because that plan becomes the project plan for certification.
How much does an ISO 27001 gap analysis cost?
An ISO 27001 gap analysis run in-house costs mainly staff time, typically five to eight working days for a small organisation with one owner who knows the business. A consultant-led ISO 27001 gap analysis costs the consultant's day rate multiplied by a similar number of days, so ask for a fixed quote. Free spreadsheets and tools exist, and CertAssist costs US$225 per month as of October 2026.
Is there an ISO 27001 gap analysis template or checklist?
Yes. The simplest ISO 27001 gap analysis template is a checklist with one row per requirement: the 7 mandatory clauses broken into their sub-clauses, then the 93 Annex A controls grouped into 37 organisational, 8 people, 14 physical and 34 technological controls. Add columns for current state, evidence, score, owner and target date. The checklist in this guide shows that structure.
Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.