A gap analysis is the standard first move toward ISO 27001 certification: a structured comparison between what your information security management system (ISMS) looks like today and what the standard requires. Done properly, it produces the three artifacts every certification project needs — a clause-by-clause compliance score, a prioritized remediation roadmap, and a realistic timeline estimate.
Gap Analysis vs. Risk Assessment vs. Internal Audit
These three exercises are often confused, but they answer different questions:
- Gap analysis — "How far are we from meeting the standard?" Done before implementation, usually once.
- Risk assessment — "What could go wrong, and which controls treat which risks?" A mandatory ISO 27001 clause (6.1.2) that feeds the Statement of Applicability.
- Internal audit — "Does our implemented ISMS actually work?" A recurring clause 9.2 requirement once the system exists.
The gap analysis comes first: it tells you whether you need a full ISMS build-out or a targeted remediation effort, and it scopes the risk assessment that follows.
The Five Steps of an ISO 27001 Gap Analysis
- Define the scope. Which business units, systems, and locations are in? Scope creep is the most common reason gap analyses stall — be explicit about what is out of scope.
- Inventory the current state. Collect existing policies, procedures, org charts, contracts, technical configurations, and prior audit findings. You cannot score what you haven't documented.
- Assess clause by clause. Work through clauses 4–10 (context, leadership, planning, support, operation, performance evaluation, improvement) and the Annex A controls. For each requirement, mark it implemented, partially implemented, or absent — and record the evidence.
- Score and prioritize. Convert findings into a compliance percentage per clause, then rank gaps by certification impact and remediation effort. Not every gap is equal: a missing risk assessment methodology blocks certification; a lightly documented supplier policy does not.
- Build the remediation roadmap. Sequence the fixes, assign owners, and set dates. This roadmap is what turns a gap analysis from a report into a project plan.
What a Good Gap Analysis Report Contains
Whether the assessment is done by a consultant or in-house, the deliverable should include: an executive summary for leadership, a clause-by-clause maturity score, an evidence log for each rating, the prioritized remediation list, and a rough effort estimate. Auditors and management both read these reports — a PDF export you can circulate and archive matters more than a spreadsheet that lives on one laptop.
Our free ISO 27001 Gap Assessment tool walks you through the clauses and Annex A controls in a structured questionnaire, scores your compliance percentage per area, and generates a PDF report you can share with leadership — entirely in your browser, so no security data leaves your machine.
DIY or Consultant?
For small teams with a modern SaaS stack, a structured self-assessment is usually sufficient for a first pass — you know where your skeletons are. Bring in a consultant when the scope spans multiple entities, when you need an independent baseline for the board, or when the gap analysis will directly feed a certified audit within 6 months. Either way, running a self-assessment first makes the paid work cheaper and faster.
After the Gap Analysis
The natural next steps: conduct the formal risk assessment, draft the Statement of Applicability, close the priority gaps, then schedule internal audit and management review (clauses 9.2/9.3) before certification. If your organization also handles AI systems, consider running our ISO/IEC 42001 AI Readiness Assessment in parallel — the management-system scaffolding largely overlaps, and our ISO 42001 implementation guide explains how the two standards complement each other.
Frequently Asked Questions
How long does an ISO 27001 gap analysis take?
A focused self-assessment takes 2–4 hours with a structured questionnaire. A consultant-led analysis for a mid-size company typically runs 2–4 weeks including document review and interviews.
What is the difference between a gap analysis and a gap assessment?
The terms are used interchangeably. "Gap analysis" emphasizes the comparison methodology; "gap assessment" emphasizes the scoring deliverable. Both measure distance from ISO 27001 conformity.
Do I need a gap analysis before certification?
It is not a formal requirement, but skipping it is the most common cause of failed Stage 1 audits. Certification bodies expect you to arrive with a working ISMS — the gap analysis is how you find out whether you have one.
Can I get a gap analysis report as a PDF?
Yes. Our ISO 27001 Gap Assessment tool generates a downloadable PDF report with per-clause scores and remediation priorities, free and browser-based.




