Logo
Standards · Compliance · Security

ISO 27001 Gap Analysis: A Step-by-Step Guide

26/09/2026
Padlock representing information security controls — ISO 27001 gap analysis

Image: "Internet Security Padlock" by mikemacmarketing, CC BY 2.0

A gap analysis is the standard first move toward ISO 27001 certification: a structured comparison between what your information security management system (ISMS) looks like today and what the standard requires. Done properly, it produces the three artifacts every certification project needs — a clause-by-clause compliance score, a prioritized remediation roadmap, and a realistic timeline estimate.

Gap Analysis vs. Risk Assessment vs. Internal Audit

These three exercises are often confused, but they answer different questions:

  • Gap analysis — "How far are we from meeting the standard?" Done before implementation, usually once.
  • Risk assessment — "What could go wrong, and which controls treat which risks?" A mandatory ISO 27001 clause (6.1.2) that feeds the Statement of Applicability.
  • Internal audit — "Does our implemented ISMS actually work?" A recurring clause 9.2 requirement once the system exists.

The gap analysis comes first: it tells you whether you need a full ISMS build-out or a targeted remediation effort, and it scopes the risk assessment that follows.

The Five Steps of an ISO 27001 Gap Analysis

  1. Define the scope. Which business units, systems, and locations are in? Scope creep is the most common reason gap analyses stall — be explicit about what is out of scope.
  2. Inventory the current state. Collect existing policies, procedures, org charts, contracts, technical configurations, and prior audit findings. You cannot score what you haven't documented.
  3. Assess clause by clause. Work through clauses 4–10 (context, leadership, planning, support, operation, performance evaluation, improvement) and the Annex A controls. For each requirement, mark it implemented, partially implemented, or absent — and record the evidence.
  4. Score and prioritize. Convert findings into a compliance percentage per clause, then rank gaps by certification impact and remediation effort. Not every gap is equal: a missing risk assessment methodology blocks certification; a lightly documented supplier policy does not.
  5. Build the remediation roadmap. Sequence the fixes, assign owners, and set dates. This roadmap is what turns a gap analysis from a report into a project plan.

What a Good Gap Analysis Report Contains

Whether the assessment is done by a consultant or in-house, the deliverable should include: an executive summary for leadership, a clause-by-clause maturity score, an evidence log for each rating, the prioritized remediation list, and a rough effort estimate. Auditors and management both read these reports — a PDF export you can circulate and archive matters more than a spreadsheet that lives on one laptop.

Our free ISO 27001 Gap Assessment tool walks you through the clauses and Annex A controls in a structured questionnaire, scores your compliance percentage per area, and generates a PDF report you can share with leadership — entirely in your browser, so no security data leaves your machine.

DIY or Consultant?

For small teams with a modern SaaS stack, a structured self-assessment is usually sufficient for a first pass — you know where your skeletons are. Bring in a consultant when the scope spans multiple entities, when you need an independent baseline for the board, or when the gap analysis will directly feed a certified audit within 6 months. Either way, running a self-assessment first makes the paid work cheaper and faster.

After the Gap Analysis

The natural next steps: conduct the formal risk assessment, draft the Statement of Applicability, close the priority gaps, then schedule internal audit and management review (clauses 9.2/9.3) before certification. If your organization also handles AI systems, consider running our ISO/IEC 42001 AI Readiness Assessment in parallel — the management-system scaffolding largely overlaps, and our ISO 42001 implementation guide explains how the two standards complement each other.

Frequently Asked Questions

How long does an ISO 27001 gap analysis take?

A focused self-assessment takes 2–4 hours with a structured questionnaire. A consultant-led analysis for a mid-size company typically runs 2–4 weeks including document review and interviews.

What is the difference between a gap analysis and a gap assessment?

The terms are used interchangeably. "Gap analysis" emphasizes the comparison methodology; "gap assessment" emphasizes the scoring deliverable. Both measure distance from ISO 27001 conformity.

Do I need a gap analysis before certification?

It is not a formal requirement, but skipping it is the most common cause of failed Stage 1 audits. Certification bodies expect you to arrive with a working ISMS — the gap analysis is how you find out whether you have one.

Can I get a gap analysis report as a PDF?

Yes. Our ISO 27001 Gap Assessment tool generates a downloadable PDF report with per-clause scores and remediation priorities, free and browser-based.

Related Insights

Privacy & Cookie Preferences

We use cookies to enhance your experience, analyze site performance, and support our marketing efforts. Your privacy matters, and you can withdraw consent at any time.