An ISO 27001 readiness assessment and a gap analysis are not the same exercise, and confusing them is why organisations arrive at a certification audit believing they were at 90% and fail Stage 2.
A gap analysis asks what is missing from the ISMS. A readiness assessment asks a narrower and much harder question: if the certification body arrived on Monday, would you pass?
Why an ISO 27001 readiness assessment asks a different question

Certification bodies are accredited against ISO/IEC 17021-1:2015 — first edition, June 2015, 48 pages, and now itself at stage 90.60, under review. It is the standard that requires an initial certification audit to be conducted in two stages, and the two stages test different things.
Stage 1 asks whether the ISMS is designed. Scope, documentation, the Statement of Applicability, the risk assessment and treatment method, and whether internal audit and management review are planned. It is largely a document exercise, and a competent gap analysis will predict it well.
Stage 2 asks whether the ISMS is operating. Records rather than intentions, sampled across the scope, with interviews of people who were nowhere near the implementation project. A gap analysis is a poor predictor of this, because a document can exist and describe a process nobody has run.
That is the whole distinction. Your gap analysis tells you what to build. An ISO 27001 readiness assessment tells you whether what you built has been running long enough to leave evidence.
The three clauses no ISO 27001 readiness assessment can shortcut
Most ISO 27001 readiness assessment findings can be fixed by effort. Three cannot, because they are gated by elapsed time rather than by work:
- Clause 9.2, internal audit — an audit programme has to have run, covering the ISMS, with records and findings.
- Clause 9.3, management review — a review has to have taken place, with the required inputs and recorded outputs and decisions.
- Clause 10.2, nonconformity and corrective action — corrective actions have to have been raised, worked and closed, which means something has to have gone wrong first.
Each of these is trivially easy to document and impossible to fake as evidence. If your readiness assessment scores them on whether a procedure exists, it will tell you that you are ready when you are weeks or months away.
This is the most common single cause of a delayed certificate, and the only fix is to start the cycle earlier — which is a scheduling decision, so it has to be made long before anyone books the audit.
Score three ways, not two
A binary scoring scheme — done or not done — cannot express the gap between the two stages. A useful ISO 27001 readiness assessment scores each requirement three ways:
- Not started.
- Documented — the policy, procedure or record template exists and is approved.
- Operating with evidence — it has run at least once in the way it is described, and there are records a stranger could sample.
The distance between the second and third column is your Stage 2 risk, expressed as a number. It is also the number to show a steering committee, because it is the one that explains why the project is not finished when the documentation is.
Where an ISO 27001 readiness assessment consistently over-scores
Four areas flatter themselves in almost every assessment:
The Statement of Applicability. Complete as a document, but the justifications for exclusion are thin and the linkage back to risk treatment decisions does not hold up when an auditor traces one. Trace three yourself, end to end, before scoring it.
Risk treatment. The register exists and is populated. What is missing is evidence that treatments were implemented and that residual risk was accepted by someone with the authority to accept it.
Awareness and competence. A training platform reports 98% completion, which is evidence of clicking rather than competence. Stage 2 tests it by asking people questions.
Supplier controls. The policy is written and the contract clauses are drafted; the supplier list is incomplete and nobody has performed the reviews the policy promises.
What is actually being audited
ISO/IEC 27001:2022 is the third edition, published October 2022, 19 pages, maintained by ISO/IEC JTC 1/SC 27. It carries one amendment, Amd 1:2024, issued free of charge.
Nineteen pages is worth noting when you are scoping an ISO 27001 readiness assessment. The requirements are short; almost all of the volume in a certification project is evidence, which is exactly the part a document-based gap analysis does not measure.
Who should run the ISO 27001 readiness assessment
Not the person who built the ISMS. That is not a comment on anyone’s integrity — it is that the author of a procedure reads it as intended rather than as written, which is the opposite of what an auditor does.
An internal auditor from another function, a second pair of eyes from a sister company, or a structured self-assessment worked through by someone who was not on the project will all surface more than the implementer will. The output should be a dated snapshot with a score per clause, not a narrative.
How the ISO 27001 readiness assessment connects
| Area | Connection |
|---|---|
| Stage 1 vs Stage 2 | What each stage tests, and why readiness has to be measured against both separately |
| ISO 27001 gap analysis | The earlier exercise: what to build, rather than whether it has run |
| ISO 27001 internal audit | One of the three clauses gated by elapsed time rather than effort |
| ISO 27001 timeline | Where the audit cycle has to sit if the time-gated clauses are to be satisfied |
Where to start
- Separate the two questions. Build from the gap analysis; certify from the readiness assessment.
- Score the ISO 27001 readiness assessment three ways, so the documented-but-not-operating population is visible.
- Check the time gates first — internal audit, management review, corrective action — because they set the earliest possible audit date.
- Trace three Statement of Applicability entries end to end before scoring it complete.
- Have someone else run it, ideally someone who was not on the project.
- Date the snapshot and repeat it, so progress is measured rather than asserted.
This guide reflects the ISO/IEC 27001:2022 and ISO/IEC 17021-1:2015 catalogue records on iso.org, read at 16 August 2026. Certification body practice varies within the accreditation rules — confirm the audit plan with yours.
The ISO 27001 Assessment Tool is an Excel workbook that scores your ISMS clause by clause, tracks progress between snapshots and produces the recommendations a readiness assessment is meant to output — and the ISO 27001 Toolkit supplies the 162 templates you use to close what it finds.