An ISO 27001 gap assessment compares what an organization has against what ISO/IEC 27001:2022 requires and produces a plan to close the difference. It is the first structured piece of work in most certification projects and the one most often bought from a consultant, which is why it pays to know exactly what it should deliver. A good gap assessment produces four outputs: a clause-by-clause and control-by-control gap register, a prioritized remediation plan, a draft Statement of Applicability, and a certification readiness estimate with a timeline. Anything less is a questionnaire; anything that claims more — a risk assessment, an internal audit — is a different exercise being sold under the wrong name. This guide explains what an ISO 27001 gap assessment is, the four outputs, how to run one, and how to read a consultant’s proposal for it.

What an ISO 27001 gap assessment is
The standard does not require a gap assessment, and the term does not appear in it. It is a project-management instrument: a snapshot of the distance between the current state and the standard, taken before implementation starts so that the implementation plan is built on evidence rather than assumption. It differs from the risk assessment the standard does require under clause 6.1.2 — that identifies risks to information and selects controls to treat them — and from the internal audit under 9.2, which checks an operating ISMS for conformity. The gap assessment asks a simpler question of each requirement and control: is it in place, partly, or not at all, and what would it take?
Its scope is the whole standard: the mandatory management-system requirements in clauses 4 to 10, and the 93 Annex A controls in four themes — 37 organizational, 8 people, 14 physical, 34 technological — assessed for existence before the organization has decided which apply. Our guide to the ISO 27001 self-assessment covers the scoring scale the gap assessment is built on.
The four outputs of an ISO 27001 gap assessment
1. The gap register
One row per clause requirement and per Annex A control, recording the current state, the gap, the evidence reviewed and the effort to close. The register is the assessment; everything else is derived from it. It should distinguish three kinds of gap, because they are closed differently:
| Gap type | Example | Closed by |
|---|---|---|
| Documentation gap | Access control practised but no approved policy or procedure | Writing and approving the document; usually weeks |
| Implementation gap | Policy exists; access reviews required by it have never run | Operating the control and generating records; usually a quarter |
| Capability gap | No logging or monitoring of the systems in scope | Tooling, budget and people; usually the critical path |
2. The prioritized remediation plan
The register sorted into a sequence. Priority comes from three factors: whether the item is a clause requirement (mandatory, and tested at stage 1), whether it is on the critical path for other items (the scope statement, the risk methodology and the asset inventory unblock most of Annex A), and effort. The plan names an owner and a target date for every item and rolls up into the project timeline. Our guide to the ISO 27001 assessment report covers how the plan is presented to management.
3. The draft Statement of Applicability
Because the gap assessment has looked at all 93 controls, it can produce a first-cut SoA: which controls appear applicable, which look excludable and why, and the implementation status of each. It is a draft — the final SoA must be justified by the risk assessment under 6.1.3 — but it saves the risk treatment step from starting with a blank list, and it exposes exclusions that will not survive scrutiny early.
4. The certification readiness estimate
A statement of how far the organization is from a certifiable position, in time and effort: typically a percentage of requirements met, the number of critical-path gaps, and an estimated date for stage 1. The estimate is the output executives read; it should carry its assumptions — scope, resourcing, tooling budget — because changing any of them changes the date. Our guide to the ISO 27001 readiness assessment covers the checks that turn an estimate into a booking.
How to run an ISO 27001 gap assessment
- Define the intended scope before assessing. The gap is measured against the ISMS you plan to certify. A gap assessment of “the company” when the certificate will cover one product platform overstates the work by a multiple.
- Collect what exists. Policies, procedures, registers, system configurations, prior audit reports, supplier contracts. The assessment is a review of evidence, not an interview about intentions.
- Assess clauses 4–10 requirement by requirement. Context, interested parties, scope, leadership commitment, policy, roles, risk methodology, objectives, resources, competence, awareness, communication, documented information, operational planning, monitoring, internal audit, management review, nonconformity and improvement. Most first-time organizations have fewer than half of these.
- Assess all 93 controls for existence and operation. Score each on the five-point scale; record the evidence; note the likely applicability. The ISO 27001 control assessment guide covers the Annex A pass in detail.
- Interview the owners, not the sponsor. HR for people controls, facilities for physical, procurement for suppliers, engineering for technological. The gap assessment that talks only to the CISO reflects the CISO’s beliefs.
- Classify, prioritize, estimate. Build the four outputs from the register and present them together.
Reading a consultant’s gap assessment proposal
Gap assessments are the most commonly outsourced ISO 27001 deliverable, and proposals vary widely. Five questions sort them:
- Does it cover the clauses, or only Annex A? A “93-control gap assessment” that skips clauses 4–10 misses the part stage 1 audits test first.
- Is it evidence-based or questionnaire-based? A questionnaire filled in by the client and summarized by the consultant is a self-assessment with a fee. Ask what evidence will be reviewed.
- Which of the four outputs are included? Many proposals deliver the register and a slide deck; the remediation plan, draft SoA and readiness estimate are the parts with the value.
- Who will be interviewed? A day with the IT manager is a partial assessment.
- Is it independent of the implementation offer? A gap assessment from a firm that also sells the implementation has an incentive to find gaps. That is not disqualifying — it is normal — but read the readiness estimate with it in mind.
For a small, single-site scope a competent gap assessment is two to five consultant days. Larger multi-site scopes scale with the number of control owners to interview rather than with headcount.
Frequently asked questions
Is an ISO 27001 gap assessment mandatory?
No. The standard requires a risk assessment (6.1.2), internal audits (9.2) and management review (9.3). The gap assessment is a planning tool run before implementation, not a requirement.
What is the difference between a gap assessment and a risk assessment?
The gap assessment compares the current state against the standard’s requirements and controls. The risk assessment identifies risks to information and selects controls to treat them. The first tells you what is missing; the second tells you what you need.
Should it cover all 93 controls before the SoA exists?
Yes. Assessing every control for existence before deciding applicability produces a better draft SoA and prevents hard controls being excluded for convenience.
What should a gap assessment deliver?
Four outputs: a gap register covering clauses 4–10 and Annex A, a prioritized remediation plan with owners and dates, a draft Statement of Applicability, and a certification readiness estimate with a timeline and its assumptions.
How often should it be repeated?
Once before implementation, and again before booking the certification audit as a readiness check. After certification the internal audit and management review take over.
Where this leaves you
Buy or build an ISO 27001 gap assessment for its four outputs — the register, the plan, the draft SoA and the readiness estimate — and judge it on the evidence it reviewed and the owners it interviewed. The register is the work; the plan is what you act on; the SoA draft saves the next step; and the readiness estimate, with its assumptions written down, is the date you can defend to the board.
References
- ISO/IEC 27001:2022 — The information security management system standard.
- ISO/IEC 27002:2022 — Implementation guidance for the 93 Annex A controls.
More on ISO 27001 assessment
- The ISO 27001 gap assessment — you are here
- ISO 27001 self-assessment: scoring all 93 controls
- ISO 27001 readiness assessment: six checks
- ISO 27001 maturity assessment: six levels
- ISO 27001 control assessment: scoring Annex A
- ISO 27001 assessment report: the six sections
A scored questionnaire across the clauses and all 93 controls, with automatic scoring, gap highlighting and summary dashboards, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.