An ISO 27001 assessment report is the document that turns a self-assessment, gap assessment or internal audit into decisions. The scoring is the work; the report is what leadership, the certification body and — under clause 9.3 — the management review actually read. Most assessment reports fail in one of two ways: they are the spreadsheet exported to Word, ninety-three rows nobody acts on, or they are a slide deck with a traffic-light summary and no evidence behind it. The report that works has six sections, in a fixed order, and it is written so that a board member can stop after the first and an auditor can start at the fourth. This guide sets out the six sections, what each contains, how to present scores so they drive priorities, and the traps that make assessment reports untrustworthy.

What an ISO 27001 assessment report is for
Three audiences read an ISO 27001 assessment report, for three reasons. Leadership reads it to decide whether to fund the remediation and when to commit to a certification date — clause 5.1 makes them accountable for the ISMS’s effectiveness and clause 9.3 requires them to review its performance. The ISMS owner and control owners read it as the work plan. And the auditor reads it, at stage 1 or at surveillance, as evidence that the organization evaluates its own system under clause 9.1 and acts on the results under clause 10. One document has to serve all three, which is why the structure matters more than the prose.
Which assessment the report follows changes the emphasis, not the structure. A self-assessment report leads with the baseline scores; a gap assessment report leads with the readiness estimate; an internal audit report leads with nonconformities. All six sections are still present.
The six sections of an ISO 27001 assessment report
| # | Section | Length | Contains | Written for |
|---|---|---|---|---|
| 1 | Executive summary | 1 page | Overall position in one paragraph; headline scores; the three to five decisions requested; the readiness estimate and its assumptions | Leadership |
| 2 | Scope, method and evidence | 1–2 pages | ISMS scope assessed; standard edition; scoring scale; who was interviewed; what evidence was reviewed; limitations | Auditor; future assessors |
| 3 | Management-system results (clauses 4–10) | 2–4 pages | Score per clause requirement with evidence reference; narrative on the clauses that fail | ISMS owner; auditor |
| 4 | Annex A control results | Table plus 2–3 pages | All 93 controls: applicability, score, evidence reference; results by theme and by 27002 attribute | Control owners; auditor |
| 5 | Findings and priorities | 2–4 pages | Each gap classified (documentation, implementation, capability), rated, and sequenced; critical-path items called out | ISMS owner; leadership |
| 6 | Action plan | Table | Every finding with owner, action, target date, resources, and the score it should reach | Everyone; the next assessment |
1. Executive summary
One page, and the ISO 27001 assessment report’s readiness statement goes in the first paragraph: “The ISMS meets 61% of clause requirements and 54% of applicable Annex A controls at implementation level 3 or above; a certifiable position is achievable by March 2027 subject to the three decisions below.” Then the decisions — a budget, a hire, a tooling purchase, a scope change — each as one sentence with a cost. Leadership should be able to act on this page alone.
2. Scope, method and evidence
The section that makes the report auditable. Name the ISMS scope assessed and whether it matches the intended certification scope; state the standard edition (ISO/IEC 27001:2022 with Amendment 1:2024); define the scoring scale used; list the roles interviewed and the documents and systems reviewed; and state the limitations honestly — “physical controls at the Leeds site were assessed by document review only”. An assessment whose method is not written down cannot be repeated, and a report that hides its limitations is discredited by the first one an auditor finds.
3. Management-system results
Clauses 4 to 10, requirement by requirement, with the score and the evidence reference. Then a narrative for each clause that scores below 3, because clause failures are structural: no risk methodology (6.1.2) means the SoA cannot be justified; no internal audit program (9.2) means stage 1 cannot proceed. Keep the narrative to what is missing and what closes it.
4. Annex A control results
The full 93-row table — applicability, score, evidence — belongs here or in an appendix, but the section’s value is the roll-up. Present the results three ways: by theme (organizational, people, physical, technological), by ISO 27002 cybersecurity concept (Identify, Protect, Detect, Respond, Recover), and by owner. The theme view shows where the ISMS is unbalanced; the concept view shows whether detection and response are funded; the owner view shows who has the work. Our guide to the ISO 27001 control assessment covers the scoring and the attributes behind these views.
5. Findings and priorities
Every score below 3 becomes a finding. Classify each as a documentation gap, an implementation gap or a capability gap, because the effort and the lead time differ by an order of magnitude between them. Rate each for its effect on certification — a clause 4–10 gap or a missing SoA control blocks stage 1; a partially operating control produces a stage 2 nonconformity — and sequence them, calling out the critical path: the scope statement, the risk methodology, the asset inventory and the SoA unblock most of everything else.
6. Action plan
A table, one row per finding: action, owner, target date, resources required, and the target score. The action plan is what the next assessment scores against, so the target score column is not decoration — it is the definition of done. Findings without an owner are not findings; they are observations, and the report should say so.
Presenting ISO 27001 assessment report scores so they drive priorities
- Show the distribution, not only the average. “Average control score 2.6” hides whether that is 93 controls at 2–3 or sixty at 4 and thirty at 0. A histogram of scores per theme tells leadership where the zeros are.
- Separate applicability from implementation. “78 of 93 controls implemented” is misleading if 15 were excluded; report “78 of 85 applicable controls” and list the exclusions with their justifications.
- Weight by certification impact, not by count. Ten low-scoring people controls matter less than one missing internal audit program. The priority section should say which findings block stage 1, which produce stage 2 nonconformities, and which are improvements.
- Show the trend where there is one. A re-assessment report should put the previous scores beside the current ones. The delta is the ISMS performance measure clause 9.1 asks for.
Traps that make an ISO 27001 assessment report untrustworthy
- Scores without evidence references. A 3 with no document or record named is an opinion. The auditor will test a sample; if the references are missing, the sample fails.
- A readiness date with no assumptions. Every estimate depends on scope, resourcing and budget. Write them down or the date will be quoted back without them.
- Findings that are recommendations. “Consider implementing MFA” is advice. “A.8.5 scores 1: MFA is not enforced for privileged accounts; enforce it on all admin accounts by 30 November — owner: Head of IT” is a finding.
- Omitting the limitations. Every assessment has them. Reports that state theirs are believed; reports that do not are checked.
- Writing for one audience. A board-only summary starves the control owners; a 93-row export starves the board. The six-section structure exists so that both are served by one document.
Frequently asked questions
Does ISO 27001 require an assessment report?
It requires documented results of monitoring and measurement (9.1), internal audit results reported to management (9.2) and management review inputs and outputs (9.3). An assessment report is the practical way most organizations produce those records; its form is not prescribed.
How long should the report be?
Six sections: a one-page executive summary, a short method section, two results sections with the full tables in appendices, a findings section and an action plan table. Ten to twenty pages plus appendices for a typical scope.
Should the full 93-control table be in the report?
Yes, in section 4 or an appendix, with applicability, score and evidence reference per control. The roll-ups by theme, attribute and owner are what the body of the section presents.
Who signs it?
The assessor signs the results; the ISMS owner accepts the action plan; leadership records its decisions in the management review minutes. Three signatures, three accountabilities.
How is a re-assessment report different?
It adds the previous scores beside the current ones and reports the delta, which becomes the ISMS’s performance trend under clause 9.1 and a management review input under 9.3.
Where this leaves you
Write the ISO 27001 assessment report in six sections — summary, method, clause results, control results, prioritized findings, action plan — with an evidence reference behind every score, assumptions behind every date, and an owner behind every finding. A report built that way is read by the board, worked by the control owners and accepted by the auditor, and the next one is a comparison rather than a restart.
References
- ISO/IEC 27001:2022 — Clauses 9.1, 9.2 and 9.3 — the records the assessment report supplies.
- ISO/IEC 27002:2022 — The control attributes used in the Annex A results section.
More on ISO 27001 assessment
- The ISO 27001 assessment report — you are here
- ISO 27001 self-assessment: scoring all 93 controls
- ISO 27001 gap assessment: the four outputs
- ISO 27001 control assessment: scoring Annex A
- ISO 27001 readiness assessment: six checks
- ISO 27001 maturity assessment: six levels
A scored questionnaire across the clauses and all 93 controls, with automatic scoring, risk analysis and the summary dashboards the report’s results sections are built from, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.