Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 assessment report explained

ISO 27001 Assessment Report: A Clear Guide to the 6 Sections

An ISO 27001 assessment report is the document that turns a self-assessment, gap assessment or internal audit into decisions. The scoring is the work; the report is what leadership, the certification body and — under clause 9.3 — the management review actually read. Most assessment reports fail in one of two ways: they are the spreadsheet exported to Word, ninety-three rows nobody acts on, or they are a slide deck with a traffic-light summary and no evidence behind it. The report that works has six sections, in a fixed order, and it is written so that a board member can stop after the first and an auditor can start at the fourth. This guide sets out the six sections, what each contains, how to present scores so they drive priorities, and the traps that make assessment reports untrustworthy.

ISO 27001 assessment report: six sections from summary to action plan
The report structure: executive summary, scope and method, management-system results, Annex A results, prioritized findings, and the action plan.

What an ISO 27001 assessment report is for

Three audiences read an ISO 27001 assessment report, for three reasons. Leadership reads it to decide whether to fund the remediation and when to commit to a certification date — clause 5.1 makes them accountable for the ISMS’s effectiveness and clause 9.3 requires them to review its performance. The ISMS owner and control owners read it as the work plan. And the auditor reads it, at stage 1 or at surveillance, as evidence that the organization evaluates its own system under clause 9.1 and acts on the results under clause 10. One document has to serve all three, which is why the structure matters more than the prose.

Which assessment the report follows changes the emphasis, not the structure. A self-assessment report leads with the baseline scores; a gap assessment report leads with the readiness estimate; an internal audit report leads with nonconformities. All six sections are still present.

The six sections of an ISO 27001 assessment report

# Section Length Contains Written for
1 Executive summary 1 page Overall position in one paragraph; headline scores; the three to five decisions requested; the readiness estimate and its assumptions Leadership
2 Scope, method and evidence 1–2 pages ISMS scope assessed; standard edition; scoring scale; who was interviewed; what evidence was reviewed; limitations Auditor; future assessors
3 Management-system results (clauses 4–10) 2–4 pages Score per clause requirement with evidence reference; narrative on the clauses that fail ISMS owner; auditor
4 Annex A control results Table plus 2–3 pages All 93 controls: applicability, score, evidence reference; results by theme and by 27002 attribute Control owners; auditor
5 Findings and priorities 2–4 pages Each gap classified (documentation, implementation, capability), rated, and sequenced; critical-path items called out ISMS owner; leadership
6 Action plan Table Every finding with owner, action, target date, resources, and the score it should reach Everyone; the next assessment

1. Executive summary

One page, and the ISO 27001 assessment report’s readiness statement goes in the first paragraph: “The ISMS meets 61% of clause requirements and 54% of applicable Annex A controls at implementation level 3 or above; a certifiable position is achievable by March 2027 subject to the three decisions below.” Then the decisions — a budget, a hire, a tooling purchase, a scope change — each as one sentence with a cost. Leadership should be able to act on this page alone.

2. Scope, method and evidence

The section that makes the report auditable. Name the ISMS scope assessed and whether it matches the intended certification scope; state the standard edition (ISO/IEC 27001:2022 with Amendment 1:2024); define the scoring scale used; list the roles interviewed and the documents and systems reviewed; and state the limitations honestly — “physical controls at the Leeds site were assessed by document review only”. An assessment whose method is not written down cannot be repeated, and a report that hides its limitations is discredited by the first one an auditor finds.

3. Management-system results

Clauses 4 to 10, requirement by requirement, with the score and the evidence reference. Then a narrative for each clause that scores below 3, because clause failures are structural: no risk methodology (6.1.2) means the SoA cannot be justified; no internal audit program (9.2) means stage 1 cannot proceed. Keep the narrative to what is missing and what closes it.

4. Annex A control results

The full 93-row table — applicability, score, evidence — belongs here or in an appendix, but the section’s value is the roll-up. Present the results three ways: by theme (organizational, people, physical, technological), by ISO 27002 cybersecurity concept (Identify, Protect, Detect, Respond, Recover), and by owner. The theme view shows where the ISMS is unbalanced; the concept view shows whether detection and response are funded; the owner view shows who has the work. Our guide to the ISO 27001 control assessment covers the scoring and the attributes behind these views.

5. Findings and priorities

Every score below 3 becomes a finding. Classify each as a documentation gap, an implementation gap or a capability gap, because the effort and the lead time differ by an order of magnitude between them. Rate each for its effect on certification — a clause 4–10 gap or a missing SoA control blocks stage 1; a partially operating control produces a stage 2 nonconformity — and sequence them, calling out the critical path: the scope statement, the risk methodology, the asset inventory and the SoA unblock most of everything else.

6. Action plan

A table, one row per finding: action, owner, target date, resources required, and the target score. The action plan is what the next assessment scores against, so the target score column is not decoration — it is the definition of done. Findings without an owner are not findings; they are observations, and the report should say so.

Presenting ISO 27001 assessment report scores so they drive priorities

  • Show the distribution, not only the average. “Average control score 2.6” hides whether that is 93 controls at 2–3 or sixty at 4 and thirty at 0. A histogram of scores per theme tells leadership where the zeros are.
  • Separate applicability from implementation. “78 of 93 controls implemented” is misleading if 15 were excluded; report “78 of 85 applicable controls” and list the exclusions with their justifications.
  • Weight by certification impact, not by count. Ten low-scoring people controls matter less than one missing internal audit program. The priority section should say which findings block stage 1, which produce stage 2 nonconformities, and which are improvements.
  • Show the trend where there is one. A re-assessment report should put the previous scores beside the current ones. The delta is the ISMS performance measure clause 9.1 asks for.

Traps that make an ISO 27001 assessment report untrustworthy

  1. Scores without evidence references. A 3 with no document or record named is an opinion. The auditor will test a sample; if the references are missing, the sample fails.
  2. A readiness date with no assumptions. Every estimate depends on scope, resourcing and budget. Write them down or the date will be quoted back without them.
  3. Findings that are recommendations. “Consider implementing MFA” is advice. “A.8.5 scores 1: MFA is not enforced for privileged accounts; enforce it on all admin accounts by 30 November — owner: Head of IT” is a finding.
  4. Omitting the limitations. Every assessment has them. Reports that state theirs are believed; reports that do not are checked.
  5. Writing for one audience. A board-only summary starves the control owners; a 93-row export starves the board. The six-section structure exists so that both are served by one document.

Frequently asked questions

Does ISO 27001 require an assessment report?
It requires documented results of monitoring and measurement (9.1), internal audit results reported to management (9.2) and management review inputs and outputs (9.3). An assessment report is the practical way most organizations produce those records; its form is not prescribed.

How long should the report be?
Six sections: a one-page executive summary, a short method section, two results sections with the full tables in appendices, a findings section and an action plan table. Ten to twenty pages plus appendices for a typical scope.

Should the full 93-control table be in the report?
Yes, in section 4 or an appendix, with applicability, score and evidence reference per control. The roll-ups by theme, attribute and owner are what the body of the section presents.

Who signs it?
The assessor signs the results; the ISMS owner accepts the action plan; leadership records its decisions in the management review minutes. Three signatures, three accountabilities.

How is a re-assessment report different?
It adds the previous scores beside the current ones and reports the delta, which becomes the ISMS’s performance trend under clause 9.1 and a management review input under 9.3.

Where this leaves you

Write the ISO 27001 assessment report in six sections — summary, method, clause results, control results, prioritized findings, action plan — with an evidence reference behind every score, assumptions behind every date, and an owner behind every finding. A report built that way is read by the board, worked by the control owners and accepted by the auditor, and the next one is a comparison rather than a restart.

References

  • ISO/IEC 27001:2022 — Clauses 9.1, 9.2 and 9.3 — the records the assessment report supplies.
  • ISO/IEC 27002:2022 — The control attributes used in the Annex A results section.

More on ISO 27001 assessment

A scored questionnaire across the clauses and all 93 controls, with automatic scoring, risk analysis and the summary dashboards the report’s results sections are built from, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.