One of the free compliance gap assessments from Governance Docs.

Score yourself against every requirement of ISO/IEC 27001:2022, free, in about an hour. All seven management system clauses and all 93 Annex A controls, with your answers saved as you go so you can stop and come back.

You get your overall readiness score at the end at no cost. The full report — your score by domain, every gap, and a prioritised remediation plan — is a separate one-off purchase.

What this tool assesses

120 requirements. Not a sample, not a shortened checklist: every clause and every Annex A control in the 2022 edition, including Amendment 1:2024, which added climate change to clauses 4.1 and 4.2 and which certification bodies now check at every audit.

DomainRequirementsWhat it asks about
Clause 4 — Context4Scope, interested parties, and the ISMS as a system of processes
Clause 5 — Leadership3Management commitment, the policy, who is accountable
Clause 6 — Planning5Risk assessment and treatment, the Statement of Applicability, objectives
Clause 7 — Support7Competence, awareness, communication, document control
Clause 8 — Operation3Running the risk process and retaining the evidence
Clause 9 — Performance evaluation3Measurement, internal audit, management review
Clause 10 — Improvement2Nonconformity, corrective action, continual improvement
A.5 — Organizational controls37Policies, roles, suppliers, incidents, cloud, legal obligations
A.6 — People controls8Screening, contracts, awareness, remote working, reporting
A.7 — Physical controls14Perimeters, entry, equipment, media, secure disposal
A.8 — Technological controls34Access, cryptography, logging, monitoring, development, change

Each requirement carries a plain-language question, a note on what good looks like, and the evidence an auditor would typically ask to see. For the detail behind the controls themselves, see our guide to the ISO 27001:2022 Annex A controls.

How the scoring works

Five levels, and one of them does the real work. Anything you mark not applicable leaves the calculation entirely rather than counting as zero, so a justified exclusion never drags your score down.

Your answerWeightWhat it means
Not started0.00No policy, process or activity exists for this requirement.
Planned0.25Approach agreed and scheduled, but nothing is in place yet.
Partially implemented0.50In place for part of the scope, or applied inconsistently.
Implemented, not evidenced0.75Operating as intended — but you could not prove it to an auditor today.
Implemented and evidenced1.00Operating as intended, with records an auditor can sample.

The distance between 0.75 and 1.00 is where most organisations find their easiest points. A control you genuinely run but cannot evidence scores 0.75, because auditors sample records, not intentions. The work is already being done; it is simply not being written down. Expect to gain more there than from anything you have not started.

Free score, or the full report

FreeFull report
Work through all 120 requirementsYesYes
Save and return as often as you likeYesYes
Overall readiness scoreYesYes
Which domains hold your gapsYesYes
Your score for each domainYes
Every open gap, listed and prioritisedYes
A remediation plan, weakest control firstYes
The document that closes each gap, namedYes
Branded PDF reportYes
Your assessment as a live Excel workbookYes

A free account is needed to see your score, which keeps your answers attached to you rather than to a browser. The report is bought once for that assessment — not a subscription — and you can regenerate it free whenever you update your answers.

What to do with your score

Treat the number as a starting position, not a grade.

  • Below 40% — you are at the documentation stage. Most gaps will be things never written down rather than things done badly. Start from a complete document set and tailor it; building 93 controls’ worth of policy from a blank page is where most projects stall.
  • 40% to 70% — you have the substance and are missing the system. Expect gaps to cluster in clauses 6, 9 and 10: risk treatment, internal audit, management review. These look like bureaucracy until an auditor asks for last year’s records.
  • Above 70% — you are close, and your remaining gaps are probably evidence rather than capability. Work the 0.75s first.

Work down from the weakest control rather than across the framework in clause order. An auditor reaches your weakest area regardless of where it sits in the standard.

Where this fits

This page is the instrument. If you want the method behind it, we have written it up separately:

Prefer to work offline?

Some teams would rather assess in a spreadsheet they control — consultants running this across several clients, or organisations whose own policy discourages putting posture data into a web form. The ISO 27001 Assessment Tool is the same instrument as an Excel workbook you download and keep.

If you already know where your gaps are and simply need the documentation, the ISO 27001 Toolkit covers every requirement here. Our list of ISO 27001 mandatory documents sets out the minimum a certification body expects to see.

Frequently asked questions

Is it really free?

Yes. All 120 requirements and your overall readiness score cost nothing. A free account is needed to view the score. The detailed report is a separate one-off purchase.

Do I have to finish in one sitting?

No. Every answer saves the moment you give it, and the assessment reopens on the first domain you have not completed — on the same device or another one once you have an account.

Which version does it assess?

ISO/IEC 27001:2022, including Amendment 1:2024. The 2013 edition is no longer certifiable; that transition ended on 31 October 2025.

Is this the same as being certified?

No. It is a structured self-assessment of your own position. Certification requires an accredited certification body to audit you and reach its own conclusion.

Can I use it for a client?

Yes. It produces a defensible starting position and a prioritised plan in about an hour, without a scoping engagement. Put the client’s name in the organisation field so the report is addressed correctly.

What happens to my answers?

They describe your current security position, so they are treated as confidential: linked to your account, never shared, and used only to produce your score and report. You can request a copy or deletion at any time. See our privacy policy.