One of the free compliance gap assessments from Governance Docs.
Score yourself against every requirement of ISO/IEC 27001:2022, free, in about an hour. All seven management system clauses and all 93 Annex A controls, with your answers saved as you go so you can stop and come back.
You get your overall readiness score at the end at no cost. The full report — your score by domain, every gap, and a prioritised remediation plan — is a separate one-off purchase.
What this tool assesses
120 requirements. Not a sample, not a shortened checklist: every clause and every Annex A control in the 2022 edition, including Amendment 1:2024, which added climate change to clauses 4.1 and 4.2 and which certification bodies now check at every audit.
| Domain | Requirements | What it asks about |
|---|---|---|
| Clause 4 — Context | 4 | Scope, interested parties, and the ISMS as a system of processes |
| Clause 5 — Leadership | 3 | Management commitment, the policy, who is accountable |
| Clause 6 — Planning | 5 | Risk assessment and treatment, the Statement of Applicability, objectives |
| Clause 7 — Support | 7 | Competence, awareness, communication, document control |
| Clause 8 — Operation | 3 | Running the risk process and retaining the evidence |
| Clause 9 — Performance evaluation | 3 | Measurement, internal audit, management review |
| Clause 10 — Improvement | 2 | Nonconformity, corrective action, continual improvement |
| A.5 — Organizational controls | 37 | Policies, roles, suppliers, incidents, cloud, legal obligations |
| A.6 — People controls | 8 | Screening, contracts, awareness, remote working, reporting |
| A.7 — Physical controls | 14 | Perimeters, entry, equipment, media, secure disposal |
| A.8 — Technological controls | 34 | Access, cryptography, logging, monitoring, development, change |
Each requirement carries a plain-language question, a note on what good looks like, and the evidence an auditor would typically ask to see. For the detail behind the controls themselves, see our guide to the ISO 27001:2022 Annex A controls.
How the scoring works
Five levels, and one of them does the real work. Anything you mark not applicable leaves the calculation entirely rather than counting as zero, so a justified exclusion never drags your score down.
| Your answer | Weight | What it means |
|---|---|---|
| Not started | 0.00 | No policy, process or activity exists for this requirement. |
| Planned | 0.25 | Approach agreed and scheduled, but nothing is in place yet. |
| Partially implemented | 0.50 | In place for part of the scope, or applied inconsistently. |
| Implemented, not evidenced | 0.75 | Operating as intended — but you could not prove it to an auditor today. |
| Implemented and evidenced | 1.00 | Operating as intended, with records an auditor can sample. |
The distance between 0.75 and 1.00 is where most organisations find their easiest points. A control you genuinely run but cannot evidence scores 0.75, because auditors sample records, not intentions. The work is already being done; it is simply not being written down. Expect to gain more there than from anything you have not started.
Free score, or the full report
| Free | Full report | |
|---|---|---|
| Work through all 120 requirements | Yes | Yes |
| Save and return as often as you like | Yes | Yes |
| Overall readiness score | Yes | Yes |
| Which domains hold your gaps | Yes | Yes |
| Your score for each domain | — | Yes |
| Every open gap, listed and prioritised | — | Yes |
| A remediation plan, weakest control first | — | Yes |
| The document that closes each gap, named | — | Yes |
| Branded PDF report | — | Yes |
| Your assessment as a live Excel workbook | — | Yes |
A free account is needed to see your score, which keeps your answers attached to you rather than to a browser. The report is bought once for that assessment — not a subscription — and you can regenerate it free whenever you update your answers.
What to do with your score
Treat the number as a starting position, not a grade.
- Below 40% — you are at the documentation stage. Most gaps will be things never written down rather than things done badly. Start from a complete document set and tailor it; building 93 controls’ worth of policy from a blank page is where most projects stall.
- 40% to 70% — you have the substance and are missing the system. Expect gaps to cluster in clauses 6, 9 and 10: risk treatment, internal audit, management review. These look like bureaucracy until an auditor asks for last year’s records.
- Above 70% — you are close, and your remaining gaps are probably evidence rather than capability. Work the 0.75s first.
Work down from the weakest control rather than across the framework in clause order. An auditor reaches your weakest area regardless of where it sits in the standard.
Where this fits
This page is the instrument. If you want the method behind it, we have written it up separately:
- ISO 27001 gap analysis — how to run one properly, in seven steps, and what it costs
- ISO 27001 self-assessment — scoring all 93 controls, and the traps in doing it yourself
- ISO 27001 readiness assessment — the checks worth making before you book an audit
- ISO 27001 tools — the four categories, and why a yes/no scale is not enough
Prefer to work offline?
Some teams would rather assess in a spreadsheet they control — consultants running this across several clients, or organisations whose own policy discourages putting posture data into a web form. The ISO 27001 Assessment Tool is the same instrument as an Excel workbook you download and keep.
If you already know where your gaps are and simply need the documentation, the ISO 27001 Toolkit covers every requirement here. Our list of ISO 27001 mandatory documents sets out the minimum a certification body expects to see.
Frequently asked questions
Is it really free?
Yes. All 120 requirements and your overall readiness score cost nothing. A free account is needed to view the score. The detailed report is a separate one-off purchase.
Do I have to finish in one sitting?
No. Every answer saves the moment you give it, and the assessment reopens on the first domain you have not completed — on the same device or another one once you have an account.
Which version does it assess?
ISO/IEC 27001:2022, including Amendment 1:2024. The 2013 edition is no longer certifiable; that transition ended on 31 October 2025.
Is this the same as being certified?
No. It is a structured self-assessment of your own position. Certification requires an accredited certification body to audit you and reach its own conclusion.
Can I use it for a client?
Yes. It produces a defensible starting position and a prioritised plan in about an hour, without a scoping engagement. Put the client’s name in the organisation field so the report is addressed correctly.
What happens to my answers?
They describe your current security position, so they are treated as confidential: linked to your account, never shared, and used only to produce your score and report. You can request a copy or deletion at any time. See our privacy policy.