An ISO 27001 gap analysis is a structured comparison of what your organization actually does against what ISO/IEC 27001:2022 requires — clauses 4 to 10 plus the 93 Annex A controls — so you know exactly what has to be built before an auditor arrives. The standard does not require you to run one, yet almost every certification project that finishes on budget starts with one. Done properly it takes a few days, produces a scored gap register, and turns “we want to get certified” into a costed plan with owners and dates.
For the full picture of the standard itself, see our complete ISO 27001:2022 guide.
What an ISO 27001 gap analysis actually measures
Two things, and people routinely forget the first. A complete ISO 27001 gap analysis measures your management system against clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement — and it measures your controls against Annex A.
Annex A of ISO/IEC 27001:2022 contains 93 controls grouped into four themes: 37 organizational, 8 people, 14 physical and 34 technological. Most teams jump straight to the technological controls because that is where the security tooling lives. Certification bodies raise most of their nonconformities against clauses 4 to 10 — the governance layer — because that is where the documentation, evidence and management routines sit. A gap analysis that only scores Annex A will make you feel far more ready than you are.
Since Amendment 1:2024, clause 4.1 also requires you to determine whether climate change is a relevant issue for your ISMS, and clause 4.2 notes that interested parties may have climate-related requirements. It is a small addition, but it is a real requirement — add both to your checklist so it does not surface as an observation at Stage 1. You can review the official scope of the standard on the ISO/IEC 27001:2022 standard page at iso.org.
ISO 27001 gap analysis vs risk assessment vs internal audit
These three get used interchangeably in sales conversations and they are not the same exercise. Confusing them is the fastest way to buy the wrong service.
| Exercise | Question it answers | Required by the standard? | When you do it | Output |
|---|---|---|---|---|
| Gap analysis | What does ISO 27001 require that we do not yet have? | No — optional but strongly advised | Before you start building the ISMS | Scored gap register and remediation plan |
| Risk assessment | What could go wrong with our information, and how bad would it be? | Yes — clauses 6.1.2 and 8.2 | Early in implementation, then at planned intervals | Risk register, risk treatment plan, Statement of Applicability |
| Internal audit | Is the ISMS we built conforming and actually operating? | Yes — clause 9.2 | Once the ISMS has been running, before certification | Audit report, nonconformities, corrective actions |
Sequence matters. The gap analysis tells you what to build. The risk assessment tells you which controls are justified and feeds the Statement of Applicability, which is mandatory under clause 6.1.3. The internal audit, months later, tells you whether any of it stuck. Running an internal audit on an ISMS you have not built yet is just an expensive gap analysis with worse paperwork.
How to run an ISO 27001 gap analysis in seven steps
1. Fix the scope first
Decide which parts of the business, which locations and which systems the ISMS will cover, and write it down before you assess anything. An ISO 27001 gap analysis run against an undefined scope produces findings you cannot act on, because nobody can say whether a given system is in or out. If the scope is genuinely undecided, assess the widest plausible boundary and narrow later.
2. Build the checklist
One row per requirement: every sub-clause from 4.1 through 10.2, then all 93 Annex A controls. Columns for current status, evidence seen, gap description, owner, priority and target date. A spreadsheet is fine — the checklist behind an ISO 27001 gap analysis is a working document, not a deliverable for the board.
3. Collect evidence, do not collect opinions
This is where most self-run reviews fail. “Yes, we do access reviews” is not evidence. The last quarterly access review export, dated and signed off, is evidence. Ask for the artifact every time. If it takes someone more than a few minutes to find, note that too — retrieval difficulty is itself a finding, and it is exactly what slows a Stage 2 audit down.
4. Score each requirement on a consistent scale
Binary compliant/non-compliant scoring hides the difference between “we have nothing” and “we do it but never write it down.” Use four levels instead:
| Score | Meaning | Typical remediation effort |
|---|---|---|
| 0 — Absent | Nothing exists | Build from scratch: policy, process and records |
| 1 — Informal | Happens in practice, undocumented, inconsistent | Document it and start keeping records |
| 2 — Documented | Written down but not consistently followed or evidenced | Enforce, train, generate evidence |
| 3 — Operating | Documented, followed, and evidenced over time | Maintain and sample at internal audit |
Anything scoring 0 or 1 is a real gap. A 2 is a trap: it looks finished on a status report and fails at Stage 2, where the auditor asks for records rather than documents.
5. Interview beyond the security team
Talk to HR about screening and offboarding, to IT about access and change management, to procurement about supplier clauses, to facilities about physical controls. The people themes and organizational themes of Annex A live outside the security function, and an ISO 27001 gap analysis that only interviews the security team will systematically miss them.
6. Prioritize by risk and by dependency
Sort the gaps into three buckets: certification blockers (mandatory documented information, the risk assessment, the Statement of Applicability, internal audit, management review), high-risk control gaps, and everything else. Then check dependencies — you cannot produce a Statement of Applicability before you have a risk assessment, and you cannot run a meaningful internal audit until the controls have been operating for a while.
7. Convert the register into a dated plan
Every gap gets a named owner, a target date and a definition of done that names the evidence. “Improve supplier security” is not a plan. “Issue supplier security policy, add security clauses to the standard MSA, and complete a risk review of the top 12 vendors by 30 November — evidence: signed policy, revised MSA template, 12 completed vendor reviews” is.
What an ISO 27001 gap analysis costs and how long it takes
Treat the following as typical market ranges rather than quotes; price depends on scope, headcount, number of sites and how much documentation already exists.
| Approach | Typical duration | Typical cost (US, 2026) | Best for |
|---|---|---|---|
| Self-assessment using a checklist or toolkit | 1–3 weeks part-time | Internal time plus template cost | Teams with someone who has done ISO 27001 before |
| Independent consultant | 3–10 consulting days | Roughly $5,000–$8,000 for a small organization | First-time implementers wanting an outside read |
| Larger consultancy, multi-site or complex scope | 2–6 weeks | Commonly $15,000–$30,000+ | Regulated, multi-entity or multi-country scopes |
US independent consultant day rates for this work generally sit around $1,400–$1,800, with larger firms higher. The honest comparison is not consultant versus free — it is consultant versus the cost of discovering the same gaps six months later, when your certification body has already been booked. For how this fits the total bill, see our ISO 27001 certification cost breakdown.
The five gaps we see most often
- No defined scope, or a scope that nobody has approved. Everything downstream inherits the ambiguity.
- A risk assessment that was done once and never repeated. Clause 8.2 expects it at planned intervals and when significant changes occur.
- A Statement of Applicability that does not match reality — controls marked applicable that nobody operates, or exclusions with no justification.
- Policies with no records behind them. The policy says quarterly; there are two records in eighteen months.
- No management review. Clause 9.3 requires it with specific inputs, and it is one of the most common nonconformities because it is the easiest to postpone.
Four of those five are governance failures, not technical ones — which is why an ISO 27001 gap analysis weighted toward Annex A gives false comfort. Once you have your gap register, our guide to the ISO 27001 mandatory documents tells you exactly which records the certification body will ask for, and our audit preparation guide covers what happens next.
Turning the gap register into a working ISMS
The output of a good ISO 27001 gap analysis is a to-do list, and most of the items on it are documents: an information security policy, a risk assessment methodology, a risk treatment plan, a Statement of Applicability, an internal audit programme, management review records, and the operational procedures behind the Annex A controls you selected. Writing those from a blank page is where implementation timelines slip from months to quarters.
Our ISO 27001 Toolkit gives you 175 editable Word and Excel templates mapped to ISO 27001:2022 — including a gap analysis checklist, risk register, Statement of Applicability and internal audit pack — for a one-time $99. You still have to do the thinking; you no longer have to do the typing.
Frequently asked questions
Is an ISO 27001 gap analysis mandatory?
No. ISO/IEC 27001:2022 does not require a gap analysis anywhere in clauses 4 to 10. It requires a risk assessment, an internal audit and a management review. The gap analysis is a planning tool that most organizations use because starting implementation without one means budgeting blind.
How long does an ISO 27001 gap analysis take?
For a single-site company under roughly 100 people, expect 3 to 5 working days of assessment plus a few days to write it up. Multi-site or regulated scopes commonly run 2 to 6 weeks. Self-assessment with a checklist usually stretches over a few weeks of part-time effort because it competes with day jobs.
Can we do the gap analysis ourselves?
Yes, and it is a reasonable choice if someone on the team has been through a certification before and can be honest about their own department. The two failure modes for self-assessment are marking things compliant on the strength of intention rather than evidence, and skipping the clauses that sit outside the security team. A structured checklist with an evidence column mitigates both.
What is the difference between a gap analysis and a Stage 1 audit?
An ISO 27001 gap analysis is your own exercise, run before you build, with no consequences attached. The Stage 1 audit is performed by your certification body once you believe you are ready; it reviews your documentation and readiness and its findings determine whether Stage 2 proceeds. If your gap analysis was thorough and you closed what it found, Stage 1 should hold no surprises.
Does a gap analysis cover the 2022 transition?
The 2013 to 2022 transition period closed on 31 October 2025, so ISO 27001:2013 certificates are no longer valid and any new ISO 27001 gap analysis should be run against the 2022 edition and its 93 Annex A controls, including Amendment 1:2024 on climate change. If you are working from a checklist built around the old 114 controls, replace it.