An ISO 27001 self-assessment is the exercise an organization runs on itself, before any auditor arrives, to score how far its information security management system meets ISO/IEC 27001:2022 — the seven management-system clauses and the 93 Annex A controls. Done properly it is the cheapest piece of assurance in the whole certification journey, because it turns “we think we are mostly there” into a numbered list of what is not. Done badly it produces a green dashboard that the stage 1 audit dismantles in an afternoon. This guide explains what an ISO 27001 self-assessment covers, the scoring scale that makes it useful, how to evidence each score, how it differs from a gap assessment, internal audit and certification audit, and the five ways self-assessments flatter their authors.

What an ISO 27001 self-assessment covers
ISO 27001:2022 has two assessable parts. Clauses 4 to 10 are the management system — context, leadership, planning, support, operation, performance evaluation, improvement — and every requirement in them is mandatory. Annex A lists 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Controls are not individually mandatory; the organization selects them through its risk treatment and records the selection, and any exclusions, in the Statement of Applicability under clause 6.1.3. A complete ISO 27001 self-assessment therefore scores every clause requirement and every control the organization has declared applicable — and, on a first pass before the SoA exists, all 93.
The 2022 edition also carries Amendment 1 of 2024, which adds climate change as a consideration in clause 4.1 and a note at 4.2. It is a small change but a self-assessment built on a 2022 checklist without it is already out of date. The 2013-to-2022 transition closed on 31 October 2025, so there is no reason to assess against the old 114-control Annex A.
The scoring scale
A binary yes/no self-assessment hides the difference between “we have a policy” and “we have a policy, it is followed and we can prove it”. A five-point implementation scale separates them:
| Score | Label | Meaning | Evidence expected |
|---|---|---|---|
| 0 | Not implemented | Nothing in place; or the requirement is not understood | None |
| 1 | Planned | Approach agreed, owner named, not yet in operation | Plan, draft document, decision record |
| 2 | Partially implemented | In operation for part of the scope, or documented but not consistently followed | Approved document; partial records |
| 3 | Implemented | In operation across the scope as documented | Approved document; operating records for the period |
| 4 | Implemented and verified | Operating, monitored, reviewed; effectiveness evidenced | As for 3, plus metrics, review minutes, audit results |
| N/A | Not applicable | Control excluded with a justification | The SoA justification |
Two rules keep the scale honest. A score of 3 or 4 requires a piece of evidence to be named — a document reference, a record location, a system report — not asserted. And N/A is only available for Annex A controls, never for clause requirements: every clause 4–10 requirement applies to every certified ISMS.
How to run an ISO 27001 self-assessment
- Fix the scope. Score against the ISMS scope you intend to certify, not the whole organization. If the scope is not yet written, writing it is the first finding.
- Assess the clauses first. Clause requirements are where first-time ISMSs fail stage 1: no documented scope (4.3), no information security objectives (6.2), no competence records (7.2), no internal audit program (9.2), no management review (9.3). Score them before the controls, because a weak clause score changes the priority of everything below it.
- Assess all 93 controls, then decide applicability. Scoring a control before deciding whether it applies avoids the temptation to exclude what is hard. The ISO 27001 control assessment, covered in our Annex A scoring guide, is the detailed version of this step.
- Record evidence against every 3 and 4. The evidence column is the assessment’s value; a score without it is an opinion.
- Have someone else sample it. Ten controls, chosen by the reviewer, evidence produced on request. If three of ten cannot be evidenced, the whole assessment is optimistic by that ratio.
- Convert the scores into a plan. Every 0, 1 and 2 becomes a remediation item with an owner and a date. That list is the gap assessment, which our guide to the ISO 27001 gap assessment covers, and the plan is what the assessment report presents.
ISO 27001 self-assessment vs the other assessments
| Assessment | Who performs it | Against what | Purpose | Required by the standard? |
|---|---|---|---|---|
| Self-assessment | The organization, usually the ISMS owner | Clauses 4–10 and Annex A | Establish current position; baseline for planning | No |
| Gap assessment | Internal or consultant | Same, focused on what is missing | Prioritized remediation plan before implementation | No |
| Risk assessment | The organization | Threats and vulnerabilities to information assets | Select controls and justify the SoA | Yes — clause 6.1.2 |
| Internal audit | Independent internal auditor or contracted auditor | The organization’s own ISMS requirements and the standard | Evidence the ISMS conforms and is effective | Yes — clause 9.2 |
| Certification audit | Accredited certification body | The standard and the SoA | Issue or maintain the certificate | For certification |
The distinctions matter to auditors. A self-assessment is not an internal audit — clause 9.2 requires auditors who are objective and impartial, and the person who runs the ISMS scoring their own work does not qualify. A self-assessment is a management tool; the internal audit is the standard’s own check on it. Our guide to the ISO 27001 readiness assessment covers the six checks to run once the self-assessment scores are high enough to book a certification body.
Five ways an ISO 27001 self-assessment flatters its authors
- Scoring the document, not the practice. An approved access control policy is a 2 until the access reviews it requires have actually happened, with records.
- Excluding controls because they are hard. A.8.16 monitoring activities and A.8.15 logging are rarely genuinely inapplicable; a justification that amounts to “we do not do this” will not survive the SoA review.
- Assessing the IT team’s view of the organization. People controls (A.6), supplier controls (A.5.19–A.5.23) and physical controls (A.7) belong to HR, procurement and facilities. If they did not score their own controls, the scores are guesses.
- Treating 4 as the target everywhere. The standard requires effectiveness, not maximum maturity. A 3 with clean records is certifiable; a program that chases 4 on all 93 controls before certifying never certifies.
- Running it once. The self-assessment is a baseline. Re-scored quarterly it becomes the ISMS’s own performance measure under clause 9.1, and the trend is what management review wants to see.
Frequently asked questions
Is an ISO 27001 self-assessment required by the standard?
No. The standard requires a risk assessment (6.1.2), an internal audit (9.2) and management review (9.3). The self-assessment is the management tool that tells you whether you are ready for those; most organizations run one before implementation and again before the certification audit.
How many items does it score?
All requirements in clauses 4 to 10 and all 93 Annex A controls — 37 organizational, 8 people, 14 physical, 34 technological — with N/A available only for controls, with a justification.
Can we use the self-assessment as our internal audit?
No. Clause 9.2 requires objectivity and impartiality; the ISMS owner scoring their own system does not meet it. Use the self-assessment to prepare for the internal audit, not to replace it.
What score is ‘ready to certify’?
There is no official threshold. In practice, every clause requirement at 3 or above and every applicable control at 3 or above, with evidence named for each, is the position certification bodies expect at stage 2.
How long does a self-assessment take?
For a small scope with an experienced owner, two to four working days across the people who own the controls; longer if evidence has to be located rather than referenced.
Where this leaves you
Run the ISO 27001 self-assessment as a scored, evidenced inventory of clauses 4–10 and all 93 controls, with the owners of each area scoring their own, a reviewer sampling the evidence, and every score below 3 converted into a dated action. Then repeat it on a cycle, because the trend between assessments is the clearest picture of the ISMS you will ever have.
References
- ISO/IEC 27001:2022 — The information security management system standard, including Amendment 1:2024.
- ISO/IEC 27002:2022 — Implementation guidance for the 93 Annex A controls.
More on ISO 27001 assessment
- The ISO 27001 self-assessment — you are here
- ISO 27001 readiness assessment: six checks
- ISO 27001 maturity assessment: six levels
- ISO 27001 gap assessment: the four outputs
- ISO 27001 control assessment: scoring Annex A
- ISO 27001 tools: the four categories
A scored questionnaire covering the clauses and all 93 controls, with automatic scoring, risk analysis and summary dashboards, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.