Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 self-assessment explained

ISO 27001 Self-Assessment: A Clear Guide to Scoring All 93 Controls

An ISO 27001 self-assessment is the exercise an organization runs on itself, before any auditor arrives, to score how far its information security management system meets ISO/IEC 27001:2022 — the seven management-system clauses and the 93 Annex A controls. Done properly it is the cheapest piece of assurance in the whole certification journey, because it turns “we think we are mostly there” into a numbered list of what is not. Done badly it produces a green dashboard that the stage 1 audit dismantles in an afternoon. This guide explains what an ISO 27001 self-assessment covers, the scoring scale that makes it useful, how to evidence each score, how it differs from a gap assessment, internal audit and certification audit, and the five ways self-assessments flatter their authors.

ISO 27001 self-assessment: clauses 4–10 plus 93 controls on a 5-point scale
The self-assessment scores every requirement and every applicable control, with evidence recorded against each score.

What an ISO 27001 self-assessment covers

ISO 27001:2022 has two assessable parts. Clauses 4 to 10 are the management system — context, leadership, planning, support, operation, performance evaluation, improvement — and every requirement in them is mandatory. Annex A lists 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Controls are not individually mandatory; the organization selects them through its risk treatment and records the selection, and any exclusions, in the Statement of Applicability under clause 6.1.3. A complete ISO 27001 self-assessment therefore scores every clause requirement and every control the organization has declared applicable — and, on a first pass before the SoA exists, all 93.

The 2022 edition also carries Amendment 1 of 2024, which adds climate change as a consideration in clause 4.1 and a note at 4.2. It is a small change but a self-assessment built on a 2022 checklist without it is already out of date. The 2013-to-2022 transition closed on 31 October 2025, so there is no reason to assess against the old 114-control Annex A.

The scoring scale

A binary yes/no self-assessment hides the difference between “we have a policy” and “we have a policy, it is followed and we can prove it”. A five-point implementation scale separates them:

Score Label Meaning Evidence expected
0 Not implemented Nothing in place; or the requirement is not understood None
1 Planned Approach agreed, owner named, not yet in operation Plan, draft document, decision record
2 Partially implemented In operation for part of the scope, or documented but not consistently followed Approved document; partial records
3 Implemented In operation across the scope as documented Approved document; operating records for the period
4 Implemented and verified Operating, monitored, reviewed; effectiveness evidenced As for 3, plus metrics, review minutes, audit results
N/A Not applicable Control excluded with a justification The SoA justification

Two rules keep the scale honest. A score of 3 or 4 requires a piece of evidence to be named — a document reference, a record location, a system report — not asserted. And N/A is only available for Annex A controls, never for clause requirements: every clause 4–10 requirement applies to every certified ISMS.

How to run an ISO 27001 self-assessment

  1. Fix the scope. Score against the ISMS scope you intend to certify, not the whole organization. If the scope is not yet written, writing it is the first finding.
  2. Assess the clauses first. Clause requirements are where first-time ISMSs fail stage 1: no documented scope (4.3), no information security objectives (6.2), no competence records (7.2), no internal audit program (9.2), no management review (9.3). Score them before the controls, because a weak clause score changes the priority of everything below it.
  3. Assess all 93 controls, then decide applicability. Scoring a control before deciding whether it applies avoids the temptation to exclude what is hard. The ISO 27001 control assessment, covered in our Annex A scoring guide, is the detailed version of this step.
  4. Record evidence against every 3 and 4. The evidence column is the assessment’s value; a score without it is an opinion.
  5. Have someone else sample it. Ten controls, chosen by the reviewer, evidence produced on request. If three of ten cannot be evidenced, the whole assessment is optimistic by that ratio.
  6. Convert the scores into a plan. Every 0, 1 and 2 becomes a remediation item with an owner and a date. That list is the gap assessment, which our guide to the ISO 27001 gap assessment covers, and the plan is what the assessment report presents.

ISO 27001 self-assessment vs the other assessments

Assessment Who performs it Against what Purpose Required by the standard?
Self-assessment The organization, usually the ISMS owner Clauses 4–10 and Annex A Establish current position; baseline for planning No
Gap assessment Internal or consultant Same, focused on what is missing Prioritized remediation plan before implementation No
Risk assessment The organization Threats and vulnerabilities to information assets Select controls and justify the SoA Yes — clause 6.1.2
Internal audit Independent internal auditor or contracted auditor The organization’s own ISMS requirements and the standard Evidence the ISMS conforms and is effective Yes — clause 9.2
Certification audit Accredited certification body The standard and the SoA Issue or maintain the certificate For certification

The distinctions matter to auditors. A self-assessment is not an internal audit — clause 9.2 requires auditors who are objective and impartial, and the person who runs the ISMS scoring their own work does not qualify. A self-assessment is a management tool; the internal audit is the standard’s own check on it. Our guide to the ISO 27001 readiness assessment covers the six checks to run once the self-assessment scores are high enough to book a certification body.

Five ways an ISO 27001 self-assessment flatters its authors

  1. Scoring the document, not the practice. An approved access control policy is a 2 until the access reviews it requires have actually happened, with records.
  2. Excluding controls because they are hard. A.8.16 monitoring activities and A.8.15 logging are rarely genuinely inapplicable; a justification that amounts to “we do not do this” will not survive the SoA review.
  3. Assessing the IT team’s view of the organization. People controls (A.6), supplier controls (A.5.19–A.5.23) and physical controls (A.7) belong to HR, procurement and facilities. If they did not score their own controls, the scores are guesses.
  4. Treating 4 as the target everywhere. The standard requires effectiveness, not maximum maturity. A 3 with clean records is certifiable; a program that chases 4 on all 93 controls before certifying never certifies.
  5. Running it once. The self-assessment is a baseline. Re-scored quarterly it becomes the ISMS’s own performance measure under clause 9.1, and the trend is what management review wants to see.

Frequently asked questions

Is an ISO 27001 self-assessment required by the standard?
No. The standard requires a risk assessment (6.1.2), an internal audit (9.2) and management review (9.3). The self-assessment is the management tool that tells you whether you are ready for those; most organizations run one before implementation and again before the certification audit.

How many items does it score?
All requirements in clauses 4 to 10 and all 93 Annex A controls — 37 organizational, 8 people, 14 physical, 34 technological — with N/A available only for controls, with a justification.

Can we use the self-assessment as our internal audit?
No. Clause 9.2 requires objectivity and impartiality; the ISMS owner scoring their own system does not meet it. Use the self-assessment to prepare for the internal audit, not to replace it.

What score is ‘ready to certify’?
There is no official threshold. In practice, every clause requirement at 3 or above and every applicable control at 3 or above, with evidence named for each, is the position certification bodies expect at stage 2.

How long does a self-assessment take?
For a small scope with an experienced owner, two to four working days across the people who own the controls; longer if evidence has to be located rather than referenced.

Where this leaves you

Run the ISO 27001 self-assessment as a scored, evidenced inventory of clauses 4–10 and all 93 controls, with the owners of each area scoring their own, a reviewer sampling the evidence, and every score below 3 converted into a dated action. Then repeat it on a cycle, because the trend between assessments is the clearest picture of the ISMS you will ever have.

References

  • ISO/IEC 27001:2022 — The information security management system standard, including Amendment 1:2024.
  • ISO/IEC 27002:2022 — Implementation guidance for the 93 Annex A controls.

More on ISO 27001 assessment

A scored questionnaire covering the clauses and all 93 controls, with automatic scoring, risk analysis and summary dashboards, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.