ISO 27001 gap analysis: how to run one and what to do next

How to run an ISO 27001 gap analysis against the 2022 standard: how it differs from an internal audit and a readiness assessment, who runs it, a clause-by-clause structure, how to score gaps honestly, and how to turn the report into a certification plan.

The short answer: An ISO 27001 gap analysis compares what your organisation does today against every requirement in ISO/IEC 27001:2022, clauses 4 to 10 plus the 93 Annex A controls, and records where you fall short. The output is a scored list of gaps, each with an owner and an effort estimate, which becomes your implementation plan. Run it before you build an ISO 27001 information security management system, and again before you book the certification audit. It is not an internal audit and does not replace one.

Most gap analyses get commissioned because a customer asked for the certificate and someone has to tell the board how far away it is. This is where the project takes its real shape: scope, budget, timeline, and the awkward conversation about who owns supplier due diligence. Get it wrong and you build the wrong ISMS at speed. Skip it and you find the gaps at stage 2, on the auditor's clock.

{{snapshot}}

ISO 27001 gap analysis at a glance

  • What it measures: current practice against clauses 4 to 10 and the four Annex A themes (organisational, people, physical, technological).
  • What it produces: a scored gap register with owners, effort and priority, which becomes the implementation plan.
  • When to run it: before implementation starts, and again four to six weeks before stage 1 as a readiness check.
  • How long it takes: one to three weeks for a single-site company of under 100 people.
  • What it is not: an internal audit. Clause 9.2 still requires one, and no auditor accepts a gap report in its place.

{{/snapshot}}

Gap analysis, readiness assessment, internal audit: three different things

These terms get used interchangeably and should not be. A gap analysis is a one-off diagnostic run before you have an ISMS, or before you have finished one. It asks what the standard requires and what you have. Nobody checks whether a control operates effectively, because most do not exist yet.

A readiness assessment is the same exercise pointed at the audit rather than the standard. It assumes the ISMS is built and asks whether the evidence would survive a stage 1 document review and a stage 2 site visit. A short, self-scored version tells you whether you are three weeks or three months away.

An internal audit is a clause 9.2 requirement: planned, independent of the work being audited, sampled against real evidence, and reported into management review. Certification bodies expect at least one full cycle before stage 2. The clause 9.2 internal audit guide covers what independence means when you have 30 staff. Present a gap analysis as your internal audit and you collect a non-conformity for the audit itself, a special kind of embarrassing.

Who should run it, and how long it takes

Three options, in ascending order of cost. Your own project owner with a good checklist and a fortnight of protected time. An external consultant, typically two to five days of interviews plus a report. Or a platform that walks you through the requirements and stores the answers as the first draft of your evidence library, so the gap analysis becomes the project.

Self-run works when the assessor has read the standard rather than a summary, and has the seniority to get honest answers out of engineering, HR and finance. It fails when the assessor is also the person who will be blamed for the gaps. In small businesses those are usually the same person, which is the strongest argument for a guided assessment over a blank spreadsheet. Consultants earn their fee on a first certification with no in-house experience. They are poor value when the gaps are obvious and the real problem is capacity.

A single-site firm of 20 to 100 people should expect one to three weeks from kick-off to a report you can plan against. Multi-entity or regulated businesses take longer, mostly because agreeing scope takes longer. Feed the scored output into the certification timeline tool and the ISO 27001 cost calculator for a date and a budget the board can argue with.

How to structure an ISO 27001 gap analysis

Work through the standard in the order it is written. Clauses 4 to 10 are the management system; Annex A is the control set you will later justify in the Statement of Applicability. For every area, record what good looks like, what you have, and what evidence you would show an auditor. Blank cells are gaps. Work from the standard itself, not a summary.

Area assessedWhat good looks likeTypical gapEvidence to collect
Clause 4: context and scopeDocumented scope with boundaries, interfaces and interested partiesNo scope statement, or "the whole company" with nothing excluded and nothing justifiedScope document, interested parties register, organisation chart
Clause 5: leadershipApproved security policy, defined roles, visible management commitmentPolicy exists but nobody senior has signed or read itSigned policy, role descriptions, leadership minutes
Clause 6: planningWritten risk method, risk treatment plan, measurable objectives, Statement of ApplicabilityNo written method; risks copied from a template registerRisk methodology, risk register, treatment plan, SoA
Clause 7: supportCompetence records, awareness training, controlled documentsTraining ran once; documents have no owner or versionTraining records, document register
Clause 8: operationRisk assessment repeated at planned intervals and on significant changeAssessment done at implementation and never revisitedDated risk assessment results, change records
Clause 9: performance evaluationInternal audit programme, management review with recorded inputs and outputsNo internal audit; management review is a calendar invite with no minutesAudit programme, audit reports, management review minutes
Clause 10: improvementNon-conformities logged with root cause and corrective actionIssues fixed informally in Slack with nothing recordedNon-conformity log, corrective action records
Annex A: organisational (37 controls)Supplier, asset, access and incident processes defined and ownedSupplier contracts with no security clauses; no asset registerSupplier register, asset inventory, incident log
Annex A: people (8 controls)Screening, contract terms, awareness, disciplinary process, remote working rulesBackground checks skipped for contractorsHR onboarding records, signed agreements, training completion
Annex A: physical (14 controls)Secure areas, clear desk, equipment disposal, off-site assetsOffice access relies on a door code unchanged since 2019Visitor logs, disposal certificates, access lists
Annex A: technological (34 controls)Logging, backup, malware protection, secure development, configuration managementBackups exist but restores are never tested; MFA is partialBackup test records, MFA coverage reports, configuration baselines

Two rules make this useful. Collect the evidence column as you go, even for areas that pass, because it becomes the skeleton of your evidence library. And nobody answers yes to a row without naming the document or system that proves it. "We do that" is not a finding.

Scoring gaps without fooling yourself

A gap analysis with three states (yes, no, partial) produces a report where most rows say partial and nobody learns anything. Use a maturity scale with at least four levels: nothing in place, informal practice, documented but not operating, operating with evidence. Score every clause and every applicable control, then weight by effort and audit risk. A missing management review is a fast fix with high audit risk. An untested backup restore is slower and, for a SaaS company, existential.

Keep the scoring honest by separating the assessor from the owner. Whoever runs your infrastructure will rate patching as operating with evidence because they know it happens. The real question is whether a stranger could confirm it in twenty minutes from records alone. If not, it scores documented but not operating. That is the test an auditor applies.

Annex A controls need a decision before they get a score. If you have not drafted your Statement of Applicability, do a first pass now: mark each control applicable or not, with a one-line justification. Scoring controls you will later exclude wastes a day and tempts people to keep them "just in case".

The gaps we see most often

The pattern repeats across sectors and company sizes.

  • No scope, or a scope nobody can defend. Clause 4.3 asks for a documented scope with boundaries and interfaces. First-timers tend to have nothing, or "the whole company" covering three legal entities and a product in beta. Fix this first, because every other gap changes size with it. Our guide to ISO 27001 scope has three worked scope statements to borrow.
  • No risk method. A register full of risks copied from a template, with no written methodology explaining how likelihood and impact were scored or what level of risk the business will accept. Auditors read the method before the register. The ISO 27001 risk assessment page walks through a scoring approach that holds up under clause 6.1.2.
  • Policies nobody reads. Twenty documents from a policy pack, naming a CISO you do not employ and a change board that has never met. Rewrite them until they describe what your team does, then get them attested. The ISO 27001 documentation guide separates what must be written down from what is optional, which is less than the pack implies.
  • No evidence trail. The controls run. The proof lives in an inbox, a Slack thread and a folder one person understands. This is the gap that turns a two-month project into a nine-month one, and the one a gap analysis most reliably catches, provided you insisted on the evidence column.

Turning the gap report into a project plan

The report is worth what happens on the Monday after it lands. Convert every scored gap into a task with an owner, effort estimate and target date, then sequence in dependency order rather than by severity: scope, then the risk method, then the risk assessment, then the SoA, then policies, then the technical controls the treatment plan calls for. Writing policies first because they look easy produces documents that contradict the risk assessment you write afterwards.

Track the gaps somewhere with live control status, not the spreadsheet you ran the analysis in. Controls Monitor holds each control's status and evidence and generates the SoA from the control set, so the gap register and the ISMS are the same object rather than two files drifting apart. Net-Defence, a UK cyber-resilience and IT MSP, moved off spreadsheets and reached ISO 27001 compliance roughly 50% faster; its managing director said the result "far exceeded what we originally thought we would get from it". Advantex, a UK IT and comms integrator already holding ISO 9001 and Cyber Essentials Plus, cut audit preparation time by 30 to 40% once gaps and evidence lived in one place.

Re-run the analysis four to six weeks before stage 1. Same structure, same scoring, different question: no longer "do we have it" but "could an auditor find it". Anything still below operating with evidence is what you fix in the final month. Nothing else gets added.

{{snapshot}}

Hicomply's take

We have read a lot of gap reports, and the worst ones were written to reassure. Fifty rows of "partial", no evidence column, no owners, and a summary saying the organisation is "well positioned". Six months later the same company is scrambling before stage 2. The reports that work are uncomfortable: they name the missing scope statement, say the risk register was copied, and attach an effort estimate to every line. Score harshly, insist on evidence for every yes, and run the analysis inside the tool you will run the ISMS in, so the answers become your evidence library rather than a PDF nobody opens again.

{{/snapshot}}

Find the gaps before the auditor does

A gap analysis done properly is the cheapest week of the whole certification. It sets the scope, sizes the budget, and tells you which four gaps out of forty matter.

Start with the free ISO 27001 readiness assessment for a first read on where you stand, then book a demo and we will run the structure above against your scope, with the answers landing in a platform that typically gets you audit-ready in two to three months rather than a spreadsheet you abandon by stage 1.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
September 18, 2026
Category
ISO 27001 Implementation
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 Gap Analysis queries, answered!

What is an ISO 27001 gap analysis?

An ISO 27001 gap analysis compares your organisation's current practices against every requirement of ISO/IEC 27001:2022, clauses 4 to 10 and the 93 Annex A controls, and records where you fall short. The output is a scored list of gaps with owners and effort estimates. It is a diagnostic run before implementation, and again before certification, to shape the project plan.

What is the difference between a gap analysis and an internal audit?

A gap analysis is a one-off diagnostic that asks what the standard requires and what you have, usually before the ISMS is built. An internal audit is a clause 9.2 requirement: planned, independent, sampled against real evidence and reported to management review. Certification bodies expect at least one internal audit before stage 2, and a gap analysis cannot be substituted for it.

How long does an ISO 27001 gap analysis take?

For a single-site company of 20 to 100 people, expect one to three weeks from kick-off to a scored report you can plan against. A consultant typically spends two to five days on interviews plus report writing. Multi-site, multi-entity or regulated businesses take longer because agreeing the ISMS scope takes longer, and scope drives everything else.

Who should carry out an ISO 27001 gap analysis?

Either an internal project owner who has read the full standard and has the seniority to get honest answers, an external consultant, or a platform-guided assessment. Self-run works well when the assessor is not the person who will be blamed for the gaps. Consultants add most value on a first certification with no in-house experience or after a stalled attempt.

What are the most common gaps found in an ISO 27001 gap analysis?

Four gaps appear almost every time: no documented ISMS scope, or one covering the whole company with nothing justified; no written risk assessment method behind the risk register; policies downloaded from a template pack that nobody has adapted or attested; and no evidence trail, with proof scattered across inboxes, chat threads and personal folders.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO 27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO 27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative