Skip to content

ISO 27001

ISO 27001 gap analysis

A gap analysis compares what your organisation does today with what ISO/IEC 27001:2022 asks for, so you know what to build before a certification audit. This guide gives a method, a rating scale, a worked example and a way to turn the gaps into a plan.

Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.

What a gap analysis is

A gap analysis is a structured look at your current practice against the standard, item by item. For each item you record what exists, how mature it is, what is missing and what evidence you could show. The output is a list of gaps with ratings, and a plan to close them.

It covers two different things. Clauses 4 to 10 are the management system: every one of them applies, and none can be excluded. Annex A is the reference list of 93 controls: which ones apply depends on your risk assessment. A gap analysis that only looks at Annex A misses the management system, which a certification audit examines just as closely.

Set the scope first

Agree the scope of the information security management system (ISMS) before you rate anything, even as a draft. Every rating depends on it: a control can be missing in one office and fine in another. The requirements guide covers how the standard expects scope to be set.

  • Which parts of the organisation, which locations, and which products or services are in.
  • Which systems, networks and cloud services support them, including internet-facing domains.
  • Which suppliers and other organisations you depend on, and where the boundary with them sits.
  • What is out, and why. An exclusion that leaves the most sensitive information outside the ISMS will be questioned.

A rating scale

Use a short scale that people rate consistently. This one asks whether a practice exists, whether it is written down, and whether there are records to show it working. It is our scale for planning, not one the standard defines.

RatingMeaningWhat you would see
0 AbsentNothing in placeNo document, no owner, no practice
1 InformalDone sometimes, depending on individualsPeople can describe it, but nothing is written and there are no records
2 DefinedWritten down, but not yet working consistentlyA policy or procedure exists, with few or no records, and has not been reviewed
3 OperatingDefined, followed and recordedAn owner, records over a period, and evidence of review
N/AAnnex A only: the control does not applyA reason that would stand up in the Statement of Applicability

Rating 3 is what an auditor needs to see. Rating 2 is an easy trap: the document is written, so the item feels done, but there is nothing to show it is followed. Clauses 4 to 10 never take N/A.

Working through clauses 4 to 10

Take each clause in turn and rate each of its parts. The table shows what to look for, in our words, and the evidence that usually shows it.

ClauseWhat to look forTypical evidence
4 Context of the organisationThe issues that affect security, the interested parties and their requirements, a defined scope, and the processes of the ISMS. Since Amendment 1:2024, also whether climate change is a relevant issue.Context and interested parties register, scope statement
5 LeadershipTop management directing and supporting the ISMS, an approved policy, and assigned roles and authoritiesApproved policy, roles document, minutes showing management involvement
6 PlanningRisk criteria, a repeatable risk assessment, risk treatment, a Statement of Applicability, a treatment plan approved by risk owners, measurable objectives, and planned changesRisk method, risk register, Statement of Applicability, treatment plan, objectives
7 SupportResources, competence, awareness, communication, and control of documents and recordsTraining and competence records, communication plan, document register
8 OperationProcesses running as planned, external suppliers relevant to the ISMS under control, risk assessments repeated, and the treatment plan carried outOperating records, updated risk assessments, treatment progress
9 Performance evaluationDefined monitoring and measurement, an internal audit programme, and management reviewMeasurement results, audit reports, management review minutes
10 ImprovementNonconformities found and handled with corrective action, and continual improvementCorrective action log, records of improvements

Clause 6 carries the most weight. Without a working risk assessment you cannot decide which controls apply, and without that you cannot write the Statement of Applicability.

Working through Annex A

Go through the 93 controls theme by theme. For each one, ask whether it is likely to be needed for a risk in scope, then rate what is in place. Before the risk assessment is done, treat applicability as provisional; the risk assessment, not the gap analysis, decides it.

  • Organisational controls (5.1 to 5.37): policies, roles, assets, access, suppliers, incidents, continuity, legal.
  • People controls (6.1 to 6.8): screening, contracts, training, leaving, remote working, reporting.
  • Physical controls (7.1 to 7.14): premises, equipment and media, including equipment at home.
  • Technological controls (8.1 to 8.34): devices, access, vulnerabilities, configuration, logging, networks, cryptography, development.

Some controls have a public, technical side you can check in minutes: how your domains handle email authentication and TLS, which software your sites reveal, and which services answer from the internet. Checking those early gives you facts rather than opinions for part of the rating. The controls guide lists which controls this applies to.

A worked example

An illustrative extract for a fictional 60-person software company preparing for its first certification. Clause references are plain numbers; Annex A controls carry an A.

Illustrative gap analysis extract. The organisation and its findings are invented.
RefFoundRatingAction
4.3 ScopeAgreed verbally as "the SaaS platform"; office IT not decided1Write the scope with its boundaries and interfaces; decide on office IT
5.2 PolicyA policy from 2023 exists but was never approved by the board2Update, approve at board level, publish to staff
6.1.2 Risk assessmentA spreadsheet of risks without owners or criteria1Define criteria and a method, assign owners, run it again
6.1.3 Statement of ApplicabilityNone0Draft once risk treatment is decided
9.2 Internal auditNone0Plan an audit programme; complete a first audit before the certification audit
A.5.9 InventoryA cloud asset list exists; certificate transparency logs show six hostnames not on it2Add or retire the hostnames and give each an owner
A.5.14 Information transferDMARC published at p=none on the main domain; no rules for file sharing1Move DMARC towards enforcement; write transfer rules
A.8.8 Technical vulnerabilitiesServer patching is automated; the marketing site runs end-of-life software2Upgrade or retire the site and bring it into the patching process
A.8.24 CryptographyA legacy API host still accepts TLS 1.0; no cryptography rules1Disable old protocol versions; write and approve cryptography rules
A.6.3 Awareness and trainingTraining at onboarding only, not recorded1Yearly refresher with attendance records

Note what the extract shows. The management system gaps (scope, risk, audit) are the ones that block certification. The technical gaps were found quickly and are mostly cheap to fix, but each still needs an owner and a rule behind it.

Collecting evidence

Rate from evidence, not from memory. For each item, note what you would show an auditor and where it lives. Evidence comes in two kinds, and it helps to keep them apart.

  • Technical evidence shows how systems are configured and behave: settings, scan results, logs, screenshots of configuration.
  • Organisational evidence shows that the ISMS is managed: documents, decisions, records of review, training records, audit reports, meeting minutes.

Evidence for an ISO 27001 gap analysis

Ironfang can check

  • Dated results of the External Security Check for DNS, email authentication, TLS, HTTP headers, technologies and certificate transparency
  • For verified domains, which of 21 fixed ports accept connections
  • A history per domain, rechecks after fixes, and notices when monitored configuration changes
  • Supporting evidence for parts of 5.9, 5.14, 8.8, 8.9, 8.16, 8.20, 8.21, 8.24 and 8.26

The organisation must establish

  • The scope, the policy, roles and the risk method
  • The risk register, risk treatment plan and Statement of Applicability
  • Objectives, monitoring results, internal audit reports and management review minutes
  • Training records, supplier reviews, incident records and corrective actions
  • Every control that cannot be seen from the internet

Documented information the standard asks for

Some evidence is required in its own right. In our words, ISO/IEC 27001 expects you to keep at least:

  • The ISMS scope (4.3) and the information security policy (5.2).
  • The risk assessment and risk treatment processes and their results (6.1.2, 6.1.3, 8.2, 8.3).
  • The Statement of Applicability and the risk treatment plan (6.1.3).
  • Information security objectives (6.2).
  • Evidence of competence (7.2), and the other documents and records you decide the ISMS needs (7.5).
  • Records of monitoring and measurement, the audit programme and audit results, and management review results (9.1, 9.2, 9.3).
  • Nonconformities, the actions taken and their results (10.2).

Good habits

  • Date everything, and keep the version that was in force at the time.
  • Record who owns each piece of evidence and where it is kept.
  • Prefer records that are produced as a by-product of work, such as tickets, logs and scheduled check results, to documents written for the audit.
  • Start early. Records over a period are stronger than a pile created the week before the audit.

Priorities and a plan

Sort the gaps in the order the work depends on, not by how easy they are.

  1. Foundations: scope, policy, roles and the risk method. Everything else depends on them.
  2. Risk: run the risk assessment, decide treatment, then write the Statement of Applicability.
  3. High-risk control gaps, starting with what is exposed to the internet, which is quick to check and often quick to fix.
  4. Records: start producing them as soon as each process exists, so the ISMS has a track record.
  5. Assurance: an internal audit and a management review, which are clause 9 requirements, before the certification audit.

Turn each gap into an action with an owner, a target date, any dependency, and a definition of done that names the evidence it will produce. Re-rate after each phase. When the ratings settle at 3, the items are ready to be tested, by your internal audit first.

The ISO 27001 checklist turns the clauses and the most common controls into items you can tick as they are done.

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.