
An ISO 27001 gap analysis is an internal readiness review that compares your current information security management system, documentation, controls, and evidence against the ISO/IEC 27001 requirements that apply to your organisation.
For this article, that means a practical comparison against ISO/IEC 27001:2022 clauses, selected Annex A controls, your Statement of Applicability, and the evidence available to show that controls are actually operating. ISO/IEC 27001:2022 specifies requirements for an information security management system, or ISMS, and supports its establishment, implementation, maintenance, and continual improvement using a risk-management process (ISO).
The output should not be a simple pass/fail checklist, a useful gap analysis produces evidence-backed findings, prioritised remediation actions, owners, target dates, and closure evidence.
What Is An ISO 27001 Gap Analysis?
An ISO 27001 gap analysis is an internal comparison of the organisation’s current ISMS against applicable ISO/IEC 27001 requirements, selected controls, and available evidence.
It helps identify areas that are:
- missing entirely
- partially implemented
- documented but not operating
- operating but poorly evidenced
- inconsistent with the organisation’s defined ISMS scope, risks, or Statement of Applicability
Not a certification audit. Implementing ISO/IEC 27001 and seeking certification are separate choices, and certification is performed by a certification body (ISO). A gap analysis can support certification preparation, but it cannot prove conformity or guarantee a certification result.
The practical test is simple: can you trace each requirement or selected control to a current process, accountable owner, supporting documentation, and operating evidence? If not, the gap analysis should make that weakness visible and actionable.
When Should You Perform An ISO 27001 Gap Analysis?
Consider performing or refreshing an ISO 27001 gap analysis when the result will change implementation priorities or audit preparation.
Common trigger points include:
- Before starting ISO 27001 implementation: to understand baseline readiness and avoid building the project around assumptions.
- After defining ISMS scope: so the review has clear organisational, process, technology, and location boundaries.
- Before internal audit preparation: to identify evidence gaps before the internal audit has to test them.
- Before external certification preparation: to check whether known weaknesses have owners, actions, and closure evidence.
- After major change: such as new systems, acquisitions, outsourcing changes, restructuring, or material process changes.
- When inheriting an immature ISMS: especially where policies exist but ownership, operating records, or risk-treatment links are unclear.
Do not treat this as a one-time spreadsheet exercise. A gap analysis is most useful when it becomes a controlled remediation and evidence-readiness process.
What Should An ISO 27001 Gap Analysis Assess?
A readiness review can be structured around ISO/IEC 27001:2022 clauses 4–10: context, leadership, planning and information-security risk management, support, operation, performance evaluation, and improvement (ISO/IEC JTC 1/SC 27).
At a practical level, assess these areas:
| Assessment area | What to review | Evidence to look for |
|---|---|---|
| ISMS scope and context | Boundaries, interested parties, internal and external issues | Scope statement, context analysis, applicability decisions |
| Leadership and governance | Roles, responsibilities, accountability, policy approval | Approved policies, role assignments, meeting records |
| Risk assessment and treatment | Risk methodology, risk register, treatment decisions | Risk assessment outputs, treatment plans, review records |
| Statement of Applicability | Control applicability, exclusions, selected controls | Current SoA, rationale for inclusion/exclusion, links to risks |
| Documented information | Policies, procedures, records, version control | Approved documents, review history, controlled repositories |
| Annex A controls | Controls selected through risk treatment and SoA decisions | Control documentation and operating evidence |
| Operation | Whether planned ISMS processes are performed | Logs, tickets, approvals, access reviews, change records |
| Performance evaluation | Monitoring, internal audit, management review | Metrics, audit plans, audit reports, management-review records |
| Improvement | Nonconformities, corrective actions, lessons learned | Corrective-action records, closure evidence, follow-up reviews |
In risk treatment, the organisation determines the controls needed to reduce information-security risk, compares them with Annex A to check that no necessary control was omitted, and documents necessary controls and applicability decisions in the Statement of Applicability (ISO/IEC JTC 1/SC 27).
Annex A in ISO/IEC 27001:2022 contains 93 reference controls grouped as organisational, people, physical, and technological controls, but their relevance depends on the organisation’s context and risk treatment (ISO/IEC JTC 1/SC 27). Do not assess Annex A as though every control automatically applies — or, more precisely, as though every reference control must be implemented.
Evidence quality matters. A draft policy is not the same as evidence that a control is implemented, monitored, and reviewed. For certification-readiness purposes, distinguish documented policies and procedures from evidence that the ISMS is being implemented and evaluated, such as internal-audit and management-review activity (UKAS).
How To Perform An ISO 27001 Gap Analysis
A practical workflow is:
-
Confirm the ISMS scope and assessment objective
Define what business units, systems, processes, locations, and third parties are included. Be clear on whether the review is for baseline planning, internal audit preparation, or certification readiness. -
Map applicable requirements and selected controls
Use ISO/IEC 27001 clauses 4–10 as the management-system baseline. Then review the SoA and risk-treatment decisions to identify relevant Annex A and custom controls. -
Collect documentation and operating evidence
Gather policies, procedures, risk records, SoA, control descriptions, review records, audit records, incidents, corrective actions, management-review outputs, and other evidence relevant to the scope. -
Interview process and control owners where needed
Use interviews to understand how processes actually work, who owns them, and whether records are complete. Do not rely on interviews alone where operating evidence should exist. -
Compare current state with expected requirement or control intent
Record whether the requirement is met, partially met, not met, or not evidenced. Keep implementation weakness separate from evidence weakness. -
Document each gap with evidence and impact
A finding should explain what was reviewed, what was missing or weak, why it matters, and what decision or action is needed. -
Classify and prioritise gaps
Use internal prioritisation criteria such as implementation status, evidence quality, risk impact, audit-readiness impact, dependencies, and remediation effort. -
Assign remediation owners and target dates
Every material finding should have an accountable owner, action, expected output, and target date. -
Validate closure with evidence
Do not close a gap just because an action was discussed or a document was drafted. Closure should be supported by agreed evidence, such as an approved document, completed review, updated risk record, or repeatable operating record.
The key is traceability: requirement or control → current state → evidence reviewed → gap → owner → remediation → closure evidence.
ISO 27001 Gap Analysis Template: Fields To Capture
Use the following structure as an internal working template. It is not an official ISO template, but it gives the analysis enough detail to support remediation and readiness tracking.
| Field | What to capture | Why it matters |
|---|---|---|
| ISO 27001 clause or Annex A/control area | Clause, requirement area, or selected control reference | Creates traceability to the assessment baseline |
| Requirement or control objective | Plain-language summary of what is expected | Helps non-specialist owners understand the issue |
| Current state | What currently exists or happens | Separates actual practice from intended practice |
| Evidence reviewed | Documents, records, screenshots, logs, tickets, interviews, or samples | Shows what the finding is based on |
| Evidence quality | Absent, weak, partial, current and repeatable | Distinguishes missing evidence from weak implementation |
| Gap description | What is missing, incomplete, inconsistent, or not evidenced | States the finding clearly |
| Risk or business impact | Why the gap matters to the ISMS, risk treatment, audit readiness, or operations | Supports prioritisation |
| Priority or severity | Internal rating such as high, medium, low | Helps sequence remediation |
| Remediation action | Specific action needed to address the gap | Turns the finding into work |
| Owner | Named role or accountable person | Prevents orphaned findings |
| Target date | Agreed date or milestone | Supports tracking |
| Status | Open, in progress, awaiting evidence, closed | Shows current progress |
| Closure evidence | Evidence required before the gap is treated as resolved internally | Prevents premature closure |
The most common failure is leaving the “evidence reviewed” and “closure evidence” fields vague. “Policy exists” may not be enough if the issue is whether the process operates consistently.
How To Score And Prioritise ISO 27001 Gaps
Scoring is an internal prioritisation tool. It is not a certification result and should not be presented as an auditor-approved rating.
A simple approach is to classify each gap across four dimensions:
| Dimension | Low concern | Medium concern | High concern |
|---|---|---|---|
| Implementation status | Implemented and evidenced | Partially implemented or inconsistent | Not implemented, undocumented, or owner unknown |
| Evidence quality | Current, repeatable evidence exists | Some evidence exists but is incomplete or outdated | No reliable evidence available |
| ISMS impact | Limited local improvement | Affects a process, record, or control area | Affects core ISMS operation, risk treatment, SoA, governance, or audit preparation |
| Remediation dependency | Can be fixed independently | Requires coordination across teams | Blocks or delays several other remediation actions |
Use the rating to decide sequence, not to create false precision. A gap with weak evidence for a core ISMS process may deserve higher priority than a larger-looking documentation issue with limited operational impact.
A practical priority rule is:
- High priority: gaps that affect core ISMS processes, risk assessment or treatment, SoA accuracy, governance, internal audit preparation, or evidence needed to show controls are operating.
- Medium priority: gaps that show partial implementation, inconsistent records, unclear ownership, or outdated documentation.
- Low priority: improvements, formatting issues, minor documentation refinements, or evidence improvements that do not materially affect readiness or risk decisions.
When in doubt, prioritise gaps that are evidence-critical, dependency-heavy, or likely to prevent a clear assessment, a clear assessment of whether the ISMS is working.
Example: From Gap Finding To Remediation Action
The example below shows how one finding can be recorded as executable remediation work. It avoids a specific control number because control applicability should be confirmed against the organisation’s SoA and risk-treatment decisions.
| Field | Example entry |
|---|---|
| ISO 27001 clause or Annex A/control area | Annex A access control area selected in the SoA |
| Requirement or control objective | User access rights should be reviewed in line with the organisation’s access-control process |
| Current state | Access reviews are described in the access-control procedure, but the last completed review record only covers one business application |
| Evidence reviewed | Access-control procedure, SoA entry, sample access-review spreadsheet, interview with IT operations owner |
| Evidence quality | Partial |
| Gap description | The organisation cannot currently evidence that access reviews are performed consistently across in-scope systems |
| Risk or business impact | Excess or inappropriate access may remain unidentified; certification-readiness evidence is incomplete for a selected control area |
| Priority or severity | High |
| Remediation action | Define the in-scope system list for access reviews, assign review owners, complete access reviews for each in-scope system, record exceptions and approvals, and update the procedure if responsibilities differ from current practice |
| Owner | IT operations lead, with system owners accountable for review completion |
| Target date | Before the planned internal audit readiness review |
| Status | Open |
| Closure evidence | Completed access-review records for all in-scope systems, documented exceptions, owner approvals, and updated procedure if required |
The point is not the specific access-control example. The point is the structure: the finding explains the evidence reviewed, the weakness, the impact, the owner, the action, and the evidence needed for internal closure.
What Should The Final Gap Analysis Report Include?
The final report should be concise enough for decision-makers to use, but detailed enough for owners to act on. Include:
- Scope and assumptions: ISMS boundaries, systems, processes, locations, and exclusions considered during the review.
- Assessment method: documents reviewed, interviews performed, sampling approach, and any limitations.
- Requirements and control areas reviewed: ISO 27001 clause areas, SoA coverage, selected Annex A or custom controls.
- Readiness themes: recurring weaknesses, such as poor evidence retention, unclear ownership, outdated risk records, or incomplete management review inputs.
- Detailed findings: each gap with requirement/control area, current state, evidence reviewed, impact, and priority.
- Remediation plan: action, owner, target date, dependency, and expected closure evidence.
- Open questions: issues requiring clarification by internal leadership, control owners, legal, security, or an external adviser.
- Closure validation approach: how the organisation will confirm that actions are complete before internal audit or certification preparation continues.
Frame the report as an internal readiness and remediation artefact. Its value is not the number of findings; it is whether the findings become owned work and whether closure is evidenced.
ISO 27001 Gap Analysis Vs Risk Assessment Vs Maturity Assessment
These activities are related, but they answer different questions.
| Activity | Main question | Typical output | How it relates |
|---|---|---|---|
| Gap analysis | How does our current ISMS compare with applicable ISO 27001 requirements, selected controls, and evidence expectations? | Findings, priorities, remediation actions, closure evidence | Can reveal missing processes, weak evidence, or incomplete control implementation |
| Risk assessment | What information-security risks affect the organisation, and how should they be evaluated? | Risk register, risk evaluation, risk-treatment inputs | Informs control decisions and treatment priorities |
| Maturity assessment | How developed, repeatable, or optimised are our practices? | Maturity ratings, improvement themes | Can support improvement planning but is not the same as compliance status |
Risk assessment and treatment are part of the ISO/IEC 27001 ISMS. The gap analysis may identify weaknesses in those processes, but it should not replace them. Likewise, a mature process may still have a compliance or evidence gap, and a compliant process may not be highly mature.
What To Do After The Gap Analysis
After the review, convert the findings into controlled remediation work:
- confirm priorities with ISMS leadership and relevant control owners
- assign owners and due dates
- update policies, processes, SoA entries, or risk-treatment records where findings show they are incomplete or inaccurate
- collect missing operating evidence
- validate closure before relying on the result for internal audit or certification preparation
- keep evidence current rather than rebuilding it for each review
A gap analysis is only useful if it moves beyond static tracking. If your team uses an operational compliance system such as Ciphrix, this is the point to move findings into owned remediation, evidence collection, and recurring control-management workflows instead of relying only on spreadsheets.
Basically, the practical outcome should be clear: each material gap has evidence, impact, priority, ownership, and a defined path to closure.
