All posts
ISO 2700112 min readAug 16, 2026

ISO 27001 gap analysis

Ashish / CEO/Co-Founder
ISO 27001 gap analysis

An ISO 27001 gap analysis is an internal readiness review that compares your current information security management system, documentation, controls, and evidence against the ISO/IEC 27001 requirements that apply to your organisation.

For this article, that means a practical comparison against ISO/IEC 27001:2022 clauses, selected Annex A controls, your Statement of Applicability, and the evidence available to show that controls are actually operating. ISO/IEC 27001:2022 specifies requirements for an information security management system, or ISMS, and supports its establishment, implementation, maintenance, and continual improvement using a risk-management process (ISO).

The output should not be a simple pass/fail checklist, a useful gap analysis produces evidence-backed findings, prioritised remediation actions, owners, target dates, and closure evidence.

What Is An ISO 27001 Gap Analysis?

An ISO 27001 gap analysis is an internal comparison of the organisation’s current ISMS against applicable ISO/IEC 27001 requirements, selected controls, and available evidence.

It helps identify areas that are:

  • missing entirely
  • partially implemented
  • documented but not operating
  • operating but poorly evidenced
  • inconsistent with the organisation’s defined ISMS scope, risks, or Statement of Applicability

Not a certification audit. Implementing ISO/IEC 27001 and seeking certification are separate choices, and certification is performed by a certification body (ISO). A gap analysis can support certification preparation, but it cannot prove conformity or guarantee a certification result.

The practical test is simple: can you trace each requirement or selected control to a current process, accountable owner, supporting documentation, and operating evidence? If not, the gap analysis should make that weakness visible and actionable.

When Should You Perform An ISO 27001 Gap Analysis?

Consider performing or refreshing an ISO 27001 gap analysis when the result will change implementation priorities or audit preparation.

Common trigger points include:

  • Before starting ISO 27001 implementation: to understand baseline readiness and avoid building the project around assumptions.
  • After defining ISMS scope: so the review has clear organisational, process, technology, and location boundaries.
  • Before internal audit preparation: to identify evidence gaps before the internal audit has to test them.
  • Before external certification preparation: to check whether known weaknesses have owners, actions, and closure evidence.
  • After major change: such as new systems, acquisitions, outsourcing changes, restructuring, or material process changes.
  • When inheriting an immature ISMS: especially where policies exist but ownership, operating records, or risk-treatment links are unclear.

Do not treat this as a one-time spreadsheet exercise. A gap analysis is most useful when it becomes a controlled remediation and evidence-readiness process.

What Should An ISO 27001 Gap Analysis Assess?

A readiness review can be structured around ISO/IEC 27001:2022 clauses 4–10: context, leadership, planning and information-security risk management, support, operation, performance evaluation, and improvement (ISO/IEC JTC 1/SC 27).

At a practical level, assess these areas:

Assessment areaWhat to reviewEvidence to look for
ISMS scope and contextBoundaries, interested parties, internal and external issuesScope statement, context analysis, applicability decisions
Leadership and governanceRoles, responsibilities, accountability, policy approvalApproved policies, role assignments, meeting records
Risk assessment and treatmentRisk methodology, risk register, treatment decisionsRisk assessment outputs, treatment plans, review records
Statement of ApplicabilityControl applicability, exclusions, selected controlsCurrent SoA, rationale for inclusion/exclusion, links to risks
Documented informationPolicies, procedures, records, version controlApproved documents, review history, controlled repositories
Annex A controlsControls selected through risk treatment and SoA decisionsControl documentation and operating evidence
OperationWhether planned ISMS processes are performedLogs, tickets, approvals, access reviews, change records
Performance evaluationMonitoring, internal audit, management reviewMetrics, audit plans, audit reports, management-review records
ImprovementNonconformities, corrective actions, lessons learnedCorrective-action records, closure evidence, follow-up reviews

In risk treatment, the organisation determines the controls needed to reduce information-security risk, compares them with Annex A to check that no necessary control was omitted, and documents necessary controls and applicability decisions in the Statement of Applicability (ISO/IEC JTC 1/SC 27).

Annex A in ISO/IEC 27001:2022 contains 93 reference controls grouped as organisational, people, physical, and technological controls, but their relevance depends on the organisation’s context and risk treatment (ISO/IEC JTC 1/SC 27). Do not assess Annex A as though every control automatically applies — or, more precisely, as though every reference control must be implemented.

Evidence quality matters. A draft policy is not the same as evidence that a control is implemented, monitored, and reviewed. For certification-readiness purposes, distinguish documented policies and procedures from evidence that the ISMS is being implemented and evaluated, such as internal-audit and management-review activity (UKAS).

How To Perform An ISO 27001 Gap Analysis

A practical workflow is:

  1. Confirm the ISMS scope and assessment objective
    Define what business units, systems, processes, locations, and third parties are included. Be clear on whether the review is for baseline planning, internal audit preparation, or certification readiness.

  2. Map applicable requirements and selected controls
    Use ISO/IEC 27001 clauses 4–10 as the management-system baseline. Then review the SoA and risk-treatment decisions to identify relevant Annex A and custom controls.

  3. Collect documentation and operating evidence
    Gather policies, procedures, risk records, SoA, control descriptions, review records, audit records, incidents, corrective actions, management-review outputs, and other evidence relevant to the scope.

  4. Interview process and control owners where needed
    Use interviews to understand how processes actually work, who owns them, and whether records are complete. Do not rely on interviews alone where operating evidence should exist.

  5. Compare current state with expected requirement or control intent
    Record whether the requirement is met, partially met, not met, or not evidenced. Keep implementation weakness separate from evidence weakness.

  6. Document each gap with evidence and impact
    A finding should explain what was reviewed, what was missing or weak, why it matters, and what decision or action is needed.

  7. Classify and prioritise gaps
    Use internal prioritisation criteria such as implementation status, evidence quality, risk impact, audit-readiness impact, dependencies, and remediation effort.

  8. Assign remediation owners and target dates
    Every material finding should have an accountable owner, action, expected output, and target date.

  9. Validate closure with evidence
    Do not close a gap just because an action was discussed or a document was drafted. Closure should be supported by agreed evidence, such as an approved document, completed review, updated risk record, or repeatable operating record.

The key is traceability: requirement or control → current state → evidence reviewed → gap → owner → remediation → closure evidence.

ISO 27001 Gap Analysis Template: Fields To Capture

Use the following structure as an internal working template. It is not an official ISO template, but it gives the analysis enough detail to support remediation and readiness tracking.

FieldWhat to captureWhy it matters
ISO 27001 clause or Annex A/control areaClause, requirement area, or selected control referenceCreates traceability to the assessment baseline
Requirement or control objectivePlain-language summary of what is expectedHelps non-specialist owners understand the issue
Current stateWhat currently exists or happensSeparates actual practice from intended practice
Evidence reviewedDocuments, records, screenshots, logs, tickets, interviews, or samplesShows what the finding is based on
Evidence qualityAbsent, weak, partial, current and repeatableDistinguishes missing evidence from weak implementation
Gap descriptionWhat is missing, incomplete, inconsistent, or not evidencedStates the finding clearly
Risk or business impactWhy the gap matters to the ISMS, risk treatment, audit readiness, or operationsSupports prioritisation
Priority or severityInternal rating such as high, medium, lowHelps sequence remediation
Remediation actionSpecific action needed to address the gapTurns the finding into work
OwnerNamed role or accountable personPrevents orphaned findings
Target dateAgreed date or milestoneSupports tracking
StatusOpen, in progress, awaiting evidence, closedShows current progress
Closure evidenceEvidence required before the gap is treated as resolved internallyPrevents premature closure

The most common failure is leaving the “evidence reviewed” and “closure evidence” fields vague. “Policy exists” may not be enough if the issue is whether the process operates consistently.

How To Score And Prioritise ISO 27001 Gaps

Scoring is an internal prioritisation tool. It is not a certification result and should not be presented as an auditor-approved rating.

A simple approach is to classify each gap across four dimensions:

DimensionLow concernMedium concernHigh concern
Implementation statusImplemented and evidencedPartially implemented or inconsistentNot implemented, undocumented, or owner unknown
Evidence qualityCurrent, repeatable evidence existsSome evidence exists but is incomplete or outdatedNo reliable evidence available
ISMS impactLimited local improvementAffects a process, record, or control areaAffects core ISMS operation, risk treatment, SoA, governance, or audit preparation
Remediation dependencyCan be fixed independentlyRequires coordination across teamsBlocks or delays several other remediation actions

Use the rating to decide sequence, not to create false precision. A gap with weak evidence for a core ISMS process may deserve higher priority than a larger-looking documentation issue with limited operational impact.

A practical priority rule is:

  • High priority: gaps that affect core ISMS processes, risk assessment or treatment, SoA accuracy, governance, internal audit preparation, or evidence needed to show controls are operating.
  • Medium priority: gaps that show partial implementation, inconsistent records, unclear ownership, or outdated documentation.
  • Low priority: improvements, formatting issues, minor documentation refinements, or evidence improvements that do not materially affect readiness or risk decisions.

When in doubt, prioritise gaps that are evidence-critical, dependency-heavy, or likely to prevent a clear assessment, a clear assessment of whether the ISMS is working.

Example: From Gap Finding To Remediation Action

The example below shows how one finding can be recorded as executable remediation work. It avoids a specific control number because control applicability should be confirmed against the organisation’s SoA and risk-treatment decisions.

FieldExample entry
ISO 27001 clause or Annex A/control areaAnnex A access control area selected in the SoA
Requirement or control objectiveUser access rights should be reviewed in line with the organisation’s access-control process
Current stateAccess reviews are described in the access-control procedure, but the last completed review record only covers one business application
Evidence reviewedAccess-control procedure, SoA entry, sample access-review spreadsheet, interview with IT operations owner
Evidence qualityPartial
Gap descriptionThe organisation cannot currently evidence that access reviews are performed consistently across in-scope systems
Risk or business impactExcess or inappropriate access may remain unidentified; certification-readiness evidence is incomplete for a selected control area
Priority or severityHigh
Remediation actionDefine the in-scope system list for access reviews, assign review owners, complete access reviews for each in-scope system, record exceptions and approvals, and update the procedure if responsibilities differ from current practice
OwnerIT operations lead, with system owners accountable for review completion
Target dateBefore the planned internal audit readiness review
StatusOpen
Closure evidenceCompleted access-review records for all in-scope systems, documented exceptions, owner approvals, and updated procedure if required

The point is not the specific access-control example. The point is the structure: the finding explains the evidence reviewed, the weakness, the impact, the owner, the action, and the evidence needed for internal closure.

What Should The Final Gap Analysis Report Include?

The final report should be concise enough for decision-makers to use, but detailed enough for owners to act on. Include:

  • Scope and assumptions: ISMS boundaries, systems, processes, locations, and exclusions considered during the review.
  • Assessment method: documents reviewed, interviews performed, sampling approach, and any limitations.
  • Requirements and control areas reviewed: ISO 27001 clause areas, SoA coverage, selected Annex A or custom controls.
  • Readiness themes: recurring weaknesses, such as poor evidence retention, unclear ownership, outdated risk records, or incomplete management review inputs.
  • Detailed findings: each gap with requirement/control area, current state, evidence reviewed, impact, and priority.
  • Remediation plan: action, owner, target date, dependency, and expected closure evidence.
  • Open questions: issues requiring clarification by internal leadership, control owners, legal, security, or an external adviser.
  • Closure validation approach: how the organisation will confirm that actions are complete before internal audit or certification preparation continues.

Frame the report as an internal readiness and remediation artefact. Its value is not the number of findings; it is whether the findings become owned work and whether closure is evidenced.

ISO 27001 Gap Analysis Vs Risk Assessment Vs Maturity Assessment

These activities are related, but they answer different questions.

ActivityMain questionTypical outputHow it relates
Gap analysisHow does our current ISMS compare with applicable ISO 27001 requirements, selected controls, and evidence expectations?Findings, priorities, remediation actions, closure evidenceCan reveal missing processes, weak evidence, or incomplete control implementation
Risk assessmentWhat information-security risks affect the organisation, and how should they be evaluated?Risk register, risk evaluation, risk-treatment inputsInforms control decisions and treatment priorities
Maturity assessmentHow developed, repeatable, or optimised are our practices?Maturity ratings, improvement themesCan support improvement planning but is not the same as compliance status

Risk assessment and treatment are part of the ISO/IEC 27001 ISMS. The gap analysis may identify weaknesses in those processes, but it should not replace them. Likewise, a mature process may still have a compliance or evidence gap, and a compliant process may not be highly mature.

What To Do After The Gap Analysis

After the review, convert the findings into controlled remediation work:

  • confirm priorities with ISMS leadership and relevant control owners
  • assign owners and due dates
  • update policies, processes, SoA entries, or risk-treatment records where findings show they are incomplete or inaccurate
  • collect missing operating evidence
  • validate closure before relying on the result for internal audit or certification preparation
  • keep evidence current rather than rebuilding it for each review

A gap analysis is only useful if it moves beyond static tracking. If your team uses an operational compliance system such as Ciphrix, this is the point to move findings into owned remediation, evidence collection, and recurring control-management workflows instead of relying only on spreadsheets.

Basically, the practical outcome should be clear: each material gap has evidence, impact, priority, ownership, and a defined path to closure.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents