English (UK) hello@isochecklist.com
Cart (0)
HomeISO 27001Gap Analysis

ISO 27001 Gap Analysis

Assess your current information security management system against every ISO 27001 requirement and Annex A control to identify gaps before your certification audit.

What Is a Gap Analysis?

A gap analysis compares your organisation's current practices against the requirements of ISO 27001. It highlights where you already conform, where partial implementation exists, and where significant gaps need to be addressed before you can achieve certification.

Running a gap analysis early in your implementation project helps you prioritise effort, allocate resources effectively, and set a realistic timeline for certification readiness.

What's Included

  • Clause-by-clause gap analysis covering Clauses 4 through 10 with maturity ratings
  • Annex A controls assessment across all 93 controls with implementation status tracking
  • Traffic-light scoring system to visualise conformity, partial conformity, and non-conformity
  • Priority action plan template for addressing identified gaps
  • Summary dashboard showing overall readiness percentage by clause and control theme
  • Space for evidence notes and responsible person assignment

How to Conduct the Gap Analysis

  1. Gather existing documentation — collect current policies, procedures, risk registers, and audit reports
  2. Assess each clause — rate your conformity level for every requirement in Clauses 4 to 10
  3. Evaluate Annex A controls — determine the implementation status of each applicable control
  4. Identify priority gaps — focus on high-risk areas and requirements that need the most work
  5. Create an action plan — assign owners, set deadlines, and track progress towards closing each gap