Most ISO 27001 gap analyses are bought for the wrong reason and produce the wrong output. Organisations want to know how far they are from certification. They receive a spreadsheet of red, amber and green. Six months later they discover the spreadsheet described their documents, not their security.

This is how to run one that leads somewhere.

What it is, and what it is not

A gap analysis measures the distance between where you are and what ISO 27001 requires. It is a diagnostic, not a judgement. It does not certify anything and it is not an audit.

The confusion matters. An audit checks conformity and produces findings. A gap analysis asks a bigger question: what would it take, in what order, to run a management system that passes audit and actually protects the business?

If the report you receive reads like an audit report, you have been given the wrong product.

When to run one

Three moments earn the cost: before a first certification, when you need a real plan and a real budget; before recertification or a transition, when a system that passed three years ago may have drifted; and after a big change, an acquisition, a new platform, a move to a managed service provider.

The wrong moment is the week before Stage 1. By then it can only tell you what you already suspect.

The five steps

The five steps of a proper ISO 27001 gap analysis: fix the scope, assess both halves, evidence not assertions, score honestly, report a plan.

1. Fix the scope before you assess anything

Every certificate has a boundary. Which entities, sites, services, systems and suppliers sit inside it is a choice, and the gap analysis has to start there, because the certificate attaches to the management system, not to a product: the boundary you draw now is the boundary on the certificate later.

The test: list the information that would cause real harm if its confidentiality, integrity or availability failed, then check the scope covers the systems and people that handle it. The commercial platform bolted on three years ago and the marketing database run by an agency are exactly where incidents happen, and a certificate that excludes them says nothing about them.

Write the scope down before the first interview. It will change. The changes are findings.

2. Assess both halves of the standard

ISO 27001 has two halves, and too many gap analyses only look at one.

The two halves of ISO 27001: clauses 4 to 10, the management system, assessed first; and Annex A, 93 reference controls, assessed second against the risk picture.

Clauses 4 to 10 are the engine: context, leadership, risk assessment and treatment, competence, operations, performance evaluation, internal audit, management review, improvement. This is where first-time organisations are weakest, because it needs decisions and routines, not technology.

Annex A is the reference set of 93 controls. They get most of the attention because they are tangible, but their weight depends on the risk assessment. At a first-time build there usually is no risk assessment yet, so the honest position is to assess all 93 as applicable and say so; the Statement of Applicability decides later which ones are not.

A gap analysis that assesses Annex A but never reaches clauses 4 to 10 has measured the controls and missed the system.

3. Evidence, not assertions

The biggest weakness in most gap analyses is that they are conducted by interview. Someone asks whether access is reviewed quarterly, someone says yes, and the cell turns green.

Ask for the evidence instead. Show me the last access review. Show me the incident log. Show me the supplier assessment for the provider that hosts your core platform. Evidence exists: met. Evidence missing: not met. Evidence stale or contradicted by what people actually do: partially met, and usually the most important finding of all.

It takes longer. It is also the only version that predicts what an auditor will find, because auditors work the same way. There is one difference in your favour: an auditor samples, while a gap analysis is the one time every requirement gets looked at. Use it.

4. Score honestly

Red, amber and green has a place: as bands for reporting progress to a board, it works. As the score for each requirement, it is a comfort blanket, not a measurement. Three colours cannot separate a control that is missing, one that is documented but not operating, one operating but not evidenced, and one working well with a gap an auditor would notice. Four situations, four different responses, so the scale underneath the bands has to carry four states. Two organisations with very different levels of control can hold the same certificate; the score is what tells you which one you are.

We score each requirement on how effectively it is working, and the scores roll up into one figure for the system. Across more than 1,400 requirements and controls assessed this way at internal audit, the organisations we support average 92, and none has received a major nonconformity at external audit. The scoring is not the reason for that record; it is what makes the honest conversation happen before the auditor forces it.

Measure effectiveness, not existence. A policy nobody follows scores as if it did not exist.

5. Report a plan, not a scorecard

The output is not the spreadsheet. It is the decision leadership can make after reading it.

That needs three things, across the report and the plan that follows it: the current state in plain language, including any scope decisions still open; actions sequenced by dependency and risk, not by clause number, with effort and ownership; and an honest distance to certification, in time, internal effort and external support. If a finance director cannot understand what is being asked and why, the exercise has failed.

Experience shows in the sequencing. Fixing the risk assessment method unlocks a dozen requirements. Supplier assurance is often the biggest single job in a managed-services environment. Documentation, which everyone assumes is the bulk of the work, is rarely the hard part once the decisions behind it are made.

Five mistakes that make a gap analysis worthless

  1. Assessing documents instead of practice.
  2. Skipping clauses 4 to 10 and going straight to Annex A.
  3. Treating it as an audit: findings without a plan.
  4. Scoring each requirement in three colours.
  5. Letting the firm that wants the implementation understate the gap. Ask for the evidence behind every score.

How long, and a note on tools

For a mid-sized organisation with a managed IT environment, a properly evidenced gap analysis is days, not weeks. Larger or multi-entity scopes take longer, and the scope work alone can be substantial. What should never take long is the report; one delivered a month after the last interview describes an organisation that has already moved on.

Platforms can structure the exercise and store the evidence, and some do it well. They cannot decide whether evidence is good enough, whether the scope is right, or which of forty gaps to close first. Those judgements are the whole value. A percentage complete that no practitioner has examined is a number, not an assessment.

Frequently asked questions

How much does an ISO 27001 gap analysis cost?

Days of senior practitioner time for a mid-sized organisation. Very cheap offers are usually interview-only and measure what people say, not what the evidence shows.

Can we do our own?

Yes, as a first step; people assess their own controls generously. A self-assessed readiness check tells you where to look; a practitioner-rated one tells you what is there.

Is it the same as a Stage 1 audit?

No. Stage 1 is the certification body confirming readiness for Stage 2, with formal findings. Run the gap analysis first; treat Stage 1 as confirmation.

Do we need one if we are already certified?

Before recertification or a transition, yes. Systems drift, and the gap analysis tells you how far before the auditor does.

How does it differ from an internal audit?

Internal audit is required by the standard and checks conformity of an operating system. A gap analysis measures distance from a target and produces a roadmap. Certified organisations need both.

Want a practitioner-rated view rather than a self-assessment?

The Management System Health Check scores how well your system is actually working, requirement by requirement. Read about the Health Check, or start with the free Readiness Check.