An ISO 27001 gap analysis compares an organization’s current information security management system against what the standard requires and identifies exactly where it falls short, before a certification auditor does. It is the diagnostic step that converts a vague sense of unreadiness into a specific, prioritized list of what to build, and its output is effectively the roadmap to certification. This guide explains the assessment method, the deliverables it produces, the logic that drives its cost, and how its findings become the plan that carries an organization to a certificate.
The reason to run the analysis before committing to a certification timeline is that it changes the plan cheaply while there is still room to change it. Discovering during a certification audit that the management system is incomplete is expensive and delays the certificate, whereas discovering it during a gap analysis is simply the first, expected step of a well-run project. The analysis turns certification from an uncertain event into a managed sequence, which is its entire value.
What an ISO 27001 Gap Analysis Is
The analysis is a structured comparison of an organization’s current state against the two parts of the standard: the management system clauses, numbered 4 through 10, and the Annex A controls. It examines what the organization already does, determines where that meets the requirements and where it does not, and produces a documented set of gaps with a plan to close them. It is a readiness exercise performed to prepare the organization, distinct from the certification audit itself, which an accredited certification body conducts to issue the certificate.
It helps to place the analysis in the sequence it belongs to. It is more diagnostic and structured than a broad first look, such as the one described in the guide to getting started with an ISO 27001 readiness assessment, and it comes before the remediation work of closing the gaps it finds. The analysis is the step that tells an organization, clause by clause and control by control, precisely what stands between it and a certificate.
It is also worth distinguishing a gap analysis from a risk assessment, since the two are often confused. A risk assessment is one of the things ISO 27001 requires an organization to have and to run, whereas a gap analysis checks whether the organization has a compliant risk assessment process along with everything else the standard demands. In other words, the risk assessment is part of what the gap analysis evaluates, not a substitute for it, and an organization needs both.
The Assessment Method
The gap analysis follows a defined method rather than a loose review, working through both parts of the standard in turn. The table sets out the core steps and what each produces.
| Step | What it involves | Output |
|---|---|---|
| Scope the ISMS | Define the boundaries of the information security management system | A defined scope |
| Assess the management clauses | Compare clauses 4 through 10 against current practice | Clause gap findings |
| Assess the Annex A controls | Evaluate which controls apply and their current status | Control gap findings and a draft Statement of Applicability |
| Rate and prioritize gaps | Judge each gap’s severity and the effort to close it | A prioritized gap register |
| Document and plan | Record the findings and build the remediation plan | A gap analysis report and roadmap |
The method matters because ISO 27001 certification examines both a working management system and the controls that system selects and applies, so a gap analysis that looked only at the Annex A controls and ignored the clauses, or vice versa, would miss half of what an auditor checks. Assessing both, and producing a draft Statement of Applicability along the way, means the analysis maps to exactly what the certification audit will assess. That alignment is what makes the findings trustworthy as a plan.
The Deliverables
The deliverables of the analysis are what turn the assessment into something an organization can act on. At minimum, the analysis should produce a gap analysis report that documents the methodology and the state of the management system, a gap register that lists each gap against the relevant clause or control with its severity and priority, and a remediation roadmap that sequences the work to close the gaps. A draft Statement of Applicability, recording which Annex A controls apply and why, is a common and valuable additional output, because it becomes a working document the organization carries forward.
The register and roadmap are the deliverables that matter most, because they convert findings into a plan with an order and an owner. An analysis that lists gaps without prioritizing them or sequencing their remediation leaves the organization knowing it has work to do but not where to start, which is a far less useful result. Specifying these deliverables before the analysis begins ensures it produces a plan rather than just a diagnosis.
What Drives the Cost
The cost of the analysis follows its scope and the organization’s starting position rather than a fixed rate. The main drivers are the size and complexity of the ISMS scope, the maturity of the organization’s existing security program, since a more mature starting point means fewer gaps to assess and document, and whether the work is done internally or with an advisor. Because these variables differ widely, a scoped estimate is more reliable than any single published figure for the analysis itself.
Where published figures are useful is in understanding the larger certification budget the gap analysis feeds into, and Elevate’s ISO 27001 certification cost guide sets out those numbers. The gap analysis is a small fraction of that total, and its return is disproportionate, because it prevents the far larger cost of a stalled or failed certification. Framing the cost of the analysis against the cost of an audit that surfaces gaps too late is what shows why it is worth doing first.
How Findings Become Your Certification Roadmap
The defining feature of the analysis is that its output is not just a report but a roadmap, and understanding how the two connect is what makes the analysis worth commissioning. The prioritized gap register orders the work by severity and effort, the remediation roadmap sequences that work into a plan, and the draft Statement of Applicability gives the organization a head start on a document it will need anyway. Together these mean that on the day the analysis is delivered, the organization does not just know its gaps; it knows the order in which to close them and roughly how long that will take.
That roadmap then runs through remediation, an internal audit, and a management review before the certification audit, each of which the standard expects to have happened. The work of closing the gaps is covered in the guide to ISO 27001 gap remediation, which is the critical path from the analysis to compliance. The gap analysis is valuable precisely because it makes that path visible and ordered from the start, which is why Elevate’s ISO 27001 services begin with it.
Common Gaps an ISO 27001 Analysis Finds
The gaps an ISO 27001 analysis surfaces are consistent across organizations, and knowing them in advance helps a team anticipate the work. The most common on the management-clause side is an incomplete or informal risk assessment and risk treatment process, which sits at the heart of the standard; many organizations manage risk in practice but cannot show the documented, repeatable process the clauses require. Closely related is a Statement of Applicability that is missing, incomplete, or not justified, since the standard expects every applicable Annex A control to be accounted for with a reason for inclusion or exclusion.
On the controls side, the recurring findings are controls that operate informally but are not documented, evidenced, or applied consistently, from access management and change control to logging and supplier security. As with other standards, an unevidenced control is treated as one that does not operate, so the gap is often not the absence of security but the absence of proof. Policies that exist but do not match actual practice are another frequent finding, because the audit checks that documentation reflects reality.
The gaps that most often cause late surprises, though, are the ones tied to the management system running as a cycle: no completed internal audit, no management review, and no record of the system having operated over time. Because the standard requires these and they cannot be produced retroactively, an organization that leaves them until the end finds them blocking the certification audit. A gap analysis run early flags them while there is still time to perform them, which is a large part of why running it first is worth the effort.
When to Run an ISO 27001 Gap Analysis
The best time to run the analysis is at the start of a certification effort, before committing to an audit date, because that is when its findings can still shape the plan without cost. An organization pursuing its first certificate benefits most, since it has the least certainty about where it stands, but the analysis also serves organizations preparing for recertification after significant change, expanding the scope of an existing ISMS, or responding to a customer that has made ISO 27001 a condition of doing business.
The unifying principle is that the analysis is worth running whenever there is uncertainty about readiness and time to act on the answer. Running it too late, once a certification audit is scheduled and imminent, forfeits much of its value, because the gaps it finds can no longer be remediated calmly and may force the audit to be postponed. The same diagnostic logic applies across frameworks, which is why an organization pursuing more than one certification often runs parallel exercises such as a SOC 2 gap analysis alongside this one.
Conclusion
An ISO 27001 gap analysis is the diagnostic that compares an organization’s information security management system against the standard’s clauses and controls, finds where it falls short, and turns that into a prioritized roadmap to certification. Its method assesses both the management clauses and the Annex A controls, its deliverables are a report, a gap register, a remediation roadmap, and often a draft Statement of Applicability, and its cost is small relative to the certification effort it de-risks.
The value is in the roadmap: an ordered, owned plan that carries an organization through remediation, internal audit, and management review to the certification audit, rather than a surprise discovered during it. To start an ISO 27001 effort with a gap analysis that makes the path to certification clear, book a call with an Elevate advisor.
Key Takeaways
An ISO 27001 gap analysis compares your ISMS against the standard and produces a prioritized roadmap to certification.
- It assesses both parts of the standard: the analysis evaluates the management clauses 4 through 10 and the Annex A controls, because a certification audit examines both.
- The deliverables are a plan, not just a diagnosis: a gap register and remediation roadmap, often with a draft Statement of Applicability, turn findings into ordered, owned work.
- Cost follows scope and maturity: the analysis is a small fraction of the total certification budget, and its return comes from preventing a far more expensive stalled or failed audit.
- The output is a roadmap: the prioritized findings sequence the remediation, internal audit, and management review that precede the certification audit, making the path visible from the start.
- Timing is the point: run the analysis before committing to an audit date, because gaps found early can be remediated calmly, while gaps found late can force a postponement.
FAQs
Q1. What is an ISO 27001 gap analysis? An ISO 27001 gap analysis is a structured comparison of an organization’s current state against the requirements of the standard, covering both the management system clauses 4 through 10 and the Annex A controls. It examines what the organization already does, identifies where that meets the requirements and where it falls short, and produces a documented set of gaps with a plan to close them. It is a readiness exercise performed before certification to prepare the organization, distinct from the certification audit itself, which an accredited certification body conducts to issue the certificate.
Q2. What is the method for an ISO 27001 gap analysis? The method works through both parts of the standard. First, scope the information security management system to define its boundaries. Next, assess the management clauses 4 through 10 against current practice, and evaluate the Annex A controls to determine which apply and their status, producing a draft Statement of Applicability. Then rate and prioritize each gap by severity and the effort to close it, and finally document the findings and build a remediation roadmap. Assessing both the clauses and the controls matters, because a certification audit examines both.
Q3. What are the deliverables of an ISO 27001 gap analysis? A complete ISO 27001 gap analysis should produce a gap analysis report documenting the methodology and the state of the management system, a gap register listing each gap against the relevant clause or control with its severity and priority, and a remediation roadmap that sequences the work to close the gaps. A draft Statement of Applicability, recording which Annex A controls apply and why, is a common and valuable additional deliverable. The register and roadmap matter most, because they convert findings into an ordered plan with owners rather than just a list of problems.
Q4. How much does an ISO 27001 gap analysis cost? The cost follows scope and starting position rather than a fixed rate. The main drivers are the size and complexity of the ISMS scope, the maturity of the existing security program, since a more mature starting point means fewer gaps to assess, and whether the work is done internally or with an advisor. The analysis itself is a small fraction of the overall certification budget, and its return comes from preventing the far larger cost of a stalled or failed audit. Published figures are most useful for the larger certification budget the gap analysis feeds into.
Q5. When should you do an ISO 27001 gap analysis? The best time is at the start of a certification effort, before committing to an audit date, because that is when the findings can still shape the plan without cost. Organizations pursuing a first certificate benefit most, but the analysis also helps those preparing for recertification after significant change, expanding an existing ISMS scope, or responding to a customer requirement. Running it too late, once a certification audit is scheduled and imminent, forfeits much of its value, because the gaps it finds can no longer be remediated calmly and may force the audit to be postponed.