What is an ISO 27001 gap analysis?

An ISO 27001 gap analysis is a structured assessment that compares your organisation's current information security controls, policies and practices against the requirements of the ISO 27001 standard. The output is a clear picture of what is already in place, what is partially in place and what is missing or needs significant development before certification is realistic.

It is not a pass/fail test. It is a diagnostic — designed to give leadership a credible starting position rather than discovering problems during the formal certification audit.

The practical value of doing this well: organisations that conduct a thorough gap analysis before starting implementation are far less likely to hit expensive surprises during the Stage 1 or Stage 2 audit. The gaps that surface late are almost always the ones nobody checked early.

The six areas a gap analysis typically covers.

ISO 27001 is built around a management system model with a set of supporting technical and organisational controls (Annex A). A thorough gap analysis looks at both layers — the management system requirements and the control set.

Area What is assessed Common finding
Scope and context What the ISMS covers, key interested parties, legal obligations Scope is undefined or too broad
Risk management Risk methodology, risk register, treatment decisions No live risk register or informal ad-hoc process only
Policies and documentation Core ISMS policies, procedures, their relevance and usage Policies exist but are outdated or unused
Governance and ownership Named responsibilities, leadership involvement, review cadence No named owner or security treated as IT-only
Technical and operational controls Annex A controls — access management, asset control, incident response, business continuity, supplier oversight Controls operating informally with no documented evidence
Evidence and continual improvement Records of reviews, incidents, training, audits, corrective actions Little or no evidence trail exists

What a gap analysis output looks like in practice.

A well-structured gap analysis produces more than a list of deficiencies. The most useful outputs include a prioritised view of gaps by severity and effort, a rough estimate of implementation work required per area, and a clear recommendation on whether the organisation should proceed directly to implementation or spend time on foundational work first.

The output should be honest about the starting position. Organisations that receive an overly optimistic gap analysis spend more time fixing surprises during implementation than those who got an accurate picture early.

How long does an ISO 27001 gap analysis take?

For a small to medium-sized organisation, a structured gap analysis typically takes two to four weeks from kickoff to final output. Larger or more complex organisations with multiple sites, regulated environments or extensive supplier networks may take longer. The variables that affect timeline most are access to the right people, availability of existing documentation and the breadth of scope being assessed.

A gap analysis should not be rushed. The value lies in the accuracy of the findings, not in completing it quickly. An assessment that misses a significant control gap costs far more to fix after the work begins than it would have if identified at the start.

The most common gaps found in practice.

Across ISO 27001 engagements, certain gaps appear with enough regularity that they are worth understanding before starting any assessment. These are not edge cases — they represent the typical distance between how organisations operate day-to-day and what a management system standard requires.

Gap analysis versus readiness assessment — is there a difference?

The terms are often used interchangeably, but there is a useful distinction. A gap analysis focuses on identifying what is absent or deficient relative to the standard. A readiness assessment goes a step further — it evaluates not just whether controls exist but whether the organisation is ready to demonstrate them under audit conditions. In practice, a thorough gap analysis should incorporate readiness thinking: identifying controls that exist on paper but could not be evidenced in an audit is as important as finding controls that are entirely absent.

How to use gap analysis results to plan implementation.

A gap analysis result is only useful if it drives a realistic, sequenced implementation plan. The most effective approach is to use the findings to identify three categories of work: quick wins that can be completed in the first few weeks with minimal effort, foundational work that must be in place before other controls can be built on top of it, and longer-term improvements that are important but can be scheduled into the middle phase of implementation.

The sequence matters as much as the content. Organisations that try to address all gaps simultaneously usually make slower progress than those that work through a structured order — particularly around risk management, which underpins most of the other control requirements.

One practical consideration at this stage is where the gap analysis output lives after the engagement ends. A list of findings in a document quickly becomes stale if ownership is not assigned and progress is not tracked. Protects is the platform YDC uses to keep actions, ownership and evidence live — so the gap analysis output becomes a working programme rather than a report that sits in a folder.

Questions to ask when choosing how to conduct a gap analysis.

What does a gap analysis typically cost?

A standalone gap analysis for a focused SME scope is typically a defined, proportionate piece of work rather than an open-ended engagement. As a reference point, a full done-for-you ISO 27001 implementation — starting from gap analysis through to Stage 1 audit — has been delivered for around £20,000 for recent SME and fintech clients. The gap analysis element alone is a fraction of that. The right starting point is a scoping call to understand the current position and what a realistic assessment involves before any cost is agreed.

Can we do the gap analysis internally?

Yes, if someone internal has sufficient ISO 27001 knowledge. The risk with internal-only assessments is objectivity — it is difficult to identify gaps in processes you are responsible for. An external view adds challenge and is more likely to surface the gaps that matter, particularly the ones that would surface during a certification audit.

What should we do with the gap analysis output?

Use it to build a sequenced implementation plan with realistic timelines, named ownership and a clear view of resource requirement. A gap analysis that produces a list of findings without driving action is a wasted exercise. The output should be a working document, not a report that sits in a folder.

How does a gap analysis relate to the Stage 1 audit?

The Stage 1 audit conducted by the certification body is essentially a formal version of part of the gap analysis — it reviews the ISMS documentation and design against the standard. A thorough internal gap analysis done before starting implementation should mean the Stage 1 audit produces few surprises. If significant gaps surface at Stage 1, it usually means the pre-implementation assessment was not thorough enough.