Free ISO 27001 gap analysis
Thirty questions across clauses 4-10 and the four Annex A themes. You get an instant readiness score, your gaps written in plain English, and a PDF action plan you can hand to your team. No account needed to see the result.
How it works
- 1. Answer
Yes, partly or no for each requirement. Skip anything that doesn't apply.
- 2. Score
See your readiness percentage overall and for each theme, instantly on this page.
- 3. Plan
Download a prioritised action plan as a PDF, or start the workspace and track it.
Context, scope and leadership
Clauses 4 and 5 — what the ISMS covers and who owns it.
Have you written down what your ISMS covers — sites, services, systems and people?
Clause 4.3Auditor expects: A documented scope statement, with exclusions and their justification.
Have you listed the parties whose requirements matter — customers, regulators, insurers, investors?
Clause 4.2Auditor expects: An interested-parties register mapping each party to its security requirements.
Is there an information security policy approved by top management within the last 12 months?
Clause 5.2 / A.5.1Auditor expects: A signed, dated policy with a review date and evidence of approval.
Are security roles and responsibilities documented and assigned to named people?
Clause 5.3 / A.5.2Auditor expects: A roles matrix naming individuals, not job titles alone.
Does leadership review security performance at a set interval with recorded decisions?
Clause 5.1 / 9.3Auditor expects: Management review minutes covering the mandated agenda items.
Risk, objectives and planning
Clause 6 — the engine of the whole standard.
Do you have a written risk assessment method with defined likelihood and impact scales?
Clause 6.1.2Auditor expects: A methodology document showing scales, risk acceptance criteria and how risks are compared.
Is there a current risk register with named owners and target dates?
Clause 6.1.2 / 8.2Auditor expects: A register showing inherent score, treatment, owner, residual score and review date.
Does each unacceptable risk have a treatment plan you are actually working through?
Clause 6.1.3Auditor expects: A risk treatment plan linking risks to Annex A controls and to open actions.
Do you have a Statement of Applicability covering all 93 Annex A controls with justifications?
Clause 6.1.3 d)Auditor expects: An SoA listing each control, applicability, justification and implementation status.
Have you set measurable security objectives with owners and a review point?
Clause 6.2Auditor expects: Objectives with a target, a measure, an owner and a date.
People, awareness and suppliers
Clause 7 plus Annex A people and supplier controls.
Are background checks and confidentiality terms in place before people start?
A.6.1 / A.6.6Auditor expects: Screening records and signed confidentiality agreements on file.
Does everyone receive security awareness training, with completion recorded?
Clause 7.3 / A.6.3Auditor expects: Training records showing who completed what and when.
Is there a leaver process that removes access and recovers assets within a set time?
A.5.11 / A.6.5Auditor expects: Leaver checklists with dated access-removal evidence.
Do you assess suppliers for security before onboarding them?
A.5.19 / A.5.21Auditor expects: Completed supplier assessments and a supplier register with risk ratings.
Do supplier contracts include security, breach-notification and data-handling terms?
A.5.20Auditor expects: Contracts or DPAs containing the agreed security clauses.
Technical controls
Annex A.8 — access, configuration, monitoring and development.
Is multi-factor authentication enforced for all users on email, identity and admin systems?
A.5.17 / A.8.5Auditor expects: A tenant screenshot or policy export showing enforcement and exceptions.
Are user access rights reviewed on a schedule, with the review recorded?
A.5.18Auditor expects: Dated access review records showing who reviewed what and the changes made.
Do you hold an inventory of information assets, systems and endpoints with owners?
A.5.9Auditor expects: An asset register kept current, ideally fed from your device and identity tooling.
Are secure configuration baselines defined and checked for drift?
A.8.9Auditor expects: Baseline documents plus compliance reports from Intune, MDM or a posture tool.
Are backups running, protected from tampering, and tested by restore at least annually?
A.8.13Auditor expects: Backup job reports and a dated restore test record.
Are security logs collected, retained and actually reviewed or alerted on?
A.8.15 / A.8.16Auditor expects: Retention settings plus evidence of alerts triaged.
Do you scan for technical vulnerabilities and patch to defined timescales?
A.8.8Auditor expects: Scan reports and patch compliance figures against your SLA.
If you build software, are secure coding rules, code review and testing documented?
A.8.25 / A.8.28Auditor expects: A secure development standard plus pull-request and testing evidence.
Operating, checking and improving
Clauses 8, 9 and 10 — proving the system runs.
Is there an incident response plan with roles, severity levels and reporting timelines?
A.5.24 / A.5.26Auditor expects: A tested plan plus an incident log, even if it records low-severity events.
Have you documented and exercised business continuity for your critical services?
A.5.29 / A.5.30Auditor expects: Continuity plans with RTO/RPO and a dated exercise report.
Do you measure whether controls are actually working, not just that they exist?
Clause 9.1Auditor expects: A monitoring and measurement plan with results over time.
Is there an internal audit programme covering the whole ISMS over a defined cycle?
Clause 9.2Auditor expects: An audit programme, audit reports and independence of the auditor.
Are nonconformities logged with root cause, corrective action and verified closure?
Clause 10.2Auditor expects: A corrective action log showing cause analysis and effectiveness checks.
Are documents version-controlled, approved and reviewed on a schedule?
Clause 7.5Auditor expects: Version history, approver, and review dates on every controlled document.
Free, instant and on this page. Nothing is sent anywhere until you ask for the PDF.
What a gap analysis actually is
An ISO 27001 gap analysis compares how your organisation works today against the requirements of the standard: the management-system clauses 4 to 10, and the 93 Annex A controls introduced in the 2022 revision. Every difference becomes a piece of work with an owner and a date. Done early it saves money, because you find the missing internal audit or Statement of Applicability months before a certification body does — not during Stage 1.
The questions above follow the order an auditor works in: scope and leadership first, then risk, then people and suppliers, then the technical controls, and finally the evidence that the system is being run and improved. Most UK SMEs score well on technical controls and poorly on documented evidence — which is why the score is broken down by theme rather than shown as one number.
Keep going
Turn the gaps into a working management system
The gaps above are the work. ISO-STANDARD.app holds the risk register, controls, owners, evidence and audit trail in one place, with AI help to draft policies and fix failing controls.