Free ISO 27001 gap analysis

Thirty questions across clauses 4-10 and the four Annex A themes. You get an instant readiness score, your gaps written in plain English, and a PDF action plan you can hand to your team. No account needed to see the result.

How it works

  1. 1. Answer

    Yes, partly or no for each requirement. Skip anything that doesn't apply.

  2. 2. Score

    See your readiness percentage overall and for each theme, instantly on this page.

  3. 3. Plan

    Download a prioritised action plan as a PDF, or start the workspace and track it.

0 of 29 answered

Context, scope and leadership

Clauses 4 and 5 — what the ISMS covers and who owns it.

Have you written down what your ISMS covers — sites, services, systems and people?

Clause 4.3

Auditor expects: A documented scope statement, with exclusions and their justification.

Have you listed the parties whose requirements matter — customers, regulators, insurers, investors?

Clause 4.2

Auditor expects: An interested-parties register mapping each party to its security requirements.

Is there an information security policy approved by top management within the last 12 months?

Clause 5.2 / A.5.1

Auditor expects: A signed, dated policy with a review date and evidence of approval.

Are security roles and responsibilities documented and assigned to named people?

Clause 5.3 / A.5.2

Auditor expects: A roles matrix naming individuals, not job titles alone.

Does leadership review security performance at a set interval with recorded decisions?

Clause 5.1 / 9.3

Auditor expects: Management review minutes covering the mandated agenda items.

Risk, objectives and planning

Clause 6 — the engine of the whole standard.

Do you have a written risk assessment method with defined likelihood and impact scales?

Clause 6.1.2

Auditor expects: A methodology document showing scales, risk acceptance criteria and how risks are compared.

Is there a current risk register with named owners and target dates?

Clause 6.1.2 / 8.2

Auditor expects: A register showing inherent score, treatment, owner, residual score and review date.

Does each unacceptable risk have a treatment plan you are actually working through?

Clause 6.1.3

Auditor expects: A risk treatment plan linking risks to Annex A controls and to open actions.

Do you have a Statement of Applicability covering all 93 Annex A controls with justifications?

Clause 6.1.3 d)

Auditor expects: An SoA listing each control, applicability, justification and implementation status.

Have you set measurable security objectives with owners and a review point?

Clause 6.2

Auditor expects: Objectives with a target, a measure, an owner and a date.

People, awareness and suppliers

Clause 7 plus Annex A people and supplier controls.

Are background checks and confidentiality terms in place before people start?

A.6.1 / A.6.6

Auditor expects: Screening records and signed confidentiality agreements on file.

Does everyone receive security awareness training, with completion recorded?

Clause 7.3 / A.6.3

Auditor expects: Training records showing who completed what and when.

Is there a leaver process that removes access and recovers assets within a set time?

A.5.11 / A.6.5

Auditor expects: Leaver checklists with dated access-removal evidence.

Do you assess suppliers for security before onboarding them?

A.5.19 / A.5.21

Auditor expects: Completed supplier assessments and a supplier register with risk ratings.

Do supplier contracts include security, breach-notification and data-handling terms?

A.5.20

Auditor expects: Contracts or DPAs containing the agreed security clauses.

Technical controls

Annex A.8 — access, configuration, monitoring and development.

Is multi-factor authentication enforced for all users on email, identity and admin systems?

A.5.17 / A.8.5

Auditor expects: A tenant screenshot or policy export showing enforcement and exceptions.

Are user access rights reviewed on a schedule, with the review recorded?

A.5.18

Auditor expects: Dated access review records showing who reviewed what and the changes made.

Do you hold an inventory of information assets, systems and endpoints with owners?

A.5.9

Auditor expects: An asset register kept current, ideally fed from your device and identity tooling.

Are secure configuration baselines defined and checked for drift?

A.8.9

Auditor expects: Baseline documents plus compliance reports from Intune, MDM or a posture tool.

Are backups running, protected from tampering, and tested by restore at least annually?

A.8.13

Auditor expects: Backup job reports and a dated restore test record.

Are security logs collected, retained and actually reviewed or alerted on?

A.8.15 / A.8.16

Auditor expects: Retention settings plus evidence of alerts triaged.

Do you scan for technical vulnerabilities and patch to defined timescales?

A.8.8

Auditor expects: Scan reports and patch compliance figures against your SLA.

If you build software, are secure coding rules, code review and testing documented?

A.8.25 / A.8.28

Auditor expects: A secure development standard plus pull-request and testing evidence.

Operating, checking and improving

Clauses 8, 9 and 10 — proving the system runs.

Is there an incident response plan with roles, severity levels and reporting timelines?

A.5.24 / A.5.26

Auditor expects: A tested plan plus an incident log, even if it records low-severity events.

Have you documented and exercised business continuity for your critical services?

A.5.29 / A.5.30

Auditor expects: Continuity plans with RTO/RPO and a dated exercise report.

Do you measure whether controls are actually working, not just that they exist?

Clause 9.1

Auditor expects: A monitoring and measurement plan with results over time.

Is there an internal audit programme covering the whole ISMS over a defined cycle?

Clause 9.2

Auditor expects: An audit programme, audit reports and independence of the auditor.

Are nonconformities logged with root cause, corrective action and verified closure?

Clause 10.2

Auditor expects: A corrective action log showing cause analysis and effectiveness checks.

Are documents version-controlled, approved and reviewed on a schedule?

Clause 7.5

Auditor expects: Version history, approver, and review dates on every controlled document.

Free, instant and on this page. Nothing is sent anywhere until you ask for the PDF.

What a gap analysis actually is

An ISO 27001 gap analysis compares how your organisation works today against the requirements of the standard: the management-system clauses 4 to 10, and the 93 Annex A controls introduced in the 2022 revision. Every difference becomes a piece of work with an owner and a date. Done early it saves money, because you find the missing internal audit or Statement of Applicability months before a certification body does — not during Stage 1.

The questions above follow the order an auditor works in: scope and leadership first, then risk, then people and suppliers, then the technical controls, and finally the evidence that the system is being run and improved. Most UK SMEs score well on technical controls and poorly on documented evidence — which is why the score is broken down by theme rather than shown as one number.

Keep going

Turn the gaps into a working management system

The gaps above are the work. ISO-STANDARD.app holds the risk register, controls, owners, evidence and audit trail in one place, with AI help to draft policies and fix failing controls.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.