
Know exactly where you stand before you commit to an ISMS.
A gap analysis against ISO/IEC 27001:2022 gives you an honest, evidenced baseline — what's already in place, what's partial, and what doesn't exist yet — before you spend budget building a management system around assumptions.
Most organisations overestimate their readiness.
It's common for a security or IT lead to believe they're '80% of the way there' on ISO 27001, based on firewalls, backups and a staff handbook that mentions passwords. The standard asks for something different: a management system with defined scope, leadership commitment, risk assessment methodology, risk treatment decisions, and evidenced operation of controls over time.
Without an independent look at clause 4 through clause 10 alongside Annex A, that gap stays invisible until a certification body's Stage 1 auditor finds it — at which point it costs time, money and credibility with whoever asked for the certificate in the first place.
We see the same patterns repeatedly: a risk register that exists but hasn't been reviewed since it was created, a Statement of Applicability copied from a template with controls marked applicable that nobody can evidence, and technical controls that are genuinely strong but never written down anywhere an auditor could check.
Boards and procurement teams asking for ISO 27001 rarely care about the mechanics — they want assurance that information risk is managed properly. A gap analysis translates that commercial pressure into a concrete, sequenced list of work rather than a vague sense that 'we should probably do ISO 27001 at some point'.
The risk of skipping this step isn't just a failed audit. It's committing a project team to eighteen months of work against the wrong priorities, or discovering three months before a customer deadline that the scope was drawn incorrectly and half the estate sits outside it.
- No independent view of maturity against clause 4-10 requirements
- Statement of Applicability drafted without evidenced justification
- Risk assessment methodology missing or inconsistently applied
- Technical controls strong but undocumented and unevidenced
- Scope boundary unclear or drawn to suit convenience rather than reality
A structured, evidence-based review, not a checklist tick.
We assess your organisation against every clause from 4 (Context of the Organisation) through 10 (Improvement), and against all 93 Annex A controls across the organisational, people, physical and technological themes introduced in the 2022 revision.
The review combines document review, system walkthroughs and structured interviews with the people who actually operate controls day to day — not just the person who wrote the policy. We're interested in what happens in practice, because that's what an auditor will test.
Each area is rated against a simple maturity scale: not started, partial, or evidenced and operating. Where a control is marked partial or absent, we record what specifically is missing rather than a generic 'needs work' note that leaves you no better informed.
Findings are prioritised against effort and risk, so you're not left with ninety equally weighted action items. Some gaps are quick policy fixes; others need genuine technical or organisational change, and we're clear about which is which.
We present the findings in a working session with your team, walk through the reasoning behind each rating, and leave you with a report and roadmap you can act on immediately — whether that's in-house or with separate implementation support.
We don't have a stake in what you do next. There's no upsell built into the recommendations; if the honest answer is 'you're closer than you think', we say so.
- Full clause 4-10 and Annex A control assessment, mapped to the four 2022 control themes
- Interviews across security, IT, HR and facilities, not document review alone
- Maturity rating and evidence notes for every control in scope
- Prioritised remediation roadmap with realistic effort estimates
- Findings workshop, not just a report left in your inbox
Everything in the engagement, set out up front.
The gap analysis is scoped and agreed with you before work starts, so there's no ambiguity about what you'll receive.
Scope and context review
Confirming ISMS scope boundaries, interested parties and applicability before assessment begins.
Clause 4-10 assessment
Leadership, planning, support, operation, performance evaluation and improvement requirements reviewed in turn.
Annex A control walkthrough
All 93 controls across organisational, people, physical and technological themes assessed for existence and evidence.
Statement of Applicability review
Testing existing inclusions and exclusions against actual risk treatment, or drafting a starting SoA where none exists.
Stakeholder interviews
Structured conversations with role holders across security, IT operations, HR and facilities.
Prioritised roadmap
Findings sequenced by risk and effort, with clear ownership suggestions for what comes next.
What you receive.
- Clause-by-clause maturity assessment
- Annex A control-by-control findings register
- Evidence notes for every rated item
- Draft or reviewed Statement of Applicability
- Prioritised remediation roadmap
- Findings presentation and workshop
- Executive summary suitable for board reporting
- Recommended ISMS scope statement
Built for organisations that need the work done properly.
Organisations starting an ISMS from scratch
You know customers or contracts require ISO 27001 but haven't started building a management system yet.
Teams unsure of their real maturity
You've got strong technical controls but no confidence they'd hold up under formal scrutiny.
Businesses that stalled mid-implementation
Work started, momentum was lost, and you need an honest reset before continuing.
Organisations preparing for a certification body approach
You want a realistic view of readiness before engaging an accredited certification body for Stage 1.
What changes once the work is done.
The point of a gap analysis isn't the report itself — it's the decisions your organisation can now make with confidence.
A defensible starting point
Every rating is backed by evidence notes, so the roadmap holds up when challenged internally.
Clear sequencing
You know what to fix first, based on risk and effort rather than alphabetical order in a spreadsheet.
A realistic timeline
Board and customer conversations about certification dates are grounded in evidence, not optimism.
Reduced audit risk
Fewer surprises when a Stage 1 auditor from your chosen certification body reviews the same ground.
A usable Statement of Applicability
Inclusions and exclusions that can actually be justified when asked.
Internal buy-in
A findings workshop that gets stakeholders aligned on priorities rather than debating them after the fact.
Why the 2022 revision matters for your gap analysis.
ISO/IEC 27001:2022 restructured Annex A into four themes — organisational, people, physical and technological — and reduced the control count from 114 to 93, consolidating several and introducing new ones covering areas such as threat intelligence, cloud security and data masking. Organisations still working from 2013-era templates are often assessing themselves against the wrong list entirely.
This matters practically: a gap analysis run against the old structure will misjudge coverage, particularly around the newer technology-related controls that didn't exist in the previous version. We assess against the current standard as published, not a historical version that happens to be easier to find templates for.
It also affects how the Statement of Applicability is structured, since the SoA needs to map to the current control set and theme grouping to be accepted by a certification body. Getting this wrong early tends to cascade into rework later in an implementation project.
We keep our methodology aligned to the current edition and update it as guidance documents from the standard's maintaining committee evolve, so a gap analysis carried out with us reflects what an auditor will actually be checking against.
Questions we are asked most often.
What exactly is an ISO 27001 gap analysis?
It's a structured review of your current information security arrangements against the clauses of ISO/IEC 27001:2022 (4-10) and the 93 controls set out in Annex A, grouped under the organisational, people, physical and technological themes. We tell you what exists, what's partial, and what's missing, before you commit resource to building an ISMS.
How is this different from ISO 27001 implementation support?
Gap analysis is a diagnostic, not a build. We don't write your policies or run your risk workshops here — we produce an honest baseline report and a prioritised list of work. Some clients take that report and implement themselves; others bring in separate implementation support afterwards.
Do you certify us against ISO 27001?
No. Certification is issued by an accredited certification body following Stage 1 and Stage 2 audits. We're not a certification body and don't claim accreditation. Our role is to help you understand and close the gap before you approach one, so the audit isn't a surprise.
How long does a gap analysis take?
For a single-site organisation with a defined scope, most gap analyses run two to four weeks from kick-off to final report, including document review, interviews and a findings workshop. Multi-site or multi-system scopes take longer — we scope this properly at the outset rather than guessing.
Will you assess our Statement of Applicability if we already have one?
Yes. If a draft SoA exists we test the justifications behind each inclusion and exclusion against your actual risk treatment plan and operating environment, rather than taking it at face value. It's common to find controls marked applicable with no real supporting evidence, or excluded ones that should be in scope.
What does the final report look like?
A clause-by-clause and Annex A control-by-control assessment with a maturity rating, evidence notes, and a prioritised remediation list mapped to owners and rough effort. We present findings in a working session rather than emailing a document and disappearing.
Can you carry out the gap analysis remotely?
Much of the document review and interviewing can be done remotely, and we do this routinely for clients outside our core delivery area. Where a physical walkthrough adds value — server rooms, access control, clear desk practice — we prefer to be on site, and we cover Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London directly.
Who should be involved from our side?
At minimum, someone who owns information security day to day and someone with visibility of HR, IT operations and facilities. For smaller organisations this can be one or two people; for larger ones we typically interview six to ten role holders across functions to get an accurate picture.
Compliance support
Framework-wide compliance work spanning Cyber Essentials, ISO 27001, NHS DSPT and more.
Vulnerability management
Ongoing technical assurance that supports the evidence base behind Annex A technological controls.
Penetration testing
Independent technical testing that feeds directly into risk treatment and control evidence.
Get an honest baseline before you commit resource.
Tell us your target scope and timeline. We'll come back with a realistic view of what a gap analysis would involve for your organisation.
Talk to a consultant