ISO 27001 Gap Assessment
Find out exactly what is missing before you attempt certification.
In plain terms
ISO 27001 is the international standard for running a real information security programme. Certification works like a credit score for security — something you can show a customer instead of asking them to take your word for it. A gap assessment tests you against all 93 Annex A controls plus the management-system clauses, and tells you precisely what stands between you and a certificate.
What you get
- Assessment against all 93 Annex A controls and clauses 4–10
- Findings rated by severity, with the evidence we could and could not see
- A gap closure plan sequenced by effort and dependency, not alphabetically
- Statement of Applicability draft you can carry into certification
Who it is for
Companies being asked for ISO 27001 by a customer, an investor, or a tender — and companies who want to know the real cost before committing.
Tool
The 93 controls we assess against
This is the exact scope of the gap assessment. Click any control to see what it asks for.
Control titles follow ISO/IEC 27001:2022 Annex A. Plain-English lines are our paraphrase, not the wording of the standard.
The part people skip
Clauses 4–10 are the requirements. Annex A is a catalogue.
ISO/IEC 27001 contains requirements an organisation must address to claim conformity. Those requirements live in clauses 4 to 10 — the management-system clauses. They are not optional and there is no picking among them.
Annex A is different. It is a reference set of 93 controls, and which of them apply to you is determined by your risk assessment and recorded in your Statement of Applicability. Excluding a control is legitimate where the SoA justifies it. Excluding a clause is not.
Context of the organisation
Determine internal and external issues, interested parties and their requirements, and define the ISMS scope. Everything downstream inherits from the scope statement.
Leadership
Top management commitment, an information security policy, and assigned roles, responsibilities and authorities. This is where an ISMS most often fails first.
Planning
Actions to address risks and opportunities, the risk assessment and treatment process, the Statement of Applicability, and measurable information security objectives.
Support
Resources, competence, awareness, communication and documented information — including how documents are controlled.
Operation
Operational planning and control, and carrying out the risk assessment and treatment you designed in clause 6 rather than merely describing it.
Performance evaluation
Monitoring, measurement, analysis and evaluation, internal audit, and management review.
Improvement
Nonconformity and corrective action, and continual improvement.
Terminology follows ISO/IEC 27001:2022. Certification is issued by an accredited certification body — DATADEFENZ prepares organisations for that assessment and does not certify.
Evidence
A policy is not a control. A control is not evidence.
The most expensive assumption in certification is that documentation equals conformity. An auditor asks three separate questions, and a document only answers the first.
Does it exist?
Is there a documented requirement, policy or procedure? This is the question a document answers, and the only one it answers.
Does it run?
Implementation plus evidence. Logs, approvals, tickets, records — artefacts produced by the control operating, not by someone describing it.
Does it work?
Effectiveness. Can you show the control achieved its objective, and that you measured it? Clause 9.1 asks this directly.
How we rate each requirement
Not assessed · Not implemented · Partially implemented · Implemented · Effective · Evidence insufficient · Needs improvement · Not applicable — justification required. Deliberately not “compliant / non-compliant”: that binary hides the distinction between a control that is missing and one that exists but cannot be demonstrated, and those two findings need completely different remediation.
