Links on this site open in a new browser tab.
Taking new engagements — Q4 hello@datadefenz.com Employee Login
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutLet's Work TogetherBook a 30-minute callContact
Services / GRC & Compliance / ISO 27001 Gap Assessment

ISO 27001 Gap Assessment

Find out exactly what is missing before you attempt certification.

In plain terms

ISO 27001 is the international standard for running a real information security programme. Certification works like a credit score for security — something you can show a customer instead of asking them to take your word for it. A gap assessment tests you against all 93 Annex A controls plus the management-system clauses, and tells you precisely what stands between you and a certificate.

What you get

  • Assessment against all 93 Annex A controls and clauses 4–10
  • Findings rated by severity, with the evidence we could and could not see
  • A gap closure plan sequenced by effort and dependency, not alphabetically
  • Statement of Applicability draft you can carry into certification

Who it is for

Companies being asked for ISO 27001 by a customer, an investor, or a tender — and companies who want to know the real cost before committing.

Tool

The 93 controls we assess against

This is the exact scope of the gap assessment. Click any control to see what it asks for.

Select a controlClick, or tab in and use arrow keys

Control titles follow ISO/IEC 27001:2022 Annex A. Plain-English lines are our paraphrase, not the wording of the standard.

The part people skip

Clauses 4–10 are the requirements. Annex A is a catalogue.

ISO/IEC 27001 contains requirements an organisation must address to claim conformity. Those requirements live in clauses 4 to 10 — the management-system clauses. They are not optional and there is no picking among them.

Annex A is different. It is a reference set of 93 controls, and which of them apply to you is determined by your risk assessment and recorded in your Statement of Applicability. Excluding a control is legitimate where the SoA justifies it. Excluding a clause is not.

Clause 4

Context of the organisation

Determine internal and external issues, interested parties and their requirements, and define the ISMS scope. Everything downstream inherits from the scope statement.

Clause 5

Leadership

Top management commitment, an information security policy, and assigned roles, responsibilities and authorities. This is where an ISMS most often fails first.

Clause 6

Planning

Actions to address risks and opportunities, the risk assessment and treatment process, the Statement of Applicability, and measurable information security objectives.

Clause 7

Support

Resources, competence, awareness, communication and documented information — including how documents are controlled.

Clause 8

Operation

Operational planning and control, and carrying out the risk assessment and treatment you designed in clause 6 rather than merely describing it.

Clause 9

Performance evaluation

Monitoring, measurement, analysis and evaluation, internal audit, and management review.

Clause 10

Improvement

Nonconformity and corrective action, and continual improvement.

Terminology follows ISO/IEC 27001:2022. Certification is issued by an accredited certification body — DATADEFENZ prepares organisations for that assessment and does not certify.

Evidence

A policy is not a control. A control is not evidence.

The most expensive assumption in certification is that documentation equals conformity. An auditor asks three separate questions, and a document only answers the first.

Requirement Policy Procedure Implementation Evidence Effectiveness Audit Improvement
Question one

Does it exist?

Is there a documented requirement, policy or procedure? This is the question a document answers, and the only one it answers.

Question two

Does it run?

Implementation plus evidence. Logs, approvals, tickets, records — artefacts produced by the control operating, not by someone describing it.

Question three

Does it work?

Effectiveness. Can you show the control achieved its objective, and that you measured it? Clause 9.1 asks this directly.

How we rate each requirement

Not assessed · Not implemented · Partially implemented · Implemented · Effective · Evidence insufficient · Needs improvement · Not applicable — justification required. Deliberately not “compliant / non-compliant”: that binary hides the distinction between a control that is missing and one that exists but cannot be demonstrated, and those two findings need completely different remediation.