{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "version": "1.0",
  "last_updated": "2026-08-12",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "product": {
    "id": "iso27001-gap-assessment",
    "name": "ISO 27001 Gap Assessment (Free Tool)",
    "category": "Information security gap assessment tool",
    "type": "WebApplication",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "canonical_url": "https://irmcon.com/products/iso27001/",
    "delivery_model": "Web-based self-serve tool",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "summary_50_words": "Free, self-serve gap assessment tool that measures organizations against ISO/IEC 27001:2022, the international standard for Information Security Management Systems (ISMS), covering the Clause 4 to 10 requirements and all 93 Annex A controls, with likelihood and impact risk scoring, risk-ranked gaps, and a downloadable report with a prioritized remediation roadmap.",
    "summary_200_words": "The ISO 27001 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures an organization against ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements, published by ISO and IEC. The user chooses an assessment scope: Clauses Only (Level 1) covers the mandatory ISMS requirements of Clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation, and improvement), while Clauses & Annex Controls (Level 2) adds all 93 Annex A information security controls across four themes: A.5 Organizational, A.6 People, A.7 Physical, and A.8 Technological, aligned with ISO/IEC 27002:2022. The user captures their company profile, works through each requirement and control, marking each compliant, partially compliant, non-compliant, or not applicable. Each gap is scored on a 5x5 risk matrix (likelihood times impact) and ranked Low, Medium, High, or Critical. The tool then generates a professional, downloadable report in PDF or Word format containing an executive summary, detailed findings, and a phased remediation roadmap across 30, 90, 180, and 365 day horizons. It is an independent tool, not affiliated with or endorsed by ISO or IEC, and complements IRM's Governance, Risk & Compliance and Virtual CISO services.",
    "feature_list": [
      "Assesses the ISO/IEC 27001:2022 Clause 4 to 10 ISMS requirements (Clauses Only, Level 1)",
      "Adds all 93 Annex A information security controls at the Clauses & Annex Controls (Level 2) scope",
      "Covers the A.5 Organizational, A.6 People, A.7 Physical and A.8 Technological control themes",
      "Scores each gap by likelihood and impact on a 5x5 risk matrix",
      "Ranks gaps as Low, Medium, High, or Critical",
      "Generates a report with an executive summary and detailed findings",
      "Builds a phased remediation roadmap (30, 90, 180, 365 days)",
      "Downloads as PDF or Word with your company logo"
    ],
    "frameworks": [
      "ISO/IEC 27001:2022, Information Security Management System (ISMS)"
    ],
    "target_audience": [
      "Small and medium organizations",
      "Startups",
      "SaaS companies preparing for ISO 27001 certification"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "IT Manager",
      "Chief Risk Officer",
      "Compliance Manager"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.com/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.com/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "Governance, Risk & Compliance Services",
        "url": "https://irmcon.com/governance-risk-compliance-grc/"
      },
      {
        "name": "Virtual CISO Services",
        "url": "https://irmcon.com/virtual-ciso-services-vciso/"
      }
    ]
  }
}
