The ISO 27001 Gap Assessment is a free tool that measures your organization against ISO/IEC 27001:2022, the international standard for Information Security Management Systems (ISMS). Assess the Clause 4 to 10 management system requirements at the Clauses Only (Level 1) scope, or add all 93 Annex A controls at the Clauses & Annex Controls (Level 2) scope; generate a downloadable report that includes a remediation roadmap.
The ISO 27001 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against ISO/IEC 27001:2022, the international standard for Information Security Management Systems (ISMS) published by ISO and IEC.
You choose your scope: Clauses Only (Level 1) covers the mandatory management system requirements of Clauses 4 to 10, and Clauses & Annex Controls (Level 2) adds all 93 information security controls from Annex A. You assess each requirement and control, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
ISO 27001, formally ISO/IEC 27001:2022, is the international standard for Information Security Management Systems (ISMS), published by ISO and IEC and the most widely adopted certifiable security standard in the world. It defines the mandatory management system requirements in Clauses 4 to 10 and 93 reference information security controls in Annex A, organized into Organizational, People, Physical, and Technological themes. Organizations of any size or industry can implement it, and accredited certification bodies audit and certify conformance, which is why enterprise customers and regulators treat an ISO 27001 certificate as strong evidence of a working security program.
The assessment is built for small and medium organizations, startups, and growing SaaS companies that face customer security questionnaires or enterprise procurement requirements and want to understand where they stand against ISO/IEC 27001:2022 before pursuing certification.
The Clauses Only (Level 1) scope is the right starting point for organizations building their first information security management system, while the Clauses & Annex Controls (Level 2) scope suits teams preparing for certification readiness or a full Statement of Applicability.
Enter your company name, website, and a description of what the company does, choose the Clauses Only (Level 1) or Clauses & Annex Controls (Level 2) assessment scope, and add your logo for the report.
Work through the Clause 4 to 10 ISMS requirements, plus the 93 Annex A controls at the Level 2 scope, mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.
Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.
Not loading? Open the ISO 27001 Gap Assessment tool in a new tab.
This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice, and it is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.
An ISO 27001 gap analysis, also called a gap assessment, is a structured comparison of your organization's current information security practices against the requirements of ISO/IEC 27001:2022, identifying which clause requirements and Annex A controls you already meet, where you fall short, and what to fix first. It is the standard starting point for any Information Security Management System (ISMS) implementation or certification project.
A good gap assessment, sometimes called an ISO 27001 readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which of the mandatory Clause 4 to 10 requirements and the 93 Annex A controls apply to you, given your business, technology stack and the information you protect? Secondly, Conformance: for each applicable requirement, do you have the process, the documentation, and the evidence an auditor would ask for?
Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your compliance obligations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.
Run your first gap assessment before you spend anything on implementation or certification. The typical ISO 27001 journey for a small or medium organization has five stages: gap assessment, remediation, internal audit (required by Clause 9.2), management review (Clause 9.3), and then the two-stage certification audit with an accredited certification body. The gap assessment sets the scope, budget, and timeline for everything that follows; organizations that skip it routinely discover missing risk assessments or undocumented controls mid-audit, when fixes are most expensive.
Repeat the assessment after major remediation work, after significant changes to your business, technology or threat environment, and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.
Annex A of ISO/IEC 27001:2022 provides 93 information security controls organized into four themes, A.5 through A.8, aligned with the guidance in ISO/IEC 27002:2022. They are not all mandatory: you select the controls your risk treatment requires and justify inclusions and exclusions in your Statement of Applicability. The 2022 edition consolidated the 114 controls of the 2013 edition into 93, adding new controls such as threat intelligence, cloud services security, data masking, data leakage prevention, and web filtering.
| Theme | Control theme | Controls | What it covers |
|---|---|---|---|
| A.5 | Organizational controls | 37 | Policies, roles and segregation of duties, threat intelligence, asset inventory and classification, access control and identity management, supplier and cloud security, incident management, business continuity and ICT readiness, and legal, records, privacy and compliance obligations. |
| A.6 | People controls | 8 | Screening, terms of employment, security awareness and training, disciplinary process, post-employment responsibilities, confidentiality agreements, remote working, and security event reporting. |
| A.7 | Physical controls | 14 | Security perimeters and entry, securing offices and secure areas, physical monitoring, environmental protection, clear desk and clear screen, equipment protection and maintenance, storage media, utilities, cabling, and secure disposal or re-use of equipment. |
| A.8 | Technological controls | 34 | Endpoint devices, privileged access, secure authentication, malware protection, vulnerability and configuration management, data deletion, masking, leakage prevention and backup, logging and monitoring, network security and segregation, cryptography, and the secure development life cycle. |
The Statement of Applicability (SoA) is the document Clause 6.1.3 requires: a list of the controls you consider necessary, with justification for every inclusion and exclusion and their implementation status. Auditors treat it as the index to your whole ISMS, and it is usually the first document a certification body asks for.
The two assessment scopes in the tool map directly onto SoA preparation. The Clauses Only (Level 1) scope covers the Clause 4 to 10 management system requirements, which are mandatory for every organization and are never excluded in an SoA; assessing them first tells you whether the management system itself (context, leadership, risk processes, support, operation, evaluation, and improvement) stands up.
The Clauses & Annex Controls (Level 2) scope adds all 93 Annex A controls, which is precisely the set you must dispose of in the SoA. Your assessment results give each control a status: compliant controls become "implemented" entries, partially compliant and non-compliant controls become "planned" entries tied to your remediation roadmap dates, and controls you mark not applicable become documented exclusions with your reasoning. Run the Level 2 scope and you have effectively drafted the evidence base for your first SoA.
A gap assessment is a diagnostic you run for yourself before building your ISMS; an internal audit is the recurring conformance check Clause 9.2 requires once the ISMS exists; a certification audit is the independent, two-stage examination by an accredited body that results in an ISO/IEC 27001 certificate. They answer different questions at different times, and none replaces the others.
| Gap assessment | Internal audit (Clause 9.2) | Certification audit | |
|---|---|---|---|
| Purpose | Measure your current information security management system against ISO/IEC 27001 to find and prioritize gaps before you invest in remediation. | Verify that your implemented ISMS conforms to ISO/IEC 27001 and your own requirements, and is effectively maintained. | Independent verification by an accredited certification body that your ISMS conforms to ISO/IEC 27001, leading to a certificate. |
| Who performs it | You (self-assessment) or a consultant. No independence requirement. | Internal staff or an outsourced auditor who is objective and impartial (they cannot audit their own work). | An accredited third-party certification body. |
| Required by the standard | No. It is a preparatory best practice, not a requirement. | Yes. Clause 9.2 requires internal audits at planned intervals. | Only if you want certification. Conformance without certification is possible. |
| Typical timing | At the start of your ISO 27001 journey, and again after major remediation or significant business or technology changes. | After the ISMS is implemented, then on a recurring audit programme. | After at least one internal audit and management review cycle. Stage 1 reviews documentation, Stage 2 audits implementation, followed by annual surveillance audits and recertification every three years. |
| Output | A gap report: compliance score, risk-ranked findings, and a remediation roadmap. | Audit report with nonconformities and observations feeding corrective action (Clause 10.2). | Audit findings and, on success, an ISO/IEC 27001 certificate with surveillance audits in following years. |
| What happens with findings | Findings become your remediation plan and inform your Statement of Applicability. Nothing is reported externally. | Findings are reported to management and tracked to closure as corrective actions. | Major nonconformities block certification until resolved; minors require a corrective action plan. |
The table below summarizes every mandatory requirement in Clauses 4 to 10 of ISO/IEC 27001:2022 and the evidence auditors typically expect to see for each. The summaries are condensed guidance prepared by IRM Consulting & Advisory, not verbatim standard text; the assessment tool above walks you through all 25 of these requirements at either scope.
| Clause | Requirement | Summary | Evidence auditors expect |
|---|---|---|---|
| 4.1 | Understanding the organization and its context | Determine the internal and external issues relevant to your ISMS and its intended outcomes, including whether climate change is a relevant issue. | Documented context analysis. |
| 4.2 | Needs and expectations of interested parties | Identify the interested parties relevant to the ISMS, their requirements, and which requirements the ISMS will address. | Interested party and requirements register. |
| 4.3 | Scope of the ISMS | Define the boundaries and applicability of the ISMS, considering context, interested party requirements, and interfaces and dependencies with other organizations. | A documented, approved scope statement. |
| 4.4 | Information security management system | Establish, implement, maintain, and continually improve the ISMS and its processes. | ISMS documentation and process interactions. |
| 5.1 | Leadership and commitment | Top management demonstrates leadership: policy and objectives set, ISMS integrated into business processes, resources provided, improvement promoted. | Management meeting records and resourcing decisions. |
| 5.2 | Information security policy | Establish an information security policy appropriate to the organization that frames objectives and commits to requirements and continual improvement. | The approved, communicated policy document. |
| 5.3 | Roles, responsibilities and authorities | Assign and communicate responsibilities for ISMS conformance and for reporting ISMS performance to top management. | Role descriptions or a RACI matrix. |
| 6.1.1 | Risks and opportunities (general) | Determine the risks and opportunities the ISMS must address and plan actions to address them. | Documented planning outputs and risk register. |
| 6.1.2 | Information security risk assessment | Define a repeatable risk assessment process with risk acceptance criteria, risk owners, and analysis of consequences, likelihood, and risk levels. | Risk assessment procedure and assessment records. |
| 6.1.3 | Information security risk treatment | Select treatment options, determine necessary controls, compare against Annex A, and produce a Statement of Applicability and an approved risk treatment plan. | Statement of Applicability and risk treatment plan with risk owner approvals. |
| 6.2 | Information security objectives and planning | Set measurable, monitored, communicated information security objectives at relevant functions, with plans to achieve them. | Documented objectives with owners, timelines, and evaluation methods. |
| 6.3 | Planning of changes | Carry out changes to the ISMS in a planned manner. | Change plans and records. |
| 7.1 | Resources | Provide the resources needed to establish, implement, maintain, and improve the ISMS. | Budgets, staffing, and tooling decisions. |
| 7.2 | Competence | Determine and ensure the competence of people whose work affects information security performance. | Competency matrix and training records. |
| 7.3 | Awareness | Ensure people know the policy, their contribution, and the implications of nonconformance. | Awareness training and communication evidence. |
| 7.4 | Communication | Determine what to communicate about the ISMS, when, with whom, and how. | A communication plan. |
| 7.5 | Documented information | Create, update, and control the documented information the ISMS requires, including protection, versioning, retention, and disposition. | Document control procedure and controlled records. |
| 8.1 | Operational planning and control | Plan and control the processes that implement your Clause 6 actions, control planned and unintended changes, and control externally provided processes and services. | Process criteria, operating records, and supplier controls. |
| 8.2 | Risk assessment (operational) | Perform information security risk assessments at planned intervals and on significant change. | Dated risk assessment results. |
| 8.3 | Risk treatment (operational) | Implement the information security risk treatment plan. | Treatment implementation records and results. |
| 9.1 | Monitoring, measurement, analysis, evaluation | Decide what to monitor and measure, with what methods, timing and responsibilities, and evaluate security performance and ISMS effectiveness. | Metrics definitions and evaluation reports. |
| 9.2 | Internal audit | Run an internal audit programme at planned intervals with objective auditors and defined criteria and scope. | Audit programme, audit reports, and auditor selection rationale. |
| 9.3 | Management review | Top management reviews the ISMS at planned intervals with defined inputs, including interested party feedback and risk treatment status, and documented results. | Management review minutes and decisions. |
| 10.1 | Continual improvement | Continually improve the suitability, adequacy, and effectiveness of the ISMS. | Improvement log and implemented changes. |
| 10.2 | Nonconformity and corrective action | React to nonconformities, correct them, address root causes, and verify corrective action effectiveness. | Nonconformity register and corrective action records. |
Closing the gaps is where most organizations want help. IRM's Virtual CISO services take teams from gap assessment through certification readiness for ISO 27001, ISO 42001, SOC 2 and CMMC, and our Governance, Risk & Compliance services build the policies, risk management and evidence habits a clean certification audit depends on.
Yes. The ISO 27001 Gap Assessment is a free, self-serve tool. You capture your company profile, choose your assessment scope, assess each ISO/IEC 27001:2022 requirement and Annex A control, and download a professional report with a remediation roadmap at no cost.
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS), published by ISO and IEC. It specifies requirements for establishing, implementing, maintaining and continually improving an information security management system, so organizations protect the confidentiality, integrity and availability of their information. Clauses 4 to 10 define the mandatory management system requirements, and Annex A provides 93 information security controls in four themes: Organizational, People, Physical and Technological.
Clauses Only (Level 1) assesses the mandatory ISMS requirements of Clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, and improvement. Clauses & Annex Controls (Level 2) covers everything in Level 1 plus all 93 Annex A controls, spanning organizational controls such as policies, asset management, access control, supplier security and incident management, people controls, physical controls, and technological controls such as logging, cryptography and secure development.
Each requirement and control is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).
The report includes an executive summary with your compliance score and top risks, detailed findings for every assessed clause requirement and Annex A control, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.
No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.
No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice, and it is an independent tool that is not affiliated with or endorsed by ISO or IEC. We recommend you seek advice from a Virtual CISO to validate findings, build your Statement of Applicability, and prepare for certification.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


