Skip to content

ISO/IEC 27001:2022 ยท Before the audit

ISO 27001 gap analysis: how to run one and what to do with the findings

A gap analysis compares where you are today against what ISO 27001 requires, so the project stops being a fog and becomes a list. Here is how to run one step by step, and what to do with each kind of gap you find.

Overview

What is an ISO 27001 gap analysis?

An ISO 27001 gap analysis is a structured comparison of your organization's current security practices and documents against the requirements of the standard: the management clauses (4 to 10) and the 93 Annex A controls. The output is a list of gaps and a plan to close them. It is not mandated by the standard; it is simply the sensible first move before you build or overhaul an ISMS.

Gap analysis vs risk assessment

A gap analysis measures you against the standard: what is missing. A risk assessment evaluates threats to your information: what could go wrong. The risk assessment is mandatory (clause 6); the gap analysis is preparation for everything, including the risk assessment.

Gap analysis vs internal audit

An internal audit (clause 9.2) is a mandatory, planned check of a running ISMS with findings and follow-up. A gap analysis happens earlier, can be informal, and exists to scope the work rather than to test the system.

Timing

When you need one

Starting from scratch

You are building an ISMS for the first time and need to size the job before you commit people to it.

Inherited policies

A folder of stale or consultant-written documents, and nobody is sure what is still true.

Documents stuck in 2013

Your set was written against the 2013 edition and never properly updated to the 2022 revision, or recertification is approaching.

The business changed shape

An acquisition, a new product, a cloud migration: the paperwork no longer matches reality.

How it goes

How to run an ISO 27001 gap analysis, step by step

  1. 1

    Fix the scope first

    Decide which parts of the business, systems and locations the ISMS will cover. Every gap you record is relative to this boundary, so agreeing it first stops the analysis sprawling.

  2. 2

    Gather everything that exists

    Policies, procedures, registers, old risk assessments, supplier lists, induction packs. Half-written and out-of-date documents count: knowing what you have is the point.

  3. 3

    Walk the management clauses (4 to 10)

    For each requirement (scope, leadership, risk assessment, objectives, support, operation, evaluation, improvement), record whether you meet it, partially meet it, or have nothing.

  4. 4

    Walk the Annex A controls

    Go through all 93 controls across the 4 themes and mark each one: in place, partly in place, missing, or not applicable to your scope with a reason.

  5. 5

    Classify every gap: documentation or implementation

    A documentation gap means the practice may exist but nothing credible describes it. An implementation gap means the control itself is not actually in place. The fix for each is different, so the split matters.

  6. 6

    Prioritize and plan the treatment

    Order the gaps by risk and by audit impact. Clause-level gaps and missing mandatory documents come first; cosmetic improvements come last.

  7. 7

    Close the documentation gaps, track the implementation gaps

    Rebuild what you have, generate what is missing, and track each implementation gap to done, control by control, so the evidence exists by the time an auditor asks.

The full list of the 93 controls in their 4 themes is on our ISO 27001 controls list.

The output

What to do with the findings

Every finding lands in one of two lanes, and the lanes have different fixes. Documentation gaps are closed by writing: rebuilding the documents you have and generating the ones you are missing, each mapped to the clause or control it satisfies. That is the document set PolicyMint generates - or start closing them yourself with our information security policy template guide, which walks the top-level document clause by clause and what an auditor checks in each one.

Implementation gaps are closed by doing: turning on MFA, testing the backups, running the access review. Those need tracking to done, control by control, and our sister tool ControlStack maps the same 93 controls in an interactive tracker built for exactly that: PolicyMint closes the documentation lane, ControlStack tracks the implementation lane.

Your existing policies

Reviewing the policies you already have

Most companies arriving at a gap analysis are not starting from zero: there is an old information security policy, an acceptable use document from an induction pack, something a consultant wrote three years ago. Those documents are inputs, not waste.

Upload an existing Word, PDF, text or Markdown policy and PolicyMint reviews it and rebuilds it as a compliant, on-brand document in the structure the standard expects, keeping what you had that was worth keeping. It generates the documents you are missing entirely. And because the Statement of Applicability assembles itself from what your documents actually cover, any Annex A control with no covering document is visible at a glance: a live view of your documentation gaps that stays current as the set grows.

ISO 27001 documents

36

ISO 27001 documents

tiered by what you actually need

ISO 42001 documents

21

ISO 42001 documents

for AI management systems

Clauses and controls mapped

182

Clauses and controls mapped

every document cites the ones it satisfies

Verifiers per section

3

Verifiers per section

on a different model to the writer

Be clear

A gap analysis is not the audit

Closing the gaps gets you ready; certification itself is a two-stage audit by an accredited certification body. If your team wants the training or exam pathway on the way there, the Mindset Cyber family runs PECB-accredited ISO 27001 courses and MindsetPrep covers exam preparation.

PolicyMint produces the documentation you are audited against, not the certificate itself.

Gap analysis FAQ

ISO 27001 gap analysis, answered

The questions people ask before they start measuring the distance.

What is an ISO 27001 gap analysis?

A structured comparison of where your organization is today against what ISO 27001 requires: the management clauses 4 to 10 and the 93 Annex A controls. The output is a list of gaps, each classified as a documentation gap or an implementation gap, that becomes your plan of work.

Is a gap analysis mandatory for ISO 27001?

No. The standard does not require one. It is standard practice before starting an ISMS because it turns an intimidating project into a concrete list, but it is not documented information the standard requires, so no auditor can demand one.

What is the difference between a gap analysis and a risk assessment?

A gap analysis compares you against the standard's requirements: what is missing. A risk assessment evaluates threats to your information: what could go wrong and how much it matters. The risk assessment is mandatory under clause 6; the gap analysis is preparation.

What is the difference between a gap analysis and an internal audit?

Timing and formality. A gap analysis happens before or during implementation and can be informal. An internal audit is a mandatory, planned activity (clause 9.2) that checks a running ISMS against the standard and your own documents, with findings and follow-up.

How long does an ISO 27001 gap analysis take?

For a small company, days rather than weeks: the honest version is a workshop walking the clauses and controls with the people who run the systems, plus the time to write up the findings. Larger scopes and multiple sites take proportionally longer.

Can PolicyMint do my gap analysis?

PolicyMint closes the documentation side. Upload the policies you already have and it reviews and rebuilds them as compliant, on-brand documents; it tells you which documents your scope requires and generates the missing ones; and the auto-assembled Statement of Applicability shows any Annex A control no document covers. Tracking whether each control is actually implemented is a different job, and our sister tool ControlStack does that.

What do I do after a gap analysis?

Close the documentation gaps first, because they are fast and everything else hangs off them. Then work the implementation gaps in priority order, run the system long enough to produce evidence, do the mandatory internal audit and management review, and book the certification audit.

PolicyMint / Next issue Ready when you are

Stop staring at an empty document set

Set up your business once. Get the documents you actually need, written for how you really operate, in your branding, checked before you see them.

Your first document is on us. We ask for a card to begin and you are not charged for it, and there is no sales call. See pricing