What an ISO 27001 Gap Analysis Is
A gap analysis measures your current position against ISO 27001 — both the management system requirements in clauses 4 to 10 and the 93 Annex A controls — and tells you what is in place, what is partial, and what is missing. It produces a findings register, a recommended ISMS scope, and an implementation roadmap with effort and cost attached to every gap.
It is preparation work, not certification. It is also not a Stage 1 audit: Stage 1 is performed by an accredited certification body as the first half of the certification audit. A gap analysis is what makes Stage 1 uneventful.
Why Scope Comes First
Most ISO 27001 advice treats scope as an administrative step. It is the most consequential decision in the entire project.
Scope determines audit days, and audit days determine fees — for three years. An ISMS scoped around every system the company owns costs more at Stage 2, more at each surveillance audit, and more at recertification, forever. An ISMS scoped around the systems that genuinely handle the information you are protecting costs less at every one of those events.
Companies that skip this step routinely make one of two mistakes:
Scoping too broadly, usually because it feels more impressive or because nobody wanted to argue for exclusions. This is the expensive one, and it compounds.
Scoping too narrowly, so the certificate does not cover the product a customer is asking about. Cheaper, but it wastes the certificate.
Getting this right is most of why the gap analysis exists.
What We Assess
Both halves of the standard. Companies often assess Annex A and forget that the clauses are where nonconformities actually get raised.
| Clause | Requirement | Where companies are weakest |
|---|---|---|
| 4 — Context | Interested parties, ISMS scope | Scope written vaguely or too broad |
| 5 — Leadership | Policy, roles, commitment | Policy exists, ownership does not |
| 6 — Planning | Risk assessment, treatment, objectives | Risk register with no owners or dates |
| 7 — Support | Competence, awareness, documentation | Training not evidenced |
| 8 — Operation | Running the risk treatment plan | Plan written, never executed |
| 9 — Evaluation | Internal audit, management review | Both missing — the most common nonconformity |
| 10 — Improvement | Nonconformity and corrective action | No corrective action log |
Plus all 93 Annex A controls across the organizational, people, physical and technological themes, each marked applicable or not with the justification that will appear in your Statement of Applicability.
What You Get
A findings register. Every clause requirement and every applicable Annex A control scored in place, partial or missing, with the evidence we saw and the reason for anything short of in place.
A scope recommendation. What belongs inside the ISMS, what should be excluded, and what the difference costs you across a three-year cycle.
A draft Statement of Applicability. The 93 controls with applicability and justification, which is the document Stage 1 examines most closely.
A costed implementation roadmap. Each gap with an owner, an effort estimate and a cost, sequenced so the mandatory clauses close before the optional refinements.
A realistic certification date. Accounting for implementation, internal audit, and certification body scheduling — which is usually the constraint nobody has checked.
Cost and Timeline
A gap analysis is stage one of an ISO 27001 programme and is priced within it. For context, a full Avantcert ISO 27001 engagement runs:
| Tier | Employees | Full engagement | Certification body fee | Max duration |
|---|---|---|---|---|
| Startup | 5–50 | from $4,000 | Separate | 60 days |
| Mid-Market | 51–200 | around $9,500 | Separate | 60 days |
| Large Enterprise | 201–500 | up to $15,000 | Separate | 60 days |
The accredited certification body's Stage 1 and Stage 2 audit fee is separate and paid directly to them, because the organization that prepares you cannot also audit you.
Most single-site gap analyses run two to three weeks. Full cost detail in ISO 27001 certification cost.
Book an ISO 27001 Gap Analysis
Tell us your headcount and roughly what you think belongs in the ISMS. Scoped proposal within 24 hours.
Our form could not load. Email your headcount and scope and you'll get the same proposal within 24 hours.
Email your requirements Open the full quote formGap Analysis FAQs
What is an ISO 27001 gap analysis?
A structured assessment of your current position against ISO 27001 — both the management system clauses 4 to 10 and the 93 Annex A controls. It produces a findings register, a recommended ISMS scope, and an implementation roadmap with effort and cost attached to each gap.
Is a gap analysis the same as a Stage 1 audit?
No. A gap analysis is preparation work performed by a consultant and carries no certification weight. Stage 1 is the first half of the certification audit, performed by an accredited certification body, and it checks whether your documented ISMS is ready for Stage 2. A gap analysis is what makes Stage 1 uneventful.
How long does an ISO 27001 gap analysis take?
Typically two to three weeks for a single-site company, driven mainly by how quickly your team can produce evidence and how many systems fall inside the proposed scope. Scoping is the first activity and it usually determines everything after it.
Do I need a gap analysis before ISO 27001 certification?
It is not mandatory. What it prevents is committing to an ISMS scope you will pay for at every audit for three years, and discovering at Stage 1 that your Statement of Applicability cannot justify its exclusions. Both are expensive to fix late and cheap to get right at the start.
Do I have to implement all 93 Annex A controls?
No. You must consider all 93 and justify which apply to you in the Statement of Applicability. A control excluded with clear justification is fine; a control excluded because nobody assessed it is a nonconformity. Determining which genuinely apply is a core output of the gap analysis.
What Happens Next
The gap analysis is stage one of an ISO 27001 engagement. See how the full engagement runs, what certification costs, or read the ISO 27001 overview if you are still deciding whether you need it.
Official reference: ISO/IEC 27001.
Get your scope right before you pay for it
Two to three weeks, and you know the gap, the cost and the date.