ISO 27001 gap assessments for consultants
Updated
An ISO 27001 gap assessment compares a client’s current practices with the requirements of ISO/IEC 27001:2022: the management system clauses 4 to 10 and the 93 controls in Annex A. The output is a list of what is conformant, what is missing and what to fix first, usually delivered as a readiness report before the client engages a certification body. For a consultant, most of the work is collecting the right evidence and explaining each conclusion clearly.
What the assessment covers
| Part | What it asks | Typical evidence |
|---|---|---|
| Clauses 4 to 10 | Context, scope, leadership, risk assessment and treatment, support, operation, performance evaluation and improvement | ISMS scope statement, risk register, risk treatment plan, internal audit reports, management review minutes |
| Annex A, organizational (37 controls) | Policies, roles, supplier relationships, incident management, business continuity, compliance | Policy set, supplier register and contracts, incident records, continuity test results |
| Annex A, people (8 controls) | Screening, terms of employment, awareness training, disciplinary process, remote working | Onboarding checklists, training completion records |
| Annex A, physical (14 controls) | Secure areas, equipment, clear desk, disposal | Site access records, disposal certificates |
| Annex A, technological (34 controls) | Access, authentication, malware, vulnerabilities, logging, backups, secure development | Identity provider exports, patch reports, backup and restore logs, change tickets |
The Statement of Applicability
The Statement of Applicability (SoA) records which Annex A controls apply, why, and whether each is implemented. It is a required document and one of the first things a certification auditor reads. Treat it as part of the gap assessment rather than a separate deliverable: exclusions need a justification, and a control declared as implemented still needs evidence.
Running the engagement
- Confirm the ISMS scope. Which locations, teams, systems and services are in, and which are out. Most later disagreements trace back to an unclear scope.
- Request evidence with a purpose. Tie each request to the clauses and controls it supports, so the client knows why you are asking.
- Assess each requirement. Record what the evidence establishes, what remains open, and whether the requirement is conformant.
- Deliver the report. Show the gaps, their priority and a practical remediation path. Keep the scope and exclusions visible so the client sees what the conclusion covers.
- Reassess. After remediation, rerun on the updated evidence and show the change since the first pass.
How Control+s supports ISO 27001 gap assessments
- Scope and SoA. Set the ISMS scope, mark Annex A applicability with justifications, and record the declared implementation status separately from what the evidence shows.
- Conformity and maturity. Each requirement gets a conformity result and a maturity score from 0 to 5 with a rationale citing the evidence. You can override either one.
- Evidence once, many frameworks. The same uploads can support SOC 2, NIST CSF or CIS Controls if the client needs them later.
- Readiness report. Generate a Word or PDF report with the ISMS scope, exclusions and their justifications, detailed findings by clause, a gap register and remediation guidance.
- Auditor review. Invite the client’s auditor to review controls, evidence and rationale, and to raise challenges against specific scores.
Control+s does not issue ISO certificates. Certification comes from an accredited certification body; Control+s prepares the assessment behind your readiness advice.
Frequently asked questions
How many Annex A controls are in ISO 27001:2022?
ISO/IEC 27001:2022 lists 93 controls in Annex A, grouped into four themes. There are 37 organizational controls, 8 people controls, 14 physical controls and 34 technological controls.
Is ISO 27001:2013 still valid?
No. The transition period set by the International Accreditation Forum ended on 31 October 2025. Certificates against the 2013 edition are no longer valid, so gap assessments should use ISO/IEC 27001:2022, including Amendment 1 from 2024.
What is the difference between a gap assessment and an internal audit?
A gap assessment measures how far the organization is from the standard, usually before certification or early in an ISMS. It can be done by a consultant who also helps close the gaps. An internal audit is a required ISMS activity under clause 9.2 and must be objective and impartial, so the auditor should not audit their own work.
Does a maturity score replace ISO conformity?
No. Certification asks whether each requirement is conformant. A maturity score is useful for showing progress and prioritizing work, but it is a separate judgment. Control+s records ISO conformity separately from maturity, and each keeps its own human override.