Govern & Assure
ISO 27001 Gap Analysis & Readiness
Measure your ISMS against ISO 27001 as it stands today, and get a prioritised route to certification with a date you can commit to.
- Assessed by lead auditors
- Clauses and controls both
- A prioritised implementation plan
- A certification date you can commit to
Most organisations already do more information security than they get credit for. A gap analysis separates what you have from what the standard requires you to demonstrate, so the implementation plan covers the distance between them and nothing more.
We assess against both halves of ISO 27001: the management system clauses that auditors fail organisations on most often (context, leadership, planning, risk treatment, internal audit, management review) and the Annex A controls your Statement of Applicability brings into play.
Get a quote for ISO 27001 Gap Analysis & Readiness
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
How it works
- 01
Confirm scope and applicability
We take the ISMS scope and establish which Annex A controls it brings into play.
- 02
Review the management system
We assess context, leadership, risk management, competence, internal audit, and management review against clauses 4 to 10.
- 03
Review the controls
We test the Annex A controls in your Statement of Applicability against the evidence behind them.
- 04
Report and prioritise
You receive findings and a prioritised implementation plan, walked through with the people who own the work.
- 05
Plan to certification
We set the route and timeline to Stage 1 and Stage 2, including how long the ISMS needs to be running first.
From findings to a certification date
The output is an implementation plan, not a list of deficiencies. Each gap carries what the standard expects, what would satisfy an auditor, an effort estimate, and a priority, grouped so the work can be assigned to the people who will actually do it.
From that plan we set out a realistic certification timeline: what must be in place before Stage 1, what needs evidence of operation before Stage 2, and how long the management system has to be running before it can credibly be audited.
What you get
Assessed by lead auditors
Reviewed by certified lead implementers and auditors who know where certification bodies actually raise nonconformities.
Clauses and controls both
The management system requirements and the Annex A controls, because certification is lost on clause 9 and 10 more often than on technical controls.
A prioritised implementation plan
Every gap with expected evidence, effort, and priority, sequenced into an order that works.
A certification date you can commit to
What has to be true before Stage 1 and Stage 2, and how much operating history the audit will expect to see.
Frequently asked questions
Straight answers to what prospective clients ask us most.
How long before we can certify?
For an organisation starting from good practice but no formal ISMS, six to nine months is typical, largely because auditors expect to see the management system operating, not just documented.
Do we need to implement every Annex A control?
No. You need to consider every control and justify what you exclude in the Statement of Applicability. The gap analysis establishes which are genuinely applicable to your scope.
We are already certified to something else. Does that count?
Often, substantially. Existing PCI DSS, Cyber Essentials, or SOC 2 work usually covers a meaningful share of Annex A, and we map what carries across rather than starting again.
Related services
Ready to talk about iso 27001 gap analysis & readiness?
Get a fixed-scope quote, usually the same working day.