Organisations pursuing ISO 27001 certification frequently underestimate the distance between where they are and where they need to be. A gap assessment is the tool that makes that distance visible before you commit to a certification timeline and budget. This article explains what a gap assessment covers, how it differs from a formal audit, and how to use the output to plan realistically.
What a gap assessment measures ¶
A gap assessment compares your current information security controls against the requirements of ISO 27001:2022, specifically the 93 controls in Annex A the clauses of the main standard. For each control, the assessor determines whether the control is fully implemented, partially implemented, or absent. The output is a gap register: a list of controls with a status, a risk rating, and a recommended remediation action. This is not a pass or fail document. It is a planning tool.
How it differs from a certification audit ¶
A certification audit is conducted by an accredited certification body and results in a formal decision: certified or not certified. A gap assessment is conducted before that process begins, by a consultant rather than a certification body, and has no formal standing. Its purpose is to surface the gaps that would cause a failed audit so you can address them first. Organisations that go into a certification audit without a prior gap assessment frequently discover expensive surprises during the audit itself.
What the remediation roadmap should look like ¶
A useful remediation roadmap groups the gaps by effort and risk. Quick wins, controls that can be implemented in a day or two with existing resources, should be separated from structural changes that require policy development, tool procurement, or organisational change. The roadmap should include a realistic time estimate for each item and an honest assessment of whether internal resource is sufficient or whether external support is needed. A roadmap that says everything is high priority is not a roadmap.
When to commission a gap assessment ¶
The right time is 12 to 18 months before your target certification date. This gives you time to address the gaps, embed the controls, and generate the evidence of operation that a certification audit will require. Commissioning a gap assessment six weeks before your audit is possible but leaves very little room to address anything structural. If your organisation is being asked by a customer to achieve certification within a specific timeframe, start the gap assessment as soon as that conversation happens.
What a gap assessment costs and what it does not cover ¶
A gap assessment for a 50-person organisation typically takes two to three days of consultant time and costs between £1,800 and £3,500 depending on the complexity of your environment and the number of sites. It does not include the implementation of the controls, the development of policies, or the certification audit itself. Those are separate costs. A good gap assessment will give you a realistic estimate of what the full certification journey will cost so you can budget accurately.
Swift Vaultgate's ISO 27001 gap assessment includes a prioritised gap register, a remediation roadmap, and three months of email support during your implementation phase. Details are on our engagement packages page.