Checklists
ISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
- Format
- XLSX
- Size
- 28 KB
- Language
- Indonesian & English
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
In short
An ISO 27001 gap assessment is the initial review measuring the distance between current practice and what the standard requires. Its result determines how long a certification programme takes and what it costs. This checklist scores clauses 4–10 and all 93 Annex A controls on a maturity scale, then summarises them into a priority map.
What This Document Is For
The first question before committing to ISO 27001 is not 'what does it cost' but 'how far are we now'. Two organisations with identical headcount can sit six months apart in readiness, and that difference — not company size — is what sets the budget.
This checklist is designed to be completed without a consultant. Each row asks one concrete question answerable as yes, partial, or not yet, then translates it into a maturity score. The summary shows which areas are already safe and which will take longest, so the decision rests on numbers rather than instinct.
What's Inside
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clauses 4–10 | Every management system requirement that must be met for certification. |
| ISO/IEC 27001:2022 | Annex A (93 controls) | The starting basis for a Statement of Applicability once the risk assessment has run. |
| SNI ISO/IEC 27001:2022 | Identical | Assessment results apply equally to the national and international certification routes. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
How long does this checklist take to complete?
Four to eight hours when completed by people who actually know the organisation — usually a mix of IT, HR, and operations. The time goes not into answering but into getting the people who can answer honestly into one room.
What score means ready for certification?
There is no official threshold. As a practical guide, organisations below 40% readiness usually need four months or more; above 70%, two to three months is typical. More telling than the total is whether clauses 4–10 are handled, because that part cannot be rushed at the end.
Can the result be used as audit evidence?
No. A gap assessment is an internal planning tool, not evidence of conformity. Conformity evidence comes from a running ISMS, internal audits, and management review.
Need guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.