ChecklistsFree

ISO 27001 Gap Assessment Checklist

Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.

In short

An ISO 27001 gap assessment is the initial review measuring the distance between current practice and what the standard requires. Its result determines how long a certification programme takes and what it costs. This checklist scores clauses 4–10 and all 93 Annex A controls on a maturity scale, then summarises them into a priority map.

Format
XLSX
Size
28 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

The first question before committing to ISO 27001 is not 'what does it cost' but 'how far are we now'. Two organisations with identical headcount can sit six months apart in readiness, and that difference — not company size — is what sets the budget.

This checklist is designed to be completed without a consultant. Each row asks one concrete question answerable as yes, partial, or not yet, then translates it into a maturity score. The summary shows which areas are already safe and which will take longest, so the decision rests on numbers rather than instinct.

Most Useful For

  • Organisations deciding whether and when to pursue ISO 27001 certification
  • Teams needing concrete numbers to put a programme budget to management
  • Companies facing a tender deadline who need to know whether that deadline is realistic

What's Inside

01

Clause 4–10 assessment

Readiness questions for context, leadership, planning, support, operation, evaluation, and improvement.

02

93 Annex A control assessment

One row per control with implementation status and notes on evidence already held.

03

Maturity scale

A 0–4 score from absent to measured and reviewed, so progress is comparable between assessment rounds.

04

Automatic summary

Readiness percentages per theme and overall, ready to take into a management meeting.

05

Effort estimate

An estimated-effort column per gap, the basis for programme scheduling and budgeting.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Clauses 4–10Every management system requirement that must be met for certification.
ISO/IEC 27001:2022Annex A (93 controls)The starting basis for a Statement of Applicability once the risk assessment has run.
SNI ISO/IEC 27001:2022IdenticalAssessment results apply equally to the national and international certification routes.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

How long does this checklist take to complete?

Four to eight hours when completed by people who actually know the organisation — usually a mix of IT, HR, and operations. The time goes not into answering but into getting the people who can answer honestly into one room.

What score means ready for certification?

There is no official threshold. As a practical guide, organisations below 40% readiness usually need four months or more; above 70%, two to three months is typical. More telling than the total is whether clauses 4–10 are handled, because that part cannot be rushed at the end.

Can the result be used as audit evidence?

No. A gap assessment is an internal planning tool, not evidence of conformity. Conformity evidence comes from a running ISMS, internal audits, and management review.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.