ISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
In short
An ISO 27001 gap assessment is the initial review measuring the distance between current practice and what the standard requires. Its result determines how long a certification programme takes and what it costs. This checklist scores clauses 4–10 and all 93 Annex A controls on a maturity scale, then summarises them into a priority map.
- Format
- XLSX
- Size
- 28 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
The first question before committing to ISO 27001 is not 'what does it cost' but 'how far are we now'. Two organisations with identical headcount can sit six months apart in readiness, and that difference — not company size — is what sets the budget.
This checklist is designed to be completed without a consultant. Each row asks one concrete question answerable as yes, partial, or not yet, then translates it into a maturity score. The summary shows which areas are already safe and which will take longest, so the decision rests on numbers rather than instinct.
Most Useful For
- Organisations deciding whether and when to pursue ISO 27001 certification
- Teams needing concrete numbers to put a programme budget to management
- Companies facing a tender deadline who need to know whether that deadline is realistic
What's Inside
Clause 4–10 assessment
Readiness questions for context, leadership, planning, support, operation, evaluation, and improvement.
93 Annex A control assessment
One row per control with implementation status and notes on evidence already held.
Maturity scale
A 0–4 score from absent to measured and reviewed, so progress is comparable between assessment rounds.
Automatic summary
Readiness percentages per theme and overall, ready to take into a management meeting.
Effort estimate
An estimated-effort column per gap, the basis for programme scheduling and budgeting.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clauses 4–10 | Every management system requirement that must be met for certification. |
| ISO/IEC 27001:2022 | Annex A (93 controls) | The starting basis for a Statement of Applicability once the risk assessment has run. |
| SNI ISO/IEC 27001:2022 | Identical | Assessment results apply equally to the national and international certification routes. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
How long does this checklist take to complete?
Four to eight hours when completed by people who actually know the organisation — usually a mix of IT, HR, and operations. The time goes not into answering but into getting the people who can answer honestly into one room.
What score means ready for certification?
There is no official threshold. As a practical guide, organisations below 40% readiness usually need four months or more; above 70%, two to three months is typical. More telling than the total is whether clauses 4–10 are handled, because that part cannot be rushed at the end.
Can the result be used as audit evidence?
No. A gap assessment is an internal planning tool, not evidence of conformity. Conformity evidence comes from a running ISMS, internal audits, and management review.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
ISO 27001 Internal Audit Checklist
A complete ISMS internal audit guide with verification points for every clause and control.
Free DownloadPDP Law Compliance Checklist
A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).
Free DownloadPenetration Test Preparation Checklist
Prepare for a pentest the right way: asset scoping, test accounts, testing windows, PICs, and legal aspects — so testing runs smoothly from day one.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.