What a defensible gap analysis covers
ISO/IEC 27001:2022 has two halves: the management-system clauses (4 through 10) and Annex A — 93 controls grouped under Organisational, People, Physical and Technological. A gap analysis that only walks Annex A misses half the certification scope and is the single most common reason organisations fail their stage-1 audit.
The five-step structure
Gap analysis sequence
- Scope & ISMS context. Define the scope statement, interested parties (clause 4) and the boundary that the certification body will audit.
- Management-system review (clauses 4–10). Leadership, planning, support, operations, performance evaluation, improvement — score each clause against documented evidence.
- Annex A control coverage. Walk the 93 controls grouped by Organisational, People, Physical and Technological. Mark implemented, partial, planned or not applicable with rationale.
- Risk treatment & SoA delta. Reconcile gaps to your risk register, update the Statement of Applicability and identify treatments needed before stage-1 audit.
- Remediation roadmap. Prioritised plan ordered by risk-reduction, effort and dependency. Most organisations need 3–6 months between gap analysis and stage-1.
Mapping to the 2022 control changes
ISO 27001:2022 reduced Annex A controls from 114 to 93 and introduced 11 new controls — including 8.23 Web Filtering, 8.28 Secure Coding, 5.7 Threat Intelligence and 5.23 Information Security for Cloud Services. If your last gap analysis predates 2022 you are walking the wrong control set; certification bodies are no longer accepting 2013-aligned SoAs.
Evidence the auditor actually asks for
- Approved ISMS scope statement with boundaries and exclusions
- Information security policy approved by top management within the last 12 months
- Risk assessment methodology, current risk register and risk treatment plan
- Statement of Applicability with justification for every Annex A control
- Internal audit programme covering all clauses across the certification cycle
- Management review minutes with decisions, actions and improvements
SHORTCUT FOR ISMS OWNERS
Generate your ISO 27001 policy pack in one mission.
FORTE/CYBERx produces a 50+ page ISO 27001:2022 policy pack with editable sections, version control and an export-ready Statement of Applicability — anchored to the 93 Annex A controls and the management-system clauses.
Try the Policy Pack WizardAnti-patterns we see
- Annex A-only assessments. Skipping clauses 4–10 fails certification before you start.
- Mark-all-implemented. Over-claiming coverage creates worse non-conformities at audit than honest gaps.
- No risk linkage. Gaps that do not feed the risk register and SoA are theatre.
- One-shot remediation. Treat gap closure as a programme with weekly cadence, not a one-week sprint.
FAQ
What is an ISO 27001 gap analysis?
A gap analysis is a structured comparison of your current information security controls against the requirements of ISO/IEC 27001:2022 — both the management-system clauses (4–10) and the 93 Annex A controls. It produces a list of gaps, the risk each gap represents, and a prioritised remediation plan.
How long does a gap analysis take?
For an Australian mid-market organisation, plan for 2–4 weeks elapsed. Most of the time is spent collecting evidence, not assessing it. Using a structured template and AI decision support typically halves the elapsed time.
Do we need a gap analysis if we already have SOC 2?
Yes. SOC 2 Trust Services Criteria overlap with about 60% of ISO 27001 Annex A, but the management-system clauses, statement of applicability and risk treatment plan are unique to ISO 27001. A gap analysis surfaces those deltas.
Should we run the gap analysis ourselves or hire a consultant?
Either is defensible. Internal teams using a structured template often produce a sharper result because they know the operating reality. Consultants add weight for the audit committee. Many of our customers run the assessment in-platform and bring a consultant in for the validation pass only.