Get Demo
↑

ISO 27001 Gap Analysis: Template and How to Run One

How to run an ISO 27001 gap analysis: steps, scoring, HTML template sections for findings, and how to turn gaps into a remediation roadmap.

Published: September 2026 Compliance · ISO 27001 10–13 min read

An ISO 27001 gap analysis compares your current security management practices to the requirements of ISO/IEC 27001 for a defined ISMS scope. Done well, it produces a prioritised remediation backlog — not a vanity score. Use the HTML template sections below as a working structure (this is not a downloadable Excel file).

Related: Compliance checklist · Risk assessment · Cost 2026 · ISO 27001 hub · CSA.

Start with scope: Gap findings are meaningless if the boundary is unclear. Lock a draft scope statement before deep control interviews.

How to Run a Gap Analysis

  1. Confirm scope and interested parties — products, sites, cloud accounts, shared services.
  2. Collect artefacts — policies, diagrams, access reviews, incident records, vendor contracts, prior audit reports.
  3. Interview owners — security, IT, HR, legal, product, facilities.
  4. Score clauses and control themes — e.g. Met / Partial / Missing / Not applicable (with justification).
  5. Record evidence references — link each score to a document, ticket, or “none found”.
  6. Prioritise remediation — risk, customer commitments, and audit blockers first.
  7. Brief leadership — effort, budget, and target certification window (as a plan, not a guarantee).

Suggested Scoring Legend

Score
Meaning
Typical next step
Met
Requirement satisfied with recent evidence
Maintain; schedule sampling in internal audit
Partial
Intent exists; gaps in design, coverage, or evidence
Close design gaps; strengthen records
Missing
No credible process or control
Design + implement; assign owner and due date
N/A
Outside scope or not applicable
Document justification for SoA / scope

HTML Template Sections (Copy into Your Tracker)

Use these columns in a sheet or in CSA:

Area
Requirement theme
Score
Evidence / gap
Owner
Target date
Context & scope
Clause 4 themes
Partial
Draft scope; no interested-party register
CISO
2026-10-15
Leadership
Policy & roles
Missing
No signed IS policy
CEO / CISO
2026-10-30
Planning
Risk & SoA
Partial
Risk register outdated
Risk owner
2026-11-15
Support
Competence & awareness
Partial
Annual training incomplete
HR
2026-11-01
Operation
Access / change / suppliers
Partial
Access review ad hoc
IT
2026-11-30
Performance
Internal audit & metrics
Missing
No internal audit programme
Compliance
2026-12-15
Improvement
Nonconformity & CAPA
Missing
No CAPA log
Compliance
2026-12-01

Expand rows for Annex A themes that matter to your scope (organisational, people, physical, technological) without treating a website table as a complete control catalogue.

From Gaps to Roadmap

How CyberSilo Helps

Run a CyberSilo Gap Analysis

We map your current state to ISO 27001 for your scope and hand back a prioritised remediation plan you can fund.

Frequently Asked Questions

Is a gap analysis the same as a certification audit?

No. A gap analysis is a readiness exercise you control. A certification audit is performed by an accredited certification body against the standard and your declared scope.

Do we need to score every Annex A control ID?

You should cover applicable Annex A themes and clause requirements relevant to your scope. Listing every control ID in a blog template is not required; prioritise high-risk and high-effort gaps first.

How long does a typical gap analysis take?

For a mid-sized scope, a typical market estimate is one to four weeks of workshops and evidence review, depending on maturity and document availability. This is a planning range, not a fixed rule.

Checklist · ISMS scope · Internal audit · Policies · ISO 27001 hub · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!