Key Takeaways
- A gap analysis compares your current security controls against ISO 27001 requirements so you know what’s missing before an auditor finds it for you.
- Most teams find close to a third of controls only partially in place, not fully missing or fully done. That middle zone is where audits usually stall.
- Run the analysis 8 to 12 weeks before your audit date, not the week before.
- Score every control, don’t just check a box. “Partially compliant” and “fully compliant” need different fixes.
- Control mapping across frameworks like SOC 2What is SOC2? and FedRAMP saves real time if you’re chasing more than one certification.
A mid-size SaaS company we’ll call typical spent six weeks building policies for its first ISO 27001 audit. On day one of the actual assessment, the auditor asked for evidence of access reviews going back a full quarter. The company had the policy. It didn’t have the logs. That single gap pushed certification back two months.
This happens more than people expect. Industry benchmarks show a typical mid-size organization enters its first review at roughly 45% fully compliant, 35% partially compliant, and 20% non-compliant. The partially compliant slice is the dangerous one. It looks done from the outside but falls apart the moment someone asks for proof.
Where a typical mid-size org stands on day one
Before remediation, this is how compliance usually breaks down across ISO 27001:2022 clauses and Annex A controls.
Mature programs with an existing SIEM and documented access controls often start closer to 60–70% compliant. Teams building from scratch tend to sit around 30–40%.
What a Gap Analysis Actually Checks
An ISO 27001 gap analysis is a side-by-side comparison. You take what your company does today for information security and hold it up against every requirement in the standard. Wherever the two don’t match, that’s a gap.
The 2022 version of the standard covers two areas:
- Clauses 4 through 10. These are the structural requirements. Leadership commitment, risk assessment, internal audits, and management review all live here.
- Annex A controls. The 2022 version brought the control count to 93, covering people, physical security, technology, and organizational practices.
You’re not just checking whether a policy exists. You’re checking whether it’s actually followed, whether someone can prove it, and whether the proof would survive an auditor asking follow-up questions.
This is also where a lot of teams underestimate the work. A policy document takes an afternoon to write. Getting three months of consistent evidence behind that policy takes three months, not an afternoon. That’s the real reason a gap analysis needs to happen early. It’s not about finding problems. It’s about giving yourself enough runway to actually fix them before the audit clock runs out.
Fully Compliant, Partially Compliant, Non-Compliant
Every finding should land in one of three buckets:
- Fully compliant. The control works and you can show evidence on request.
- Partially compliant. Something exists, but it’s incomplete, undocumented, or inconsistently applied.
- Non-compliant. Nothing is in place. You’re starting from zero on this one.
Sorting gaps this way matters because the fix is different for each. A non-compliant control might need a new policy written from scratch. A partially compliant one might just need six more months of consistent logs.
How to Run the Gap Analysis Before Your Audit
Timing decides whether this exercise actually helps you. Run it too close to the audit and you won’t have room to fix what you find. Here’s the order that works.
How to run the gap analysis, in order
Each step feeds directly into the next — skipping the scope step is where most analyses stall.
Define scope
Identify which systems, teams, and boundaries the analysis will cover.
Review the standard
Work through Clauses 4–10 plus all 93 Annex A controls.
Assemble the team
Security, IT, HR, and legal — with executive sponsorship behind it.
Assess controls
Compare current state against required state, honestly.
Document findings
Mark each control compliant, partial, or non-compliant — with evidence.
Build the remediation plan
Prioritize by risk impact, assign owners, set timelines.
1. Set the Scope 8 to 12 Weeks Out
Pick which business units, systems, and data flows the analysis will cover. A narrow scope moves faster. A scope that’s too broad burns weeks reviewing systems that never touch sensitive data. Most teams that wait until 2 to 3 weeks before the audit end up rushing the scope and missing whole categories of controls.
2. Pull the Standard and Build Your Checklist
Go clause by clause, then control by control, through ISO 27001:2022. For each one, write down what you currently do, not what you plan to do. This is not the place for optimism.
3. Gather Evidence, Not Just Opinions
Ask each control owner for proof. Access review logs, training completion records, incident response tickets, vendor contracts. If someone says “we do that,” the next question is always “show me.”
4. Score Every Control
Use the three-tier system above. Resist the urge to mark something “compliant” because the intent is right. Auditors care about consistency and documentation, not intentions.
5. Build a Prioritized Remediation Plan
Rank gaps by risk and effort. A missing incident response plan is a bigger risk than a slightly outdated org chart. Assign an owner and a deadline to each item, not just a category.
6. Re-Check the High-Risk Items Before the Audit Date
Two weeks out, go back through anything flagged high-risk. Confirm it’s actually fixed, not just assigned to someone.
The Gaps That Show Up Most Often
A few patterns repeat across almost every gap analysis, regardless of company size.
- Access reviews exist on paper but don’t happen on schedule. Teams write the policy, then let quarterly reviews slip to twice a year.
- Incident response plans are never tested. The document exists. Nobody has run a tabletop exercise against it.
- Vendor risk assessments stop after onboarding. New vendors get vetted. Existing ones don’t get re-checked as contracts renew.
- Training records are incomplete. Security awareness training happens, but completion isn’t tracked well enough to prove it during an audit.
- Documentation lives in someone’s head, not a system. The person who knows the process hasn’t written it down anywhere an auditor can see.
None of these are exotic problems. They’re the boring, easy-to-miss gaps that only surface once someone goes looking for evidence instead of just asking “do we do this?”
If you’re pursuing more than one certification, mapping your controls across SOC 2 and ISO 27001 in one pass saves you from re-doing the same evidence-gathering work twice. The overlap between frameworks is bigger than most teams assume. A FedRAMP versus SOC 2 mapping exercise often shows that 60 to 70 percent of control work can be reused across frameworks, which is worth knowing if a federal or enterprise deal is also on your roadmap.
Turn this gap analysis into evidence, automatically
Spreadsheets can run a gap analysis once. Compliance Teammate keeps running it — pulling proof from the systems you already use and keeping every control’s status current, not just accurate on the day you checked.
- ✓ Pulls evidence automatically from your IdP, SIEM, ticketing, and cloud configs
- ✓ Maps controls across ISO 27001, SOC 2, GDPR, and more from one workspace
- ✓ Flags drift the moment a control stops passing, not at next audit
FAQs
How long does an ISO 27001 gap analysis take?
Who should run the gap analysis?
Is a gap analysis the same as a risk assessment?
What happens if we skip the gap analysis and go straight to the audit?
Before Your Next Audit
A gap analysis isn’t a formality you check off before certification. It’s the difference between walking into an audit knowing exactly where you stand and walking in hoping nothing embarrassing comes up. Give yourself 8 to 12 weeks, score honestly, and fix the partially compliant items first. Those are the ones most likely to trip you up.