Press TechRound interviews Secure.com CEO on the future of AI security
Read

How to Run an ISO 27001 Gap Analysis Before Your Audit

Learn how to run an ISO 27001 gap analysis before your next audit, spot compliance gaps early, and build a plan to fix them before the auditor does.

Key Takeaways

  • A gap analysis compares your current security controls against ISO 27001 requirements so you know what’s missing before an auditor finds it for you.
  • Most teams find close to a third of controls only partially in place, not fully missing or fully done. That middle zone is where audits usually stall.
  • Run the analysis 8 to 12 weeks before your audit date, not the week before.
  • Score every control, don’t just check a box. “Partially compliant” and “fully compliant” need different fixes.
  • Control mapping across frameworks like SOC 2What is SOC2? and FedRAMP saves real time if you’re chasing more than one certification.

A mid-size SaaS company we’ll call typical spent six weeks building policies for its first ISO 27001 audit. On day one of the actual assessment, the auditor asked for evidence of access reviews going back a full quarter. The company had the policy. It didn’t have the logs. That single gap pushed certification back two months.

This happens more than people expect. Industry benchmarks show a typical mid-size organization enters its first review at roughly 45% fully compliant, 35% partially compliant, and 20% non-compliant. The partially compliant slice is the dangerous one. It looks done from the outside but falls apart the moment someone asks for proof.

Benchmark data

Where a typical mid-size org stands on day one

Before remediation, this is how compliance usually breaks down across ISO 27001:2022 clauses and Annex A controls.

45% Fully compliant Controls in place and working as required.
35% Partially compliant Something exists, but it’s undocumented or incomplete.
20% Non-compliant Nothing in place — needs to be built from scratch.

Mature programs with an existing SIEM and documented access controls often start closer to 60–70% compliant. Teams building from scratch tend to sit around 30–40%.

What a Gap Analysis Actually Checks

An ISO 27001 gap analysis is a side-by-side comparison. You take what your company does today for information security and hold it up against every requirement in the standard. Wherever the two don’t match, that’s a gap.

The 2022 version of the standard covers two areas:

  • Clauses 4 through 10. These are the structural requirements. Leadership commitment, risk assessment, internal audits, and management review all live here.
  • Annex A controls. The 2022 version brought the control count to 93, covering people, physical security, technology, and organizational practices.

You’re not just checking whether a policy exists. You’re checking whether it’s actually followed, whether someone can prove it, and whether the proof would survive an auditor asking follow-up questions.

This is also where a lot of teams underestimate the work. A policy document takes an afternoon to write. Getting three months of consistent evidence behind that policy takes three months, not an afternoon. That’s the real reason a gap analysis needs to happen early. It’s not about finding problems. It’s about giving yourself enough runway to actually fix them before the audit clock runs out.

Fully Compliant, Partially Compliant, Non-Compliant

Every finding should land in one of three buckets:

  • Fully compliant. The control works and you can show evidence on request.
  • Partially compliant. Something exists, but it’s incomplete, undocumented, or inconsistently applied.
  • Non-compliant. Nothing is in place. You’re starting from zero on this one.

Sorting gaps this way matters because the fix is different for each. A non-compliant control might need a new policy written from scratch. A partially compliant one might just need six more months of consistent logs.

How to Run the Gap Analysis Before Your Audit

Timing decides whether this exercise actually helps you. Run it too close to the audit and you won’t have room to fix what you find. Here’s the order that works.

The 6-step sequence

How to run the gap analysis, in order

Each step feeds directly into the next — skipping the scope step is where most analyses stall.

01

Define scope

Identify which systems, teams, and boundaries the analysis will cover.

02

Review the standard

Work through Clauses 4–10 plus all 93 Annex A controls.

03

Assemble the team

Security, IT, HR, and legal — with executive sponsorship behind it.

04

Assess controls

Compare current state against required state, honestly.

05

Document findings

Mark each control compliant, partial, or non-compliant — with evidence.

06

Build the remediation plan

Prioritize by risk impact, assign owners, set timelines.

1. Set the Scope 8 to 12 Weeks Out

Pick which business units, systems, and data flows the analysis will cover. A narrow scope moves faster. A scope that’s too broad burns weeks reviewing systems that never touch sensitive data. Most teams that wait until 2 to 3 weeks before the audit end up rushing the scope and missing whole categories of controls.

2. Pull the Standard and Build Your Checklist

Go clause by clause, then control by control, through ISO 27001:2022. For each one, write down what you currently do, not what you plan to do. This is not the place for optimism.

3. Gather Evidence, Not Just Opinions

Ask each control owner for proof. Access review logs, training completion records, incident response tickets, vendor contracts. If someone says “we do that,” the next question is always “show me.”

4. Score Every Control

Use the three-tier system above. Resist the urge to mark something “compliant” because the intent is right. Auditors care about consistency and documentation, not intentions.

5. Build a Prioritized Remediation Plan

Rank gaps by risk and effort. A missing incident response plan is a bigger risk than a slightly outdated org chart. Assign an owner and a deadline to each item, not just a category.

6. Re-Check the High-Risk Items Before the Audit Date

Two weeks out, go back through anything flagged high-risk. Confirm it’s actually fixed, not just assigned to someone.

The Gaps That Show Up Most Often

A few patterns repeat across almost every gap analysis, regardless of company size.

  • Access reviews exist on paper but don’t happen on schedule. Teams write the policy, then let quarterly reviews slip to twice a year.
  • Incident response plans are never tested. The document exists. Nobody has run a tabletop exercise against it.
  • Vendor risk assessments stop after onboarding. New vendors get vetted. Existing ones don’t get re-checked as contracts renew.
  • Training records are incomplete. Security awareness training happens, but completion isn’t tracked well enough to prove it during an audit.
  • Documentation lives in someone’s head, not a system. The person who knows the process hasn’t written it down anywhere an auditor can see.

None of these are exotic problems. They’re the boring, easy-to-miss gaps that only surface once someone goes looking for evidence instead of just asking “do we do this?”

If you’re pursuing more than one certification, mapping your controls across SOC 2 and ISO 27001 in one pass saves you from re-doing the same evidence-gathering work twice. The overlap between frameworks is bigger than most teams assume. A FedRAMP versus SOC 2 mapping exercise often shows that 60 to 70 percent of control work can be reused across frameworks, which is worth knowing if a federal or enterprise deal is also on your roadmap.

Secure.com · Compliance Teammate

Turn this gap analysis into evidence, automatically

Spreadsheets can run a gap analysis once. Compliance Teammate keeps running it — pulling proof from the systems you already use and keeping every control’s status current, not just accurate on the day you checked.

  • Pulls evidence automatically from your IdP, SIEM, ticketing, and cloud configs
  • Maps controls across ISO 27001, SOC 2, GDPR, and more from one workspace
  • Flags drift the moment a control stops passing, not at next audit
Meet the Compliance Teammate
Live evidence log
A.5.15 Access control Synced
A.8.16 Monitoring Synced
A.5.23 Cloud security Synced
A.5.36 Policy review Synced

FAQs

How long does an ISO 27001 gap analysis take?
It depends on company size and scope, but most teams need two to four weeks for a thorough review. Rushing it in a few days usually means missed controls.
Who should run the gap analysis?
Internal security or compliance staff can run it if they know the standard well. Many companies bring in outside consultants for a first pass since an outside view tends to catch things internal teams have gotten used to overlooking. Either way, whoever runs it needs the authority to ask control owners hard questions and push back on vague answers.
Is a gap analysis the same as a risk assessment?
No. A gap analysis compares your practices against ISO 27001 requirements. A risk assessment looks at threats to your specific business and how likely they are to cause harm. ISO 27001 requires both, and they usually happen close together.
What happens if we skip the gap analysis and go straight to the audit?
You can, but you’re taking a real risk. Auditors will find the same gaps a self-review would have caught, except now they show up on your official report and can delay certification by months.

Before Your Next Audit

A gap analysis isn’t a formality you check off before certification. It’s the difference between walking into an audit knowing exactly where you stand and walking in hoping nothing embarrassing comes up. Give yourself 8 to 12 weeks, score honestly, and fix the partially compliant items first. Those are the ones most likely to trip you up.