Skip to main content

ISO 27001 Gap Analyzer

ISO 27001 is the international standard for information security management systems (ISMS). This tool helps you identify gaps across information security policies, risk assessment, asset management, access control, incident management, and business continuity to prepare for certification.

Global
24 Questions
6 Categories
Progress: 0/24

Information Security Policies

0/3

Risk Assessment & Treatment

0/4

Asset Management

0/3

Access Control & Cryptography

0/5

Incident Management

0/5

Business Continuity

0/4

Information Security Policies

Assessment of ISMS policy documentation, approval, and review processes.

12 pts

Q1

Do you have a formal Information Security Management System (ISMS) policy approved by top management that defines the scope, objectives, and commitment to continual improvement?

critical
5 pts

Q2

Are your information security policies reviewed at planned intervals (at least annually) or when significant changes occur, and are review records maintained?

high
4 pts

Q3

Have you defined the scope of your ISMS, including the boundaries, interfaces, and dependencies with external parties?

high
3 pts
VertiComply

Build HIPAA-compliant healthcare applications with AI-powered code generation.

Product

Features

Pricing

Tools

Company

About

Blog

Contact

Legal

Privacy

Terms

Compliance

© 2026 VertiComply. All rights reserved.

Built for HIPAA + SOC 2 Type II

About the ISO 27001 Compliance Checker

This gap analyser scores your information security management system against ISO/IEC 27001:2022. The 2022 revision restructured Annex A from 114 controls in 14 domains to 93 controls in four themes — organisational, people, physical and technological — and introduced eleven genuinely new controls including threat intelligence, information security for cloud services, ICT readiness for business continuity, and secure coding. Scoring weights the management system clauses 4 through 10 alongside the Annex A controls, because certification is lost far more often on management system failures — no internal audit programme, no management review, an unmaintained risk treatment plan — than on a missing technical control. Annex A is a reference set to select from, not a checklist to complete: the Statement of Applicability documenting what you included, what you excluded, and why, is the document an auditor opens first.

What this ISO 27001 assessment covers

The 24-question assessment scores 100 points across 6 weighted categories. Each category reflects a distinct ISO 27001 control domain.

Information Security Policies · 12 pts · 3 questions

Assessment of ISMS policy documentation, approval, and review processes.

Risk Assessment & Treatment · 20 pts · 4 questions

Evaluation of risk assessment methodology, treatment plans, and Statement of Applicability.

Asset Management · 14 pts · 3 questions

Assessment of information asset inventory, classification, and disposal practices.

Access Control & Cryptography · 20 pts · 5 questions

Evaluation of access control policies, least privilege, and cryptographic controls.

Incident Management · 18 pts · 5 questions

Assessment of incident response procedures, evidence handling, and lessons learned.

Business Continuity · 16 pts · 4 questions

Evaluation of business impact analysis, continuity plans, and redundancy measures.


Common ISO 27001 compliance gaps

The patterns we see most frequently in ISO 27001 self-assessments and remediation work. Each is the kind of finding an auditor flags first.

The Statement of Applicability is a copy of Annex A with everything marked applicable. A credible SoA justifies inclusion and exclusion against your actual risk assessment. Marking all 93 controls applicable signals that no risk assessment drove the selection.

Risk assessment methodology is undocumented. Clause 6.1.2 requires a defined, repeatable process producing consistent, valid and comparable results. A spreadsheet of risks with no stated method for how likelihood and impact were derived fails this.

Internal audit has never actually run. Clause 9.2 requires internal audits at planned intervals covering the whole ISMS. This is one of the most common Stage 2 findings, and it cannot be remediated quickly because the evidence is a track record.

Management review is informal. Clause 9.3 specifies the inputs and outputs of management review. Discussing security at a leadership meeting is not a management review unless it covers the required agenda and is minuted as such.

The 2022 controls were never gap-assessed. Organisations transitioning from ISO 27001:2013 frequently mapped old controls to new numbering without assessing the eleven new controls — threat intelligence, cloud services security, ICT readiness for business continuity, secure coding, data leakage prevention and the rest.

Scope is drawn too broadly or too vaguely. Scope determines audit effort and certificate value. An imprecise scope statement produces either an unaffordable audit or a certificate that customers correctly read as not covering the product they buy.

Corrective actions are closed without effectiveness review. Clause 10.1 expects you to review whether the action actually eliminated the cause. Closing a nonconformity because a task was completed is not the same thing.


What to do with your ISO 27001 results

Your score is a starting point — these are the steps that convert the assessment into actionable remediation.

Fix the scope statement first. Everything downstream — risk assessment, SoA, audit cost, certificate credibility — depends on it being precise about which services, locations and information assets are covered.

Rebuild the SoA from your risk assessment rather than from Annex A. Each control should trace to a risk it treats, and each exclusion should have a stated justification.

Stand up the internal audit programme now, whatever else is unfinished. It requires elapsed time to produce evidence, so starting it late is the most common cause of a delayed certification.

Run an explicit gap assessment on the eleven controls new in 2022, especially cloud services security and secure coding if you build software.

Schedule the management review with the clause 9.3 agenda and minute it properly. It is low effort and it is checked at every audit.


ISO 27001 compliance FAQ

How long does ISO 27001 certification take?

For an organisation starting without a formal ISMS, typically six to twelve months to Stage 2. The binding constraint is rarely control implementation — it is accumulating evidence that the management system has been operating: a completed internal audit cycle, at least one management review, and a risk treatment plan with a history. Certification then runs on a three-year cycle with annual surveillance audits.

What changed in ISO 27001:2022?

Annex A was restructured from 114 controls across 14 domains into 93 controls across four themes — organisational, people, physical, technological — with eleven new controls including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. The management system clauses saw only minor changes.

Is ISO 27001 equivalent to SOC 2?

No, though they overlap heavily in the controls they expect. ISO 27001 is a certification against a management system standard, issued by an accredited body and internationally recognised. SOC 2 is an attestation report written by a CPA firm against the Trust Services Criteria, and is predominantly a North American expectation. Many organisations pursuing both find the control work largely shared and the reporting requirements entirely separate.

Does ISO 27001 cover HIPAA requirements?

Partially, and not automatically. A well-run ISMS produces much of the technical and organisational evidence the HIPAA Security Rule expects, but HIPAA imposes specific obligations — business associate agreements, the breach notification rule, minimum necessary — that ISO 27001 does not address. Certification is useful evidence in a HIPAA programme, not a substitute for one.

Do we need ISO 27001 if we already have SOC 2?

Only if your customers ask for it. The practical driver is geography and sector: European and international enterprise buyers, and public sector tenders, commonly require ISO 27001, while US buyers more often accept SOC 2 Type II. Since the underlying control work overlaps substantially, adding the second is usually far cheaper than the first was.

Build it instead of buying it

Generate a ISO 27001-compliant healthcare app with the controls built in

VertiComply generates production-ready healthcare applications with ISO 27001 controls scaffolded from the first commit — no add-on tier, no platform lock-in, code exported to your GitHub.

Start free