ISO 27001
ISO 27001 Gap Assessment
A gap assessment exists to answer two questions: how far is the organisation from a certifiable ISMS, and what is the shortest credible path there. It is not an audit and it does not produce a pass mark. It produces a register of what is missing, ordered by what blocks certification and what merely improves it — which are different, and conflating them is how implementation programmes lose a year.
Methodology
- 01
Discover
Business interviews, ISMS scope, interested parties, locations, processes, information assets and existing governance. Primary output: scope baseline + stakeholder map.
- 02
Assess
Gap assessment, risk context, current controls, evidence review and maturity observations. Primary output: gap register + risk inputs.
- 03
Control applicability review
Each Annex A control assessed for applicability against the scope and risk context, with the reasoning recorded — because the Statement of Applicability will need it and reconstructing it later is harder than capturing it now.
- 04
Evidence review
Existing policies, registers, records and audit reports examined for what already demonstrates control operation. Most organisations have more usable evidence than they think, and duplicating it is the most common waste in an ISMS programme.
- 05
Maturity observation
How consistently existing practice actually operates, as distinct from what the documentation claims. A documented process nobody follows is a finding, not a control.
- 06
Roadmap and prioritisation
Gaps sequenced by certification impact, dependency and effort, with an honest view of what can be achieved before a target audit date.
Approach to testing
- Assessed against Clauses 4–10 as well as Annex A. Organisations routinely prepare the controls and fail on the management system clauses, which is where certification audits actually go wrong.
- Blocking gaps are separated from improvement gaps. Treating them as one list is how a programme spends six months on control hardening and arrives at the audit without a risk methodology.
- Existing evidence is credited. The objective is a certifiable ISMS, not a new document set, and CSS's own position is that the deliverable is not a folder of ISO documents.
- Maturity is assessed by asking the people who operate the control, not by reading the procedure. The gap between the two is usually the finding.
- The roadmap states what is achievable before the target date and what is not. A plan that assumes unlimited capacity is a plan the client will abandon in month three.
Types of assessment
Full gap assessment (default)
Clauses 4–10 and all applicable Annex A controls, with evidence review and maturity observation.
Clause-only assessment
Management system clauses alone. Appropriate where controls are strong but governance is informal — a common pattern in technology businesses.
Pre-certification readiness check
A narrower assessment close to a scheduled audit, focused on whether the organisation would pass rather than on what could be better.
Multi-site or group assessment
Where scope covers several entities or locations, including whether one ISMS or several is the right structure.
Frameworks and standards
- ISO/IEC 27001:2022
- The requirements standard — Clauses 4 to 10 and Annex A. This is what certification is against.
- ISO/IEC 27002:2022
- Control implementation guidance. Not a certification standard, and CSS's statement is explicit on that distinction.
- ISO/IEC 27005
- Risk management guidance, where the client's risk methodology is in scope.
- CSS GRC lifecycle
- Discover, Assess, Design, Build, Operate, Assure, Improve — the sequence the wider engagement would follow.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS gap register
Structured recording of each requirement, current state, gap, owner and priority.
Evidence map
Linking existing artefacts to the requirements they already satisfy, to avoid duplication.
PlyoGRC workspace
Where engaged, the gap register and evidence map are maintained as controlled records rather than as a spreadsheet that goes stale.
Structured interviews
With IT, HR, Legal, Privacy, Procurement, Facilities, Engineering and business owners — the assessment is conversational before it is documentary.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Context and scope (Clause 4)
- Internal and external issues identified
- Interested parties and their requirements
- ISMS scope defined and defensible
- Boundaries and interfaces with excluded areas
Leadership (Clause 5)
- Information security policy, and whether leadership can articulate it
- Roles, responsibilities and authorities assigned
- Evidence of management commitment beyond a signature
- Resourcing adequate to the stated scope
Planning (Clause 6)
- Risk assessment methodology documented and repeatable
- Risk register populated and current
- Risk treatment plan with owners and dates
- Statement of Applicability with justification for inclusions and exclusions
- Information security objectives, measurable
Support and operation (Clauses 7–8)
- Competence, awareness and training records
- Documented information control
- Operational planning and control evidence
- Risk assessment performed at planned intervals
Evaluation and improvement (Clauses 9–10)
- Monitoring and measurement, with actual results
- Internal audit programme and completed audits
- Management review with recorded decisions
- Nonconformity and corrective action records
- Evidence of continual improvement
Annex A controls
- Organisational controls: governance, policies, supplier, incident, continuity
- People controls: screening, terms, awareness, disciplinary, remote working
- Physical controls: secure areas, equipment, clear desk, physical access
- Technological controls: identity, endpoint, network, secure development, logging, backup, vulnerability management
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Evidence mapping across hundreds of existing artefacts against 93 Annex A controls plus the management clauses is systematic comparison, and doing it by sampling is how organisations rebuild documents they already had.
Cross-referencing what policies claim against what operational records actually show surfaces the controls that exist on paper only.
Dependency analysis across the gap register determines the real critical path to certification, which is rarely the order people would choose intuitively.
Consistency checking across multiple sites or entities finds where one location's practice diverges from the documented standard.
Every gap and every maturity judgement is made by a human consultant. Agents map evidence and check consistency; whether a control genuinely operates is established by asking the people who run it, and that is not delegated.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Blocking gaps separated from improvements
Two lists, not one. What prevents certification and what merely improves posture are different problems with different urgency, and merging them is the most common reason implementation programmes overrun.
Existing evidence credited
CSS's stated position is that the deliverable is not a folder of ISO documents. The assessment looks for what already works before proposing anything new.
Clauses as well as controls
Most gap assessments concentrate on Annex A because it is concrete. Certification audits fail on Clauses 4–10, and this assessment weights them accordingly.
An honest roadmap
The plan states what is achievable before the target audit date and what is not, rather than assuming capacity the client does not have.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Prioritised gap register: requirement, current state, gap, owner, effort, certification impact
- Evidence map linking existing artefacts to the requirements they already satisfy
- Maturity observations per control area
- Implementation roadmap sequenced by dependency and target audit date
- Distance from certification, stated as blocking gaps rather than a percentage
- Realistic timeline to audit readiness, with the constraint named
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
An EdTech platform with security practices already in place, seeking a structured view of its ISO 27001 position and of what certification readiness would require.
- Finding
- Controls were operating, but had never been mapped against ISO 27001:2022 clauses and Annex A in one place — so documentation gaps and evidence gaps blurred into implementation gaps. Documentation was spread across multiple locations, control ownership was interpreted differently across teams, and there were more findings than could be sequenced against the resources available.
- Recommendation
- Review the ISMS scope and context alongside the existing policies, procedures and records; assess ISO 27001:2022 clauses and Annex A controls against current organisational practice; hold stakeholder discussions to confirm which controls were operating and where evidence existed; and score maturity by control domain, sequencing remediation by risk, ownership and effort.
- Outcome
- Every gap classified by type — documentation, evidence, ownership or implementation — so remediation effort matched the actual shortfall rather than the finding count. Delivered as a gap assessment report, a clause and control assessment, a risk and gap register, a maturity and readiness view and a remediation roadmap. The organisation's chief executive noted the thoroughness of the assessment of their information security posture.
Large BFSI organisation — published in CyberSmithSECURE's own capability statement as a representative case.
- Finding
- A compliance mandate for ISO 27001, with financial information, intellectual property and employee details entrusted to third parties, and a need to align security practice with business strategy rather than run it separately.
- Recommendation
- Information gathering through OSINT, network mapping, vulnerability identification and prioritisation, with ethical-hacking-led assurance used as part of the broader security programme rather than as a separate exercise.
- Outcome
- ISO 27001 compliance achieved, with stronger alignment between security practices and business strategy. CSS's own GRC lesson from the engagement: certification is most valuable when risk, control implementation and business objectives reinforce one another.
Large BPO — published in CyberSmithSECURE's own capability statement as a representative case.
- Finding
- PCI-DSS non-compliance, limited top-management visibility into IT security layers, and a need to make security and compliance stronger customer-acquisition enablers rather than cost centres.
- Recommendation
- OSINT, network mapping, scanning and enumeration, vulnerability identification, exploitation and auditing, delivered as one programme intervention.
- Outcome
- Improved PCI-DSS compliance posture and improved customer-acquisition capability. CSS's stated lesson: security controls become commercially useful when leadership can connect them to customer trust, contractual requirements and operational risk.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.