Evaluate

    ISO/IEC 27001 gap analysis

    A clause-by-clause and control-by-control assessment of where you stand against ISO/IEC 27001, and what closing the distance will cost in money, effort and calendar time. It ends in a costed plan you can take to a board — not a maturity score.

    Duration

    3–4 weeks

    Built on

    ISO/IEC 27001:2022 · ISO/IEC 27002:2022

    Indicative price

    €8,500–19,000 per engagement

    Who this is for

    • CISO or security manager

      Has been asked what certification would take and needs a number, not an impression.

    • CFO or managing director

      Is deciding whether to fund a certification programme at all.

    • IT director

      Will absorb most of the remediation work and wants to know how much.

    • Compliance lead

      Needs to know whether this can run alongside the management systems already in place.

    A maturity score is not a plan

    Most gap analyses end in a spider diagram and a number out of five. It looks like an answer and it is not one, because nobody can act on it. A score of 2.7 tells you nothing about what to do on Monday, what it will cost, or whether you can certify this year.

    What you actually need is a finding register: for every clause of the standard and every Annex A control, one of three verdicts — missing, exists but cannot be evidenced, or in place and adequate. The middle category is the one that surprises people, and it is usually the largest. Most organisations are doing far more than they can prove.

    The second thing a gap analysis has to settle is scope, and this is where the money is. Scope is the single biggest lever on cost, timeline and audit effort, and the assessment is the right moment to test the boundary you assumed. We have seen programmes halve in size on the strength of one well-argued exclusion, and others quietly double because a subsidiary was left in without anyone asking why.

    The third is sequence. The gaps are not equal: some are quick documentation work, some need budget and a procurement cycle, and a few have long lead times that will govern your certification date whatever else happens. Knowing which is which in week three, rather than month five, is the difference between a programme that lands and one that slips.

    We deliver the findings as a costed plan with owners and effort estimates, and we tell you plainly whether we think you should proceed. Occasionally the honest answer is not yet.

    How we do it

    1. 01

      Kick-off and scope hypothesis

      2 days

      We agree the boundary we are assessing against, and the commercial reason for certifying — the two are related, and testing the second usually improves the first. We identify the people we need and book them now, because interview availability is the most common cause of slippage.

    2. 02

      Documentation review

      3–5 days

      Everything you already have: policies, procedures, contracts, asset inventories, previous audit reports, incident records. Read before we ask anyone a question, so that interviews are spent on what the documents do not say.

    3. 03

      Interviews

      3–5 days

      Structured sessions across IT, HR, legal, operations and leadership. We are testing whether the documented process and the real process are the same, which is the gap an auditor finds.

    4. 04

      Control assessment

      3–5 days

      Every Annex A control assessed on evidence, not on assertion. Where a control is claimed, we ask to see the artefact that proves it operates.

    5. 05

      Findings workshop

      1 day

      We present the findings to your team before writing the report. Anything we have misunderstood gets corrected here rather than being argued about later.

    6. 06

      Costed plan

      3–5 days

      The report, the remediation plan with effort and cost per gap, the scope recommendation and an indicative certification timeline working back from your target date.

    Named artefacts

    What you receive

    • Finding register — every clause and every Annex A control, with one of three verdicts and the evidence seen
    • Scope recommendation, with the argument for each proposed inclusion and exclusion
    • Costed remediation plan, with effort estimate and owner per gap
    • Sequenced roadmap, with the long-lead items identified
    • Indicative certification timeline, worked back from your target audit date
    • Estimate of certification body fees, so the budget is complete
    • Board summary — two pages, decision-ready

    What we need from you

    • Access to existing documentation before we start, including previous audit reports and anything you consider unfinished.
    • Six to ten people for one hour each, across IT, HR, legal, operations and leadership.
    • Someone with the authority to answer scope questions during the engagement, not afterwards.
    • Your commercial reason for certifying — which client, which tender, which insurer. It genuinely changes what we recommend.

    What changes

    1. 01You know what certification costs before you commit to it.
    2. 02You know whether your assumed scope is the right one, and why.
    3. 03You know which gaps have long lead times and therefore govern your date.
    4. 04You can fund the programme from a plan rather than an estimate.
    5. 05You find out now if the honest answer is that you are not ready.

    What it costs

    €8,500–19,000 per engagement

    All prices exclude VAT.

    Questions

    How is this different from an audit?

    An audit issues a conformity opinion against the standard — it tells you whether you comply. A gap analysis tells you what to do about the fact that you do not yet. Different deliverable, different engagement, and we never present one as the other.

    Can the gap analysis fee be credited against implementation?

    Yes. If you proceed with us within ninety days, the assessment fee is credited against the implementation engagement.

    What if we have already started on our own?

    Then the assessment is usually faster and the report is shorter, because a good deal already exists. What we most often find in that situation is strong technical controls and weak evidence — which is quick to fix once someone names it.

    Will you tell us not to proceed?

    If that is the answer, yes. The common reasons are an unclear commercial driver, a scope nobody will own, or a remediation budget that does not exist. All three are better discovered in week three.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.