Business Key Consult logo
Business Key Consult
Services / ISO 27001 gap assessment
ISO/IEC 27001:2022ISO 19011Risk-based

ISO/IEC 27001:2022 gap assessment

Get an independent view of your current state against ISO/IEC 27001:2022 before investing time in certification readiness or an internal audit.

What the gap assessment includes

Scope and context

We review the ISMS scope, interested parties, key processes, and the actual technology environment.

Requirements and evidence

We compare available policies, records, and practices with applicable requirements and controls.

Risk-based priorities

We sequence gaps by risk, dependency, and effort instead of delivering a generic checklist.

Next-step plan

You receive a practical plan for owners, sequencing, and preparation for an internal or certification audit.

When it is useful

  • before starting or restarting an ISO/IEC 27001 programme
  • before a certification or surveillance audit
  • after changes in scope, cloud environment, suppliers, or key processes
  • when leadership needs evidence-based priorities and a realistic plan

Your result

A structured report with observations, evidence, priority assessment, and recommended actions. A gap assessment is not a certification audit and does not replace a formal internal audit; it provides a clear basis for preparing one.

Frequently asked questions

What is the difference between a gap assessment and an internal audit?

A gap assessment evaluates the current state and sequences the route to readiness. An internal audit tests conformity and effectiveness of the implemented system against an audit plan and criteria.

Can the assessment be performed remotely?

Yes. For a suitable scope, document and evidence review as well as interviews can be conducted remotely.

What is needed for an initial assessment?

Send your objective, scope, number of locations and employees, implementation status, and preferred timeline. We will return clarifying questions and a proposed approach.