The Art of CTO ISO 27001 Gap Analysis is a free readiness questionnaire covering 51 of the 93 Annex A controls in ISO 27001:2022, across all four control themes. Each control is marked fully implemented, partially implemented, missing or not applicable, producing a weighted readiness score per domain and a prioritised gap list. It is a gap analysis, not a Statement of Applicability or a certification audit.
How far are we from ISO 27001?
A gap analysis across the Annex A controls with a certification path.
About 20 min · Assessment · Free
About this toolWhy it matters, common mistakes, FAQ
How Far Are You From ISO 27001, In Practice?
ISO 27001 certification is increasingly a procurement gate in Europe, and the gap between 'we have good security' and 'we have an ISMS' is usually nine to twelve months of work. Knowing which it is changes what you can promise a prospect this quarter.
Teams jump to the Annex A controls and skip the management system — scope, risk methodology, Statement of Applicability, internal audit, management review. The controls are the visible part; the ISMS is what is actually being certified.
Questions CTOs ask
- What is an ISO 27001 gap analysis?
- An ISO 27001 gap analysis compares your current information security practices against the requirements of the ISO 27001:2022 standard, including its 93 Annex A controls organized across organizational, people, physical, and technological themes. It identifies which controls are fully implemented, partially implemented, or missing entirely, and the results create a prioritized remediation roadmap for achieving certification. This tool covers 51 of those 93 controls — the ones that most often decide whether a first certification audit goes well — so use it to size the work, then build a full Statement of Applicability with your auditor.
- How long does ISO 27001 certification take?
- Most organizations achieve ISO 27001 certification in 6-18 months depending on their starting maturity. The process includes gap analysis (2-4 weeks), ISMS design and policy creation (2-3 months), control implementation (3-6 months), internal audit (2-4 weeks), management review, and the external certification audit (Stage 1 and Stage 2). Companies with existing SOC 2 or similar frameworks can often accelerate this to 6-9 months due to overlapping controls.
Related Reading
ISO 27001 Gap Analysis Tool Guide: Turn Annex A into a 90-Day Readiness Plan
ISO 27001 gap analysis tool guide for ISO 27001:2022 certification preparation
guidesNIST Cybersecurity Framework Assessment: A CTO Companion Guide to CSF 2.0 Gap Analysis
NIST cybersecurity framework assessment: a CTO companion guide to CSF 2.0 gap analysis
guidesPCI DSS compliance checklist for startups: a companion guide to the PCI DSS Checker
PCI DSS compliance checklist for startups: a companion guide to the PCI DSS Checker