Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free ISO 27001 Gap Assessment:
See How Close You Are to Certification-Ready

ISO/IEC 27001:2022 Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive ISO 27001 gap assessment below to see where your company actually stands against the 2022 revision, the only version a certification body audits against now that ISO 27001:2013 certificates fully sunset on October 31, 2025.

    Answer 9 quick questions across the ISMS management clauses and the 4 Annex A control themes, and get your readiness score in about 2 minutes: your risk level, a rough certification timeline and cost range, the specific gaps to close, and a printable checklist you can hand to your team, IT provider, or compliance consultant.

    No sign-up to see your result.

    What ISO 27001 Actually Requires (the short version)

    ISO/IEC 27001:2022 has two parts. Clauses 4 through 10 are the management-system requirements, the ISMS itself, and they’re commonly grouped into four stages of a plan-do-check-act cycle:

    • Plan

      Understand your context, get leadership committed, run a risk assessment and treatment plan

    • Do

      Put the resources, competence, and controls in place and operate them

    • Check

      Internal audit and management review to confirm the system is actually working, not just written down

    • Act

      Fix what the audit and review turn up

    Annex A is the control catalog: 93 controls grouped into 4 themes, Organizational (37 controls total), People (8 controls total), Physical (14 controls total), and Technological (34 controls total). You don’t have to implement all 93. Your Statement of Applicability (SoA) documents which ones apply to your business and justifies excluding the rest, and that one document is exactly where most small and mid-size companies get stuck.

    The checklist below is organized around those requirements.

    The Full ISO 27001 Gap-Assessment Checklist

    Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a reviewer can’t either.

    • 1. Risk Assessment and Treatment (Plan):

      ✓ A documented information security risk assessment identifying your critical assets and the risks to them, reviewed in the last 12 months.

      ✓ A risk treatment plan that tracks each identified risk through to a decision (accept, reduce, transfer, or avoid).

    • 2. Statement of Applicability and Annex A Scoping:

      ✓ A Statement of Applicability (SoA) listing all 93 Annex A controls, marked applicable or excluded.

      ✓ A specific, documented justification for every control you exclude, not just a blanket “not applicable.”

    • 3. Leadership and Policy:

      ✓ A written information security policy formally approved by senior leadership.

      ✓ Clearly assigned ownership of information security day to day.

    • 4. Organizational Controls (37 of the 93 total):

      ✓ A documented inventory of information assets, systems, and devices, classified by sensitivity.

      ✓ Vendor and subcontractor security review (a questionnaire or contract clause) before granting them access to your systems or data.

      ✓ Documented policies for acceptable use, access control, and incident management.

    • 5. People Controls (8 of the 93 total):

      ✓ Annual information security awareness training for all staff, with signed or logged completion records.

      ✓ Background screening for roles with access to sensitive systems or data.

      ✓ A documented disciplinary process for security-policy violations.

    • 6. Physical Controls (14 of the 93 total):

      ✓ Physical access controls (locked doors, visitor logs) for any area housing servers or sensitive records.

      ✓ Encryption on laptops and devices that leave the office.

      ✓ Secure disposal procedures for hardware and media before reuse or disposal.

    • 7. Technological Controls (34 of the 93 total):

      ✓ Multi-factor authentication (MFA) required on systems holding sensitive data.

      ✓ Access granted on a need-to-know, least-privilege basis.

      ✓ Encryption in transit and at rest, and logging/monitoring of access to sensitive systems.

      ✓ Tested backups and a documented business-continuity plan.

    • 8. Internal Audit and Management Review (Check/Act):

      ✓ A completed internal audit of the ISMS within the last 12 months.


      ✓ A documented management review of the audit findings, with tracked corrective actions.

    • 9. The Certification Process Itself:

      ✓ Stage 1 audit: the certification body reviews your documentation (policy, risk assessment, SoA) for completeness.

      ✓ Stage 2 audit: the certification body tests whether your controls are actually operating as documented.

      ✓ Surveillance audits in years 1 and 2 after certification, then a recertification audit in year 3.

    How to read your gaps?

    • 0 – 2 Gaps and None in Risk Assessment

      Strong Shape. Companies here are often certification-ready in 3-4 months

    • 3 – 6 Gaps or 1 Critical Gap

      Real, findable issues that would draw findings in a Stage 1 audit, and a realistic timeline runs closer to 6-9 months.

    • 7+ Gaps or 2+ Critical Gaps

      Means you’d likely fail Stage 1 today, and the build-out realistically runs 9-12+ months

    Across all three bands, first-year certification costs for a small or mid-size company (gap analysis, consultant time if you use one, and the certification body’s audit fees combined) typically run in the $15,000-$50,000 range, with the low end reflecting a lean, mostly self-managed build and the high end reflecting a consultant-led project or a more complex environment.

    Most of the technical items above (MFA, encryption, access logging, tested backups) live in your IT setup, not a policy binder, which is the half of the ISMS a managed IT and cybersecurity partner operates for you.

    ISO 27001 Gap-Assessment FAQ

    What is ISO 27001 and do we actually need it?

    ISO/IEC 27001 is the international standard for an information security management system (ISMS): a structured, documented program for identifying and managing information security risk. Certification is voluntary, but it’s increasingly a prerequisite in enterprise RFPs and vendor security reviews, especially for manufacturing, finance/accounting, and professional-services firms selling to larger customers. If you’re repeatedly losing deals to an “ISO 27001 required” line item, that’s usually the real trigger, more than a general sense you “should” be compliant.

    What happened to ISO 27001:2013? Why does everything say “2022” now?

    As of October 31, 2025, ISO 27001:2013 certificates are no longer valid. The International Accreditation Forum set a firm transition deadline requiring all certified organizations to move to the 2022 revision, and certification bodies now audit exclusively against ISO/IEC 27001:2022. If your company (or a vendor you rely on) is still citing a 2013 certificate, treat that as expired, not current.

    Which Annex A controls actually apply to a small or mid-size company?

    There’s no fixed subset that applies to every small business, that’s exactly what your Statement of Applicability is for: it documents which of the 93 controls fit your actual risk profile and operations, and justifies excluding the rest. In practice, smaller companies with simpler environments often exclude controls tied to things they don’t do (e.g., specific supplier-chain or development-environment controls) while still fully implementing the core access-control, encryption, and incident-management controls. A gap assessment like the one above is the fastest way to see where you likely stand before a consultant scopes your SoA formally.

    How long does ISO 27001 certification take for a small or mid-size company?

    Companies with a simple environment and few existing gaps are sometimes certification-ready in as little as 3-4 months. Most small and mid-size companies with real gaps to close realistically need 6-9 months, and companies starting from close to zero often need 9-12 months or more. The variable isn’t company size so much as how much of the ISMS (risk assessment, SoA, policies, technical controls, internal audit) already exists versus needs to be built from scratch.

    How much does ISO 27001 certification cost?

    For a small or mid-size company, first-year costs (gap analysis, any consultant support, and the certification body’s Stage 1/Stage 2 audit fees) typically fall in the $15,000-$50,000 range, based on published 2026 industry cost guides. A lean, mostly self-managed build using existing IT infrastructure tends toward the low end; a consultant-led project or a more complex environment (multiple locations, more systems, more vendors) tends toward the high end.

    We’re a cloud service or SaaS provider. Do we need ISO 27017, ISO 27018, or CSA STAR instead of ISO 27001?

    No, you need ISO 27001 first, either alongside these or as the base you build on. ISO 27017 adds cloud-specific security controls on top of ISO 27001/27002, including clarity on who, you or your cloud provider, is responsible for which control. ISO 27018 adds controls specific to protecting personally identifiable information (PII) that you process in a public cloud as a data processor. CSA STAR (the Cloud Security Alliance’s Security, Trust, Assurance and Risk program) goes a step further: STAR Level 2 certification requires you already hold, or obtain alongside it, an accredited ISO 27001 certificate, and then layers the CSA Cloud Controls Matrix on top of it. In every case, the gap assessment above is the right starting point, since all three build on the same ISMS foundation and the same Annex A controls you’re being scored against here. If a customer or prospect is specifically asking for one of these three, run the assessment above first, then talk to us about scoping the cloud-specific add-on.

    Do we need ISO 27001 if we’re only losing deals over an RFP checkbox?

    That’s still a real business reason to pursue it, and it’s the single most common driver for manufacturing, finance/accounting, and professional-services firms in our experience. The certification itself, and the ISMS behind it, holds up regardless of why you started. Many companies begin the process purely to stop losing enterprise deals and end up with a genuinely more secure environment as a side effect, not the other way around.

    Ready to close your gaps?

    If your result flagged gaps in access control, encryption, audit logging, or tested backups, that’s technical and process work an IT and cybersecurity partner handles day to day.

    LeadingIT helps manufacturing, finance/accounting, and professional-services firms in Chicagoland build the technical controls, documentation support, and evidence an ISO 27001 audit expects, we deliver this FOR clients, not as a certifying body; only an accredited certification body issues the actual certificate.

    Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we support ISO 27001-aligned technical controls as a managed service.