Taking new engagements — Q4 hello@datadefenz.com
ServicesProductsResourcesPracticeAboutTalk to us
Services / GRC & Compliance / ISO 27001 Gap Assessment

ISO 27001 Gap Assessment

Find out exactly what is missing before you attempt certification.

In plain terms

ISO 27001 is the international standard for running a real information security programme. Certification works like a credit score for security — something you can show a customer instead of asking them to take your word for it. A gap assessment tests you against all 93 Annex A controls plus the management-system clauses, and tells you precisely what stands between you and a certificate.

What you get

  • Assessment against all 93 Annex A controls and clauses 4–10
  • Findings rated by severity, with the evidence we could and could not see
  • A gap closure plan sequenced by effort and dependency, not alphabetically
  • Statement of Applicability draft you can carry into certification

Who it is for

Companies being asked for ISO 27001 by a customer, an investor, or a tender — and companies who want to know the real cost before committing.

Tool

The 93 controls we assess against

This is the exact scope of the gap assessment. Click any control to see what it asks for.

Select a controlClick, or tab in and use arrow keys

Control titles follow ISO/IEC 27001:2022 Annex A. Plain-English lines are our paraphrase, not the wording of the standard.