What an ISO 27001 gap assessment actually tells you — and what it doesn't

Organisations planning ISO 27001 certification often move straight to implementation. A structured gap assessment clarifies scope, saves time and sets realistic expectations for the certification timeline.

An ISO 27001 gap assessment is a structured review of your current information security controls against the requirements of ISO/IEC 27001:2022 — the 93 controls in Annex A and the management system requirements in Clauses 4 to 10.

It does not tell you whether you will pass a certification audit. That decision is made by an independent accredited certification body following their own Stage 1 and Stage 2 process.