ipfour
Security consultant reviewing ISO 27001 gap analysis documentation and control assessment frameworks
ISO 27001 Phase 1

ISO 27001 Gap Analysis. Know exactly where you stand.

Before you invest in building an ISMS, you need to know what is already in place and what is missing. Our ISO 27001 gap analysis gives you a clause-by-clause assessment against all 93 Annex A controls, a maturity score, and a prioritised remediation roadmap.

ISO 27001 Phase 1
UK-Wide Service
Fixed-Price Report
Board-Ready Output
31
Average gaps identified per organisation
3 weeks
Typical gap analysis completion time
93
Annex A controls assessed in full
UK-wide
Service delivery across England, Scotland and Wales
What We Deliver

Six deliverables. One complete gap picture.

Annex A Control Assessment

A structured review of your current security controls against all 93 Annex A controls in ISO 27001:2022, producing a clear conformity rating for each requirement.

Maturity Scoring

Each gap is scored by severity and remediation effort, giving you a realistic view of how much work is required and where to focus first.

Remediation Roadmap

A prioritised action plan with realistic timelines, resource requirements, and dependencies mapped out so your team knows exactly what to do next.

Existing Controls Review

We identify which controls you already have in place, reducing duplication and accelerating your path to certification by building on what works.

Critical Gap Identification

Immediate flagging of any gaps that would result in a major non-conformity at audit, so you can address the highest-risk items without delay.

Executive Briefing

A clear, non-technical summary of findings for your board or senior leadership team, including estimated investment and timeline to certification.

Our Process

From document review to remediation roadmap. Six structured steps.

01

Document Review

We review your existing security policies, risk registers, incident logs, and any relevant management system documentation to understand your current baseline.

02

Stakeholder Interviews

Structured interviews with IT, security, legal, compliance, and senior leadership to understand current security practices in reality versus on paper.

03

Technical Controls Review

Assessment of technical controls including access management, network security, encryption, patch management, and monitoring configurations.

04

Gap Scoring

Each identified gap is scored against a consistent framework covering severity, likelihood of audit failure, and estimated remediation effort.

05

Roadmap Development

We build a phased remediation roadmap that sequences work logically, respects your resource constraints, and targets certification within your desired timeframe.

06

Findings Presentation

We present findings to your project team and leadership, answer questions, and agree the remediation plan before moving to ISMS design.

UK Use Cases

Organisations that needed clarity. Before they committed.

Professional Services

Law firm pre-certification assessment

A UK law firm handling sensitive client data needed to understand their ISO 27001 readiness before committing to a certification timeline. Our gap analysis identified 31 gaps, of which 5 were critical. We delivered a 10-week remediation roadmap that kept their certification target on track.

Public Sector

NHS supplier compliance review

An NHS supplier needed ISO 27001 certification to retain their framework position. Our gap analysis gave them a clause-by-clause assessment and a clear remediation plan, enabling them to achieve certification within the required 9-month window.

Technology

SaaS platform security baseline

A UK SaaS business processing personal data needed to understand their security control maturity before their enterprise sales team could progress deals requiring ISO 27001. Our gap analysis identified the three control areas requiring immediate investment.

Start Your ISO 27001 Journey

Get a clear picture of your ISO 27001 readiness. Fixed price. Three weeks.

Our fixed-price gap analysis gives you a complete Annex A assessment, a maturity score, and a prioritised remediation roadmap. Everything you need to make an informed decision about your ISO 27001 programme.