ISO 27001 Gap Analysis: Closing the Distance to Certification | Lorikeet Security Skip to main content
Back to Blog

ISO 27001 Gap Analysis: Closing the Distance to Certification

Lorikeet Security Team August 21, 2026 11 min read

ISO/IEC 27001 is different in shape from SOC 2. It certifies an Information Security Management System — a governance machine defined by clauses 4 through 10 — plus a set of controls drawn from Annex A. Certification comes through an accredited body in two stages: a Stage 1 documentation review and a Stage 2 assessment of whether the ISMS actually operates. A gap analysis is how you measure the distance to that certification before the certification body starts writing findings down.

The 2022 revision matters: ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes — Organizational, People, Physical, and Technological. If your gap analysis is still mapped to the old 114-control Annex, it is measuring against the wrong target.

What an ISO 27001 gap analysis measures

The management system (clauses 4–10)

This is the half teams underestimate. ISO certifies the system that manages security, so the gap analysis has to assess:

A missing internal audit or management-review cadence is one of the most common reasons a first ISO attempt stalls — and it is invisible if your gap analysis only looks at technical controls.

The Annex A controls and the Statement of Applicability

The gap analysis maps each of the 93 Annex A controls to your environment and feeds the Statement of Applicability (SoA) — the document declaring which controls apply, which do not, and why. The SoA is the spine of the audit; a sloppy one guarantees a rough Stage 2. The gap analysis is where you build it honestly.

Where penetration testing fits in ISO 27001

Two Annex A controls in the 2022 revision effectively call for real technical testing:

As with SOC 2, an auditor will accept a recent, independent penetration test as strong evidence for these controls — and its absence is a gap the assessment will note. The gap analysis defines the ISMS scope; the pentest is then scoped to the systems inside it.

Common ISO 27001 gaps we find: a risk assessment that was done once and never revisited, an SoA that excludes controls without a defensible justification, no evidence of internal audit or management review, awareness training that was never delivered, and A.8.8 satisfied by a policy that promises vulnerability management with no scan or pentest behind it.

Stage 1 and Stage 2 — and why the gap analysis mirrors both

Stage 1 is a documentation review: does the ISMS exist on paper and is it internally coherent? Stage 2 tests whether it operates. A good gap analysis rehearses both — first checking that the documentation is complete and consistent (your private Stage 1), then checking that the controls actually run and produce evidence (your private Stage 2). Walk into the real Stage 1 having already passed your own, and the certification path shortens considerably.

How Lorikeet runs an ISO 27001 gap analysis

We assess both halves — the management-system clauses and the Annex A controls — and produce a remediation plan plus a draft Statement of Applicability you can take into Stage 1. For the technological controls, we ground the assessment in your real environment using Attack Surface Management and validate A.8.8 and A.8.29 with an independent penetration test run on our PTaaS platform: Lory's autonomous testing, countersigned by a human pentester, delivered as a report your certification body will accept. Gap analysis and pentest, scoped to the same ISMS boundary, in one plan.

Measure the Distance to ISO 27001

Lorikeet Security runs ISO 27001 gap analyses across the ISMS clauses and Annex A controls, paired with independent penetration testing for the technical-vulnerability controls — so Stage 2 holds no surprises.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!