ISO/IEC 27001 is different in shape from SOC 2. It certifies an Information Security Management System — a governance machine defined by clauses 4 through 10 — plus a set of controls drawn from Annex A. Certification comes through an accredited body in two stages: a Stage 1 documentation review and a Stage 2 assessment of whether the ISMS actually operates. A gap analysis is how you measure the distance to that certification before the certification body starts writing findings down.
The 2022 revision matters: ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes — Organizational, People, Physical, and Technological. If your gap analysis is still mapped to the old 114-control Annex, it is measuring against the wrong target.
What an ISO 27001 gap analysis measures
The management system (clauses 4–10)
This is the half teams underestimate. ISO certifies the system that manages security, so the gap analysis has to assess:
- Clause 4 — Context: have you defined the ISMS scope, interested parties, and their requirements?
- Clause 5 — Leadership: is there a security policy, top-management commitment, and assigned roles?
- Clause 6 — Planning: a documented risk assessment and risk treatment methodology, and security objectives.
- Clause 7 — Support: resources, competence, awareness, and documented information control.
- Clause 8 — Operation: the risk assessment and treatment actually carried out.
- Clause 9 — Performance evaluation: monitoring, internal audit, and management review.
- Clause 10 — Improvement: nonconformity handling and continual improvement.
A missing internal audit or management-review cadence is one of the most common reasons a first ISO attempt stalls — and it is invisible if your gap analysis only looks at technical controls.
The Annex A controls and the Statement of Applicability
The gap analysis maps each of the 93 Annex A controls to your environment and feeds the Statement of Applicability (SoA) — the document declaring which controls apply, which do not, and why. The SoA is the spine of the audit; a sloppy one guarantees a rough Stage 2. The gap analysis is where you build it honestly.
Where penetration testing fits in ISO 27001
Two Annex A controls in the 2022 revision effectively call for real technical testing:
- A.8.8 — Management of technical vulnerabilities: you must obtain information about vulnerabilities, evaluate exposure, and take action. A penetration test plus a functioning remediation process is direct evidence.
- A.8.29 — Security testing in development and acceptance: testing must be defined and performed across the lifecycle.
As with SOC 2, an auditor will accept a recent, independent penetration test as strong evidence for these controls — and its absence is a gap the assessment will note. The gap analysis defines the ISMS scope; the pentest is then scoped to the systems inside it.
Common ISO 27001 gaps we find: a risk assessment that was done once and never revisited, an SoA that excludes controls without a defensible justification, no evidence of internal audit or management review, awareness training that was never delivered, and A.8.8 satisfied by a policy that promises vulnerability management with no scan or pentest behind it.
Stage 1 and Stage 2 — and why the gap analysis mirrors both
Stage 1 is a documentation review: does the ISMS exist on paper and is it internally coherent? Stage 2 tests whether it operates. A good gap analysis rehearses both — first checking that the documentation is complete and consistent (your private Stage 1), then checking that the controls actually run and produce evidence (your private Stage 2). Walk into the real Stage 1 having already passed your own, and the certification path shortens considerably.
How Lorikeet runs an ISO 27001 gap analysis
We assess both halves — the management-system clauses and the Annex A controls — and produce a remediation plan plus a draft Statement of Applicability you can take into Stage 1. For the technological controls, we ground the assessment in your real environment using Attack Surface Management and validate A.8.8 and A.8.29 with an independent penetration test run on our PTaaS platform: Lory's autonomous testing, countersigned by a human pentester, delivered as a report your certification body will accept. Gap analysis and pentest, scoped to the same ISMS boundary, in one plan.
Measure the Distance to ISO 27001
Lorikeet Security runs ISO 27001 gap analyses across the ISMS clauses and Annex A controls, paired with independent penetration testing for the technical-vulnerability controls — so Stage 2 holds no surprises.