ISO 27001 gap assessment: what to expect
A gap assessment measures the distance between what you do now and what the standard requires. Its value is entirely in the findings report, so this page is mostly about how to tell a good one from an invoice with a spreadsheet attached.
An ISO 27001 gap assessment costs $8,000 to $20,000 CAD in Canada, takes two to four weeks, and should produce a finding for every one of the 93 Annex A controls and every one of the 25 clause requirements, each with a current state, a required state, an owner and an effort estimate. If what comes back is a colour coded spreadsheet with no owners and no estimates, you paid for a survey rather than a plan.
It is the right first purchase for most companies, because committing to a full implementation before anyone has looked at your environment means buying work you may not need. It is the wrong purchase if you already know you are starting from nothing, because you can predict the finding.
What the assessment covers
Two halves, and firms that only do the first half are common enough to be worth checking for. Annex A is the visible half: 93 controls, and for each one a judgement about whether it operates, partially operates or does not exist. The clause requirements are the half that gets skipped, and they are where first time certifications fail, because a company can close every technical control and still have no documented scope, no management review and no internal audit program.
| Area | What is assessed | Where gaps usually are |
|---|---|---|
| Clauses 4 and 5 | Scope, context, interested parties, leadership, policy | No written scope, or one written by department |
| Clause 6 | Risk method, risk register, treatment, Statement of Applicability, objectives | A template register with no owners; objectives that are not measurable |
| Clauses 7 and 8 | Competence, awareness, document control, operational planning | Document control, almost always. Policies in five places with no version history |
| Clause 9 | Monitoring, internal audit, management review | Never held, or held without the inputs the clause lists |
| Clause 10 | Nonconformity, corrective action, improvement | No mechanism at all for raising and closing a nonconformity |
| A.5 organizational | Policies, roles, supplier and cloud controls, incident management, continuity | Supplier security, and the classification scheme nobody uses |
| A.6 people | Screening, terms, awareness, disciplinary, remote working | Offboarding evidence, and screening records for early employees |
| A.7 physical | Perimeters, entry, equipment, clear desk, disposal | Rarely a problem for cloud companies, and the exclusions need justifying |
| A.8 technological | Access, cryptography, logging, secure development, vulnerability management, testing | Logging retention, and evidence that vulnerabilities are tracked to closure |
What a good findings report contains
Ask to see a redacted sample before signing. The difference between firms is almost entirely visible in that document. Four things should be present for every finding.
- Evidence of what is true today, not what the policy says. A finding that reads "access reviews are documented in the access policy" is worthless. One that reads "the access policy requires quarterly reviews; the last recorded review was in March and covered two of eleven systems" is a finding.
- The specific requirement it fails, cited by clause or control number, so you can argue with it.
- A named owner from your organization, agreed during the assessment rather than assigned afterwards by someone who does not know who does what.
- An effort estimate and a dependency, because a plan without sequencing produces forty parallel workstreams and no progress.
The best reports also mark which findings are blocking, meaning stage 2 cannot proceed until they are closed, and which are simply work. That distinction is what lets you set a realistic certification date instead of guessing.
Running the first pass yourself
Before you buy anything, do the cheap version. It takes a day and it changes what you buy.
Take the Annex A control list and, for each control, write one of three answers: it runs and we can produce evidence from the last quarter; it runs but nobody records it; it does not exist. Do not consult the policy while doing this. Ask the person who would have to produce the evidence. The gap between what a policy says and what the responsible person can produce within the hour is the real gap, and it is invisible to any assessment done on documents alone.
The Annex A self-assessment tool runs that logic across the four control themes and scores where you sit, and the control list itself with what each theme covers is on the Annex A page.
Do not let your certification body do this
ISO/IEC 17021-1 stops an accredited body from certifying a management system it consulted on, with a two-year cool off after the advice ends. A gap assessment from your intended certification body is close enough to consultancy that it can disqualify them, and some bodies offer a limited version specifically structured to avoid that. If you want a body's opinion before stage 1, ask for a pre-assessment and ask them in writing to confirm it does not affect their ability to certify you.
What it costs and what changes the price
| Depth | Range (CAD) | Deliverable |
|---|---|---|
| Document review only | $4,000 to $8,000 | Findings against what you have written down. Cheap, and misses the operating gaps. |
| Interview based, full standard | $8,000 to $20,000 | Findings report against all 93 controls and the clause requirements, with owners and estimates. |
| Assessment plus roadmap and budget | $15,000 to $30,000 | The above plus a sequenced plan, a certification date and a costed budget. |
| Pre-audit or mock stage 2 | $5,000 to $12,000 | Different thing, done at the end rather than the start, by someone who audits for a living. |
Price moves with the number of people to be interviewed and the number of distinct environments, not with headcount directly. A forty-person company with one product and one cloud account is a smaller assessment than a fifteen-person company with three acquired products on separate infrastructure.
Do not pay for a gap assessment twice. If you go on to buy implementation support from the same firm, the assessment fee is commonly credited against it, and it is worth asking before you sign the first engagement rather than after. The itemised certification cost covers where this line sits relative to everything else.
What to do with the findings
Sequence them by dependency rather than by severity. Scope, risk assessment and the Statement of Applicability come first regardless of how they scored, because every other finding is defined relative to them. Then anything with a procurement lead time, because single sign-on licensing or a logging platform takes weeks to buy and configure and nothing else waits on it. Then the recurring activities, because those need to start early enough to have produced records by the time an auditor samples them.
The findings that look worst are usually not the ones that delay you. A missing incident response plan is a week of work. A missing three months of access review records is three months, and no budget shortens it. That is why readiness is measured in elapsed time rather than tasks.
Get a gap assessment quoted
Tell us your scope and what exists today, and we will match you with Canadian firms that will assess it properly.
Get matchedCommon questions
How much does an ISO 27001 gap assessment cost in Canada?
$8,000 to $20,000 CAD for an interview based assessment covering all 93 Annex A controls and the clause requirements. A document only review runs $4,000 to $8,000 CAD and is worth less than the difference, because it cannot see whether a documented control is actually operating.
How long does a gap assessment take?
Two to four weeks for most Canadian companies. Roughly a week of interviews and evidence sampling, then a week or two to write the report. If a firm quotes three days end to end, it is doing a document review, which is a legitimate product but a different one.
Can we do a gap assessment ourselves?
Yes, and the first pass is worth doing internally whatever you buy afterwards. What you lose is calibration: an experienced assessor knows what an auditor accepts as evidence, and that judgement is the part you cannot read out of the standard. Do the internal pass first so the paid assessment starts from a real picture rather than from discovery.
Should the gap assessment come before or after we pick a certification body?
Before, in almost every case. The assessment tells you your scope, your likely certification date and your budget, and all three are things the body asks about when quoting. Booking a body first means quoting a scope you have not validated. The one exception is when a customer deadline forces you to hold a stage 2 slot, since scheduling can take two months on its own.