ISO27K

ISO 27001 gap assessment: what to expect

A gap assessment measures the distance between what you do now and what the standard requires. Its value is entirely in the findings report, so this page is mostly about how to tell a good one from an invoice with a spreadsheet attached.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

An ISO 27001 gap assessment costs $8,000 to $20,000 CAD in Canada, takes two to four weeks, and should produce a finding for every one of the 93 Annex A controls and every one of the 25 clause requirements, each with a current state, a required state, an owner and an effort estimate. If what comes back is a colour coded spreadsheet with no owners and no estimates, you paid for a survey rather than a plan.

It is the right first purchase for most companies, because committing to a full implementation before anyone has looked at your environment means buying work you may not need. It is the wrong purchase if you already know you are starting from nothing, because you can predict the finding.

What the assessment covers

Two halves, and firms that only do the first half are common enough to be worth checking for. Annex A is the visible half: 93 controls, and for each one a judgement about whether it operates, partially operates or does not exist. The clause requirements are the half that gets skipped, and they are where first time certifications fail, because a company can close every technical control and still have no documented scope, no management review and no internal audit program.

What a full gap assessment examines
AreaWhat is assessedWhere gaps usually are
Clauses 4 and 5Scope, context, interested parties, leadership, policyNo written scope, or one written by department
Clause 6Risk method, risk register, treatment, Statement of Applicability, objectivesA template register with no owners; objectives that are not measurable
Clauses 7 and 8Competence, awareness, document control, operational planningDocument control, almost always. Policies in five places with no version history
Clause 9Monitoring, internal audit, management reviewNever held, or held without the inputs the clause lists
Clause 10Nonconformity, corrective action, improvementNo mechanism at all for raising and closing a nonconformity
A.5 organizationalPolicies, roles, supplier and cloud controls, incident management, continuitySupplier security, and the classification scheme nobody uses
A.6 peopleScreening, terms, awareness, disciplinary, remote workingOffboarding evidence, and screening records for early employees
A.7 physicalPerimeters, entry, equipment, clear desk, disposalRarely a problem for cloud companies, and the exclusions need justifying
A.8 technologicalAccess, cryptography, logging, secure development, vulnerability management, testingLogging retention, and evidence that vulnerabilities are tracked to closure

What a good findings report contains

Ask to see a redacted sample before signing. The difference between firms is almost entirely visible in that document. Four things should be present for every finding.

  • Evidence of what is true today, not what the policy says. A finding that reads "access reviews are documented in the access policy" is worthless. One that reads "the access policy requires quarterly reviews; the last recorded review was in March and covered two of eleven systems" is a finding.
  • The specific requirement it fails, cited by clause or control number, so you can argue with it.
  • A named owner from your organization, agreed during the assessment rather than assigned afterwards by someone who does not know who does what.
  • An effort estimate and a dependency, because a plan without sequencing produces forty parallel workstreams and no progress.

The best reports also mark which findings are blocking, meaning stage 2 cannot proceed until they are closed, and which are simply work. That distinction is what lets you set a realistic certification date instead of guessing.

Running the first pass yourself

Before you buy anything, do the cheap version. It takes a day and it changes what you buy.

Take the Annex A control list and, for each control, write one of three answers: it runs and we can produce evidence from the last quarter; it runs but nobody records it; it does not exist. Do not consult the policy while doing this. Ask the person who would have to produce the evidence. The gap between what a policy says and what the responsible person can produce within the hour is the real gap, and it is invisible to any assessment done on documents alone.

The Annex A self-assessment tool runs that logic across the four control themes and scores where you sit, and the control list itself with what each theme covers is on the Annex A page.

Do not let your certification body do this

ISO/IEC 17021-1 stops an accredited body from certifying a management system it consulted on, with a two-year cool off after the advice ends. A gap assessment from your intended certification body is close enough to consultancy that it can disqualify them, and some bodies offer a limited version specifically structured to avoid that. If you want a body's opinion before stage 1, ask for a pre-assessment and ask them in writing to confirm it does not affect their ability to certify you.

What it costs and what changes the price

Gap assessment pricing in Canada, CAD
DepthRange (CAD)Deliverable
Document review only$4,000 to $8,000Findings against what you have written down. Cheap, and misses the operating gaps.
Interview based, full standard$8,000 to $20,000Findings report against all 93 controls and the clause requirements, with owners and estimates.
Assessment plus roadmap and budget$15,000 to $30,000The above plus a sequenced plan, a certification date and a costed budget.
Pre-audit or mock stage 2$5,000 to $12,000Different thing, done at the end rather than the start, by someone who audits for a living.

Price moves with the number of people to be interviewed and the number of distinct environments, not with headcount directly. A forty-person company with one product and one cloud account is a smaller assessment than a fifteen-person company with three acquired products on separate infrastructure.

Do not pay for a gap assessment twice. If you go on to buy implementation support from the same firm, the assessment fee is commonly credited against it, and it is worth asking before you sign the first engagement rather than after. The itemised certification cost covers where this line sits relative to everything else.

What to do with the findings

Sequence them by dependency rather than by severity. Scope, risk assessment and the Statement of Applicability come first regardless of how they scored, because every other finding is defined relative to them. Then anything with a procurement lead time, because single sign-on licensing or a logging platform takes weeks to buy and configure and nothing else waits on it. Then the recurring activities, because those need to start early enough to have produced records by the time an auditor samples them.

The findings that look worst are usually not the ones that delay you. A missing incident response plan is a week of work. A missing three months of access review records is three months, and no budget shortens it. That is why readiness is measured in elapsed time rather than tasks.

Get a gap assessment quoted

Tell us your scope and what exists today, and we will match you with Canadian firms that will assess it properly.

Get matched

Common questions

How much does an ISO 27001 gap assessment cost in Canada?

$8,000 to $20,000 CAD for an interview based assessment covering all 93 Annex A controls and the clause requirements. A document only review runs $4,000 to $8,000 CAD and is worth less than the difference, because it cannot see whether a documented control is actually operating.

How long does a gap assessment take?

Two to four weeks for most Canadian companies. Roughly a week of interviews and evidence sampling, then a week or two to write the report. If a firm quotes three days end to end, it is doing a document review, which is a legitimate product but a different one.

Can we do a gap assessment ourselves?

Yes, and the first pass is worth doing internally whatever you buy afterwards. What you lose is calibration: an experienced assessor knows what an auditor accepts as evidence, and that judgement is the part you cannot read out of the standard. Do the internal pass first so the paid assessment starts from a real picture rather than from discovery.

Should the gap assessment come before or after we pick a certification body?

Before, in almost every case. The assessment tells you your scope, your likely certification date and your budget, and all three are things the body asks about when quoting. Booking a body first means quoting a scope you have not validated. The one exception is when a customer deadline forces you to hold a stage 2 slot, since scheduling can take two months on its own.