
Standard-oriented diagnosis for ISO 27001
ISO 27001 GAP analysis: How far is your organisation really?
The ISO 27001 GAP analysis of Kynexis Information Security is a quality assessment of your current ISMS compared to ISO/IEC 27001:2022. You can see what is demonstrably arranged, what parts or evidence are missing and what steps are priority for implementation, certification or structural assurance. The outcome is a diagnosis with roadmap that guides implementation and preparation for a later internal or certification audit.
- Policies and measures exist, but it is unclear which ISO 27001 requirements are demonstrably fulfilled.
- Documents have been prepared, while ownership, execution or proof does not yet go everywhere.
- The preparation for certification lacks reliable prioritisation and planning.
- You want to avoid that deficiencies will only become visible during the internal or certification audit.
What are the risks? Without independent GAP analysis, a lot of work is done on the basis of assumptions and lack of operation, evidence and responsibilities can delay the path late.
Our promise of service
A clear diagnosis of your ISMS and the route to certification
The ISO 27001 GAP analysis compares your current design, execution and proof with ISO/IEC 27001:2022 and makes visible which improvements are needed first.
- Overview of standard coverage and gaps
- Assessment of operation and evidence
- Prioritized roadmap towards certification
ISO 27001 GAP Analysis
What is ISO 27001 GAP analysis?
The ISO 27001 GAP analysis of Kynexis Information Security is a quality assessment of your current ISMS compared to ISO/IEC 27001:2022. You can see what is demonstrably arranged, what parts or evidence are missing and what steps are priority for implementation, certification or structural assurance. The outcome is a diagnosis with roadmap that guides implementation and preparation for a later internal or certification audit.
When does this service fit?
View of the distance between current practice and desired standard
For this GAP analysis, choose if your organisation wants to implement ISO 27001, strengthen an existing ISMS or prepare for certification. The analysis brings standards, risks, measures, documentation and ownership into a coherent picture.
Research area
From organisational context to demonstrable operation
The analysis follows the structure of ISO/IEC 27001:2022 and involves the relevant management measures from Annex A.
Context and Scope
Stakeholders, processes, boundaries, dependencies and scope of ISMS.
Leadership and governance
Policy, roles, responsibilities, decision-making and management involvement.
Risk management
Methodology, risk analysis, risk treatment, acceptance and link with measures.
Support and implementation
Competences, communication, documentation and operational control.
Evaluation
Objectives, monitoring, internal audits and management assessment.
Improvement and Annex A
Derogations, corrective measures and the justification of selected controls.
Your result
An executable route to a coherent ISMS
The reporting links any relevant difference with risk, need for proof, owner and follow-up step. Kynexis Information Security can support the follow-up with a structured evidence register in Normity, so that documents and actions remain centrally available.
- GAP overview per relevant norm requirement
- Assessment of ISMS, Risk Approach and Annex A
- Priorities with owner and need for proof
- Roadmap towards implementation or certification
- Management discussion and advice on follow-up steps
How we work
So we work out the GAP analysis
- 01
Determining Scope
Define ambition, certification target, organisational context and ISMS boundaries.
- 02
GAP Investigations
Compare documents, practices, risks and evidence with the standard.
- 03
Indicate differences
GAPs weigh on risk, coherence, effort and certification.
- 04
Configure Roadmap
Define actions, owners, evidence and logical implementation order.
ISO 27001 follow-up route
GAP analysis, implementation and internal audit
The GAP analysis determines where the ISMS is now. Afterwards, the execution of improvements and independent checking of the operation remain identifiable separate steps.
ISO 27001 GAP Analysis
To present the current design, implementation, evidence and priorities independently.
Fit for this implementation phaseISO 27001 implementation support
Missing parts workable design and make ISMS work in the organisation.
View this phase →ISO 27001 internal audit
Independently assess whether agreements are being implemented and the ISMS is demonstrably working.
View this phase →Internal control
Actions, controls, evidence and management reporting continue to follow cycle.
View this phase →Discuss your certification ambition, ISMS scope and desired depth for a targeted diagnosis and a feasible roadmap.
Schedule an intake call →Frequently Asked Questions
Practical answers on ISO 27001 GAP Analysis
What is an ISO 27001 GAP analysis investigating?
The analysis compares the current ISMS, the risk approach, implementation and evidence available with ISO/IEC 27001:2022 and the relevant management measures from Annex A.
Is a GAP analysis the same as a certification audit?
No. The GAP analysis is a preliminary diagnosis and provides direction for improvement. Only an accredited certification body can carry out the formal certification audit and provide an ISO 27001 certificate.
What is the difference with ISO 27001 implementation or internal audit?
The GAP analysis determines where your ISMS is now and provides a feasible roadmap. Implementation is then actually decorating and implementing the missing parts. An internal audit will later assess independently whether the set up of ISMS meets and works according to its own agreements and standards.
Can we start if there's not much documentation?
Yes. The analysis shows exactly what documentation and evidence are needed. Existing practices are used as starting points wherever possible, so that ISMS is compatible with practice.
How does Normity support the follow-up?
Kynexis Information Security can capture risks, demands, measures, actions, owners and evidence structured in Normity. This supports progress, audit preparation and permanent assurance.

A good GAP analysis looks at documents and daily practice. This will make it visible whether responsibilities, measures and controls really work.