Standard-oriented diagnosis for ISO 27001

ISO 27001 GAP analysis: How far is your organisation really?

The ISO 27001 GAP analysis of Kynexis Information Security is a quality assessment of your current ISMS compared to ISO/IEC 27001:2022. You can see what is demonstrably arranged, what parts or evidence are missing and what steps are priority for implementation, certification or structural assurance. The outcome is a diagnosis with roadmap that guides implementation and preparation for a later internal or certification audit.

Do you recognize this?
  • Policies and measures exist, but it is unclear which ISO 27001 requirements are demonstrably fulfilled.
  • Documents have been prepared, while ownership, execution or proof does not yet go everywhere.
  • The preparation for certification lacks reliable prioritisation and planning.
  • You want to avoid that deficiencies will only become visible during the internal or certification audit.

What are the risks? Without independent GAP analysis, a lot of work is done on the basis of assumptions and lack of operation, evidence and responsibilities can delay the path late.

Our promise of service

A clear diagnosis of your ISMS and the route to certification

The ISO 27001 GAP analysis compares your current design, execution and proof with ISO/IEC 27001:2022 and makes visible which improvements are needed first.

  • Overview of standard coverage and gaps
  • Assessment of operation and evidence
  • Prioritized roadmap towards certification

ISO 27001 GAP Analysis

What is ISO 27001 GAP analysis?

The ISO 27001 GAP analysis of Kynexis Information Security is a quality assessment of your current ISMS compared to ISO/IEC 27001:2022. You can see what is demonstrably arranged, what parts or evidence are missing and what steps are priority for implementation, certification or structural assurance. The outcome is a diagnosis with roadmap that guides implementation and preparation for a later internal or certification audit.

FOR WHOMFor ISO 27001 implementation
WHENView of the distance between current practice and desired standard
RESULTAn executable route to a coherent ISMS

When does this service fit?

View of the distance between current practice and desired standard

For this GAP analysis, choose if your organisation wants to implement ISO 27001, strengthen an existing ISMS or prepare for certification. The analysis brings standards, risks, measures, documentation and ownership into a coherent picture.

For ISO 27001 implementationFor the redesign of ISMSFor preparation for certification

Research area

From organisational context to demonstrable operation

The analysis follows the structure of ISO/IEC 27001:2022 and involves the relevant management measures from Annex A.

Context and Scope

Stakeholders, processes, boundaries, dependencies and scope of ISMS.

Leadership and governance

Policy, roles, responsibilities, decision-making and management involvement.

Risk management

Methodology, risk analysis, risk treatment, acceptance and link with measures.

Support and implementation

Competences, communication, documentation and operational control.

Evaluation

Objectives, monitoring, internal audits and management assessment.

Improvement and Annex A

Derogations, corrective measures and the justification of selected controls.

Your result

An executable route to a coherent ISMS

The reporting links any relevant difference with risk, need for proof, owner and follow-up step. Kynexis Information Security can support the follow-up with a structured evidence register in Normity, so that documents and actions remain centrally available.

  • GAP overview per relevant norm requirement
  • Assessment of ISMS, Risk Approach and Annex A
  • Priorities with owner and need for proof
  • Roadmap towards implementation or certification
  • Management discussion and advice on follow-up steps
KYNEXISISO 27001 GAP Analysis
7Large GAP12Supplement18Demonstrable
FocusISMS, ownership and evidenceRisk-driven and enforceable

How we work

So we work out the GAP analysis

  1. 01

    Determining Scope

    Define ambition, certification target, organisational context and ISMS boundaries.

  2. 02

    GAP Investigations

    Compare documents, practices, risks and evidence with the standard.

  3. 03

    Indicate differences

    GAPs weigh on risk, coherence, effort and certification.

  4. 04

    Configure Roadmap

    Define actions, owners, evidence and logical implementation order.

ISO 27001 follow-up route

GAP analysis, implementation and internal audit

The GAP analysis determines where the ISMS is now. Afterwards, the execution of improvements and independent checking of the operation remain identifiable separate steps.

02 IMPLEMENTATIE

ISO 27001 implementation support

Missing parts workable design and make ISMS work in the organisation.

View this phase →
03 INTERNAL REVIEW

ISO 27001 internal audit

Independently assess whether agreements are being implemented and the ISMS is demonstrably working.

View this phase →
04 ASSURANCE

Internal control

Actions, controls, evidence and management reporting continue to follow cycle.

View this phase →
Make your next step concreteHave ISO 27001 GAP analysis performed?

Discuss your certification ambition, ISMS scope and desired depth for a targeted diagnosis and a feasible roadmap.

Schedule an intake call

Frequently Asked Questions

Practical answers on ISO 27001 GAP Analysis

What is an ISO 27001 GAP analysis investigating?

The analysis compares the current ISMS, the risk approach, implementation and evidence available with ISO/IEC 27001:2022 and the relevant management measures from Annex A.

Is a GAP analysis the same as a certification audit?

No. The GAP analysis is a preliminary diagnosis and provides direction for improvement. Only an accredited certification body can carry out the formal certification audit and provide an ISO 27001 certificate.

What is the difference with ISO 27001 implementation or internal audit?

The GAP analysis determines where your ISMS is now and provides a feasible roadmap. Implementation is then actually decorating and implementing the missing parts. An internal audit will later assess independently whether the set up of ISMS meets and works according to its own agreements and standards.

Can we start if there's not much documentation?

Yes. The analysis shows exactly what documentation and evidence are needed. Existing practices are used as starting points wherever possible, so that ISMS is compatible with practice.

How does Normity support the follow-up?

Kynexis Information Security can capture risks, demands, measures, actions, owners and evidence structured in Normity. This supports progress, audit preparation and permanent assurance.

Wouter Parent

A good GAP analysis looks at documents and daily practice. This will make it visible whether responsibilities, measures and controls really work.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates