ISO 27001 Gap Analysis That Tells You How to Fix
Most gap tools hand you a checklist and stop there. EvaluationCat identifies every missing control, ranks it by severity, and translates each gap into a concrete remediation task with steps, tools, cost, and effort.
What Is an ISO 27001 Gap Analysis?
A gap analysis compares the security controls you actually have today against what ISO/IEC 27001:2022 Annex A requires — all 93 controls across organizational, people, physical, and technological domains.
The output is a clear list of where you fall short: controls that are entirely missing, partially implemented, or only planned. Done well, it becomes the foundation of your entire ISMS implementation plan. Done poorly, it's a spreadsheet nobody acts on.
A gap analysis is also distinct from an internal audit and from certification: it is usually the first step — establishing your baseline before you design processes, train teams, or invite auditors.
Typical checklist tools give you
- ×A yes/no list of controls
- ×A percentage with no context
- דImplement access control policy” — no how
- ×No prioritization by risk or effort
EvaluationCat gives you
- Five-level maturity scoring per control, weighted by importance
- Severity-ranked gaps across four domains
- Per-gap remediation with steps, tools, cost, effort
- 30/90/180-day prioritized roadmap (Pro)
Every Gap Comes With a Fix
This is what one identified gap looks like in an EvaluationCat report
A.8.5
Secure Authentication
Why it matters
Passwords alone are trivially compromised through phishing and credential reuse. Without MFA, a single leaked password grants full account access.
How to fix
Enforce multi-factor authentication on all user and administrative accounts. Prefer phishing-resistant methods (hardware keys, passkeys) for admin roles.
Recommended tools
Okta, Auth0, Entra ID, or cloud-native MFA
Effort
4–8 hours
Cost
$0–$3/user/month
Example shown. Full reports contain every applicable gap, ranked into a 30/90/180-day plan.
Related Pages
ISO 27001 Self-Assessment
Run the full 93-control assessment first — gaps come free with it.
Sample Report
See what the finished report looks like, gap table included.
Security Assessment for Startups
Unblock enterprise deals without hiring a consultant.
Scoring Methodology
How severity and readiness are calculated.
Find Your Gaps. Fix Them in the Right Order.
Free to run. Your baseline takes about 30–60 minutes to establish.
Start Free Gap Analysis