ISO 27001

ISO 27001 Gap Assessment

Cycore's 115-prompt ISO 27001 self-assessment. Score each prompt 0 to 3, record the evidence and the owner, and find your gaps before you talk to an auditor.

Download the PDF
PDF, 13 pages, no form

We built this gap assessment for teams preparing for an ISO 27001 audit, or tightening an information security management system they already run. It's a Cycore self-assessment based on ISO/IEC 27001:2022. Work through it with the people who own each area, and you'll have a list of gaps with a name next to each one before you talk to an auditor.

What's inside

Seven clause sections, 115 prompts:

  • Clause 4, Context of the organization (16)
  • Clause 5, Leadership (18)
  • Clause 6, Planning (20)
  • Clause 7, Support (19)
  • Clause 8, Operation (10)
  • Clause 9, Performance evaluation (23)
  • Clause 10, Improvement (9)

Every prompt scores 0 to 3, so the 115 prompts make a maximum of 345, with space to write in the evidence and the owner. After the scored sections there's an unscored sample of 38 of the 93 Annex A reference controls, each with the gap we commonly find.

How to use it

Score each prompt, add up each clause, and total out of 345. The score is a Cycore planning signal. It isn't a certification status, and it doesn't predict how long the work will take. Give every prompt under 3 an owner and a date, and carry them back into your GRC platform if you run one. The Annex A sample isn't scored. Use it to check your own control set, then compare against the full Annex A.

Download the PDF and work through it with your team.

Download the PDF
Format
PDF, 13 pages
Last reviewed
September 23, 2026
Form
None

proof of work

Read the case study
ISO 27001

ISO 27001 Gap Assessment

Cycore's 115-prompt ISO 27001 self-assessment. Score each prompt 0 to 3, record the evidence and the owner, and find your gaps before you talk to an auditor.

Download the PDF

We built this gap assessment for teams preparing for an ISO 27001 audit, or tightening an information security management system they already run. It's a Cycore self-assessment based on ISO/IEC 27001:2022. Work through it with the people who own each area, and you'll have a list of gaps with a name next to each one before you talk to an auditor.

What's inside

Seven clause sections, 115 prompts:

  • Clause 4, Context of the organization (16)
  • Clause 5, Leadership (18)
  • Clause 6, Planning (20)
  • Clause 7, Support (19)
  • Clause 8, Operation (10)
  • Clause 9, Performance evaluation (23)
  • Clause 10, Improvement (9)

Every prompt scores 0 to 3, so the 115 prompts make a maximum of 345, with space to write in the evidence and the owner. After the scored sections there's an unscored sample of 38 of the 93 Annex A reference controls, each with the gap we commonly find.

How to use it

Score each prompt, add up each clause, and total out of 345. The score is a Cycore planning signal. It isn't a certification status, and it doesn't predict how long the work will take. Give every prompt under 3 an owner and a date, and carry them back into your GRC platform if you run one. The Annex A sample isn't scored. Use it to check your own control set, then compare against the full Annex A.

Download the PDF and work through it with your team.

ISO 27001 framework page

Read the case study

More Cycore resources

Next step

Talk to Cycore about your ISO 27001 gaps

This checklist is a Cycore diagnostic organized around the AICPA Trust Services Criteria. It is not an AICPA checklist and it is not legal or audit advice. Your auditor determines examination scope, evidence, and conclusions. Completing every item does not guarantee readiness or a particular audit outcome.