ISO 27001 gap analysis: the decision that sets your budget
Before the gap analysis, your ISO 27001 budget is a guess. After it, it is an estimate. That is the entire value of the exercise, and it is why it comes before the budget rather than inside it. Nobody publishes a price for one, so here is what it covers, how to buy it, and how to tell a good one from an expensive one.
Updated July 2026
Why this page carries no price
Gap analyses are quoted per engagement and no consultant publishes a rate. A price range here would be invented, and it would be a strange thing to invent on the page whose entire argument is that you should stop estimating and go and find out.
The gap analysis is also the cheapest part of the programme and the one that decides the expensive parts. Ask two or three assessors for a proposal against an identical brief. You will learn more from how they scope the assessment than from what they charge for it.
What it is actually for
To set the scope
Scope is the largest lever you control over cost, timeline and audit time. The gap analysis is where you learn what a narrower scope would actually cost you commercially, while changing it is still free.
To size the work
How much of the ISMS already exists is the biggest difference between two similar companies, and it is unknowable until someone looks. This is the number your budget depends on.
To make a real decision
Go, adjust or wait. A gap analysis that cannot change your mind was a formality, and you paid for a report instead of a decision.
A gap analysis is not Stage 1
They look similar and answer a similar question, which is why people conflate them. Stage 1 of the certification audit establishes whether your ISMS is designed and documented well enough to be audited at Stage 2. A gap analysis asks the same thing, on your timetable, with no consequences.
The difference is what a bad answer costs. At gap analysis, a poor result is information and you adjust. At Stage 1, you have already chosen a body, agreed a scope, set a date and started paying for audit time, and remediation now sits between you and a Stage 2 that is already booked.
The standard does not require a gap analysis. It is optional in the way that checking your work before submitting it is optional. What Stage 1 and Stage 2 each do.
Delivery models, and what each is good for
Consultant led, on site
Good for: Complex or physical environments, multiple sites, anywhere the real process differs from the documented one.
Limit: The most expensive way to read documents. Worth it for what someone notices by walking around, not for the document review itself.
Consultant led, remote
Good for: Cloud-native and remote-first organisations where the evidence is all in systems anyway.
Limit: Interviews work fine remotely. What you lose is the incidental observation, which matters more in physical environments than in a SaaS business.
Platform assisted self assessment
Good for: Teams with real internal knowledge who need structure and a control framework rather than judgement.
Limit: A platform maps controls and collects evidence. It will not tell you your scope is wrong, and scope is the decision that matters most here.
Hybrid: self assess, expert review
Good for: Most organisations, most of the time. You do the legwork, an expert challenges the answers and the scope.
Limit: Only works if the internal assessment is honest. If your team rates everything green, an expert reviewing it inherits the same blind spot.
The choice is less about budget than about which constraint binds. If you lack knowledge of what auditors accept, buy judgement. If you lack structure, a platform supplies it. If you lack objectivity about your own controls, only an outsider fixes that, and no platform will. The three routes compared.
What a usable deliverable contains
Agree this list before the engagement starts, not when the report arrives. Any of these missing is work that quietly returns to you.
How to tell a good assessment from an expensive one
Signs it was worth it
- It made a specific scope recommendation and argued for it
- It talked to the people who operate the process, not only the people who own the documents
- Findings are prioritised and sequenced, with dependencies
- It says where you are already fine and can stop
- It refers to your systems, your data and your customers by name
- It changed at least one thing you believed before it started
Signs it was not
- It could have been written about any company in your sector
- Document review only, with nobody interviewed
- No scope recommendation, or scope treated as already settled
- Every gap resolves to buying something
- Effort ratings too vague to plan from
- It arrived with a proposal for the remediation attached, priced
The decision it exists to inform
A gap analysis is not a document, it is a decision point. Three honest outcomes, and the exercise has failed if it could only ever have produced the first:
Go
The gaps are known and closeable, the scope is agreed, the resourcing is real. Request audit quotes on the scope and headcount you have now confirmed.
Adjust
The work is larger than assumed. Narrow the scope, move the date, or resource it properly. Usually the right answer, and the cheapest place to reach it.
Wait
The fundamentals are not there. Fix them as security work rather than certification work, and revisit. A certificate over an ISMS nobody runs fails in year two anyway.
Settle these before you request audit quotes
The gap analysis is where the two inputs that drive your audit quote get fixed. Leave either unresolved and every quote you collect is provisional.
- The scope, in writing. Which services, systems, teams and locations sit inside the boundary. An ambiguous scope invites a defensive estimate from every body you ask.
- The headcount, on the right definition. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. Contractors and freelancers inside the scope count. Undercounting here is the most common cause of a revised quote.
With both settled you can send an identical brief to several accredited bodies, which is the only way comparing their quotes means anything. How to source a defensible quote.