Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 gap analysis: the decision that sets your budget

Before the gap analysis, your ISO 27001 budget is a guess. After it, it is an estimate. That is the entire value of the exercise, and it is why it comes before the budget rather than inside it. Nobody publishes a price for one, so here is what it covers, how to buy it, and how to tell a good one from an expensive one.

Updated July 2026

Why this page carries no price

Gap analyses are quoted per engagement and no consultant publishes a rate. A price range here would be invented, and it would be a strange thing to invent on the page whose entire argument is that you should stop estimating and go and find out.

The gap analysis is also the cheapest part of the programme and the one that decides the expensive parts. Ask two or three assessors for a proposal against an identical brief. You will learn more from how they scope the assessment than from what they charge for it.

What it is actually for

To set the scope

Scope is the largest lever you control over cost, timeline and audit time. The gap analysis is where you learn what a narrower scope would actually cost you commercially, while changing it is still free.

To size the work

How much of the ISMS already exists is the biggest difference between two similar companies, and it is unknowable until someone looks. This is the number your budget depends on.

To make a real decision

Go, adjust or wait. A gap analysis that cannot change your mind was a formality, and you paid for a report instead of a decision.

A gap analysis is not Stage 1

They look similar and answer a similar question, which is why people conflate them. Stage 1 of the certification audit establishes whether your ISMS is designed and documented well enough to be audited at Stage 2. A gap analysis asks the same thing, on your timetable, with no consequences.

The difference is what a bad answer costs. At gap analysis, a poor result is information and you adjust. At Stage 1, you have already chosen a body, agreed a scope, set a date and started paying for audit time, and remediation now sits between you and a Stage 2 that is already booked.

The standard does not require a gap analysis. It is optional in the way that checking your work before submitting it is optional. What Stage 1 and Stage 2 each do.

Delivery models, and what each is good for

Consultant led, on site

Good for: Complex or physical environments, multiple sites, anywhere the real process differs from the documented one.

Limit: The most expensive way to read documents. Worth it for what someone notices by walking around, not for the document review itself.

Consultant led, remote

Good for: Cloud-native and remote-first organisations where the evidence is all in systems anyway.

Limit: Interviews work fine remotely. What you lose is the incidental observation, which matters more in physical environments than in a SaaS business.

Platform assisted self assessment

Good for: Teams with real internal knowledge who need structure and a control framework rather than judgement.

Limit: A platform maps controls and collects evidence. It will not tell you your scope is wrong, and scope is the decision that matters most here.

Hybrid: self assess, expert review

Good for: Most organisations, most of the time. You do the legwork, an expert challenges the answers and the scope.

Limit: Only works if the internal assessment is honest. If your team rates everything green, an expert reviewing it inherits the same blind spot.

The choice is less about budget than about which constraint binds. If you lack knowledge of what auditors accept, buy judgement. If you lack structure, a platform supplies it. If you lack objectivity about your own controls, only an outsider fixes that, and no platform will. The three routes compared.

What a usable deliverable contains

Agree this list before the engagement starts, not when the report arrives. Any of these missing is work that quietly returns to you.

Control-by-control assessmentEvery control you consider applicable, rated against what evidence exists today, not against intent. Ratings that are all green are a finding in themselves.
Management system clausesThe ISMS requirements: context, leadership, planning, support, operation, performance evaluation, improvement. This is where unprepared organisations are weakest, because it is the part that cannot be bought.
A scope recommendationWhat should be inside the ISMS boundary and what should not, with the commercial consequences of each. The single most valuable page in the document.
Prioritised findingsWhat to do first, what depends on what, and what can wait. A list of gaps in Annex A order is a checklist, not a plan.
Effort estimates you can plan fromSpecific enough to resource. Vague ratings push the actual estimating work back onto you, which is what you paid to avoid.
What is genuinely fineA good assessment tells you where to stop as well as where to start. Over-engineering controls that were already adequate is a real and common cost.

How to tell a good assessment from an expensive one

Signs it was worth it

  • It made a specific scope recommendation and argued for it
  • It talked to the people who operate the process, not only the people who own the documents
  • Findings are prioritised and sequenced, with dependencies
  • It says where you are already fine and can stop
  • It refers to your systems, your data and your customers by name
  • It changed at least one thing you believed before it started

Signs it was not

  • It could have been written about any company in your sector
  • Document review only, with nobody interviewed
  • No scope recommendation, or scope treated as already settled
  • Every gap resolves to buying something
  • Effort ratings too vague to plan from
  • It arrived with a proposal for the remediation attached, priced

The decision it exists to inform

A gap analysis is not a document, it is a decision point. Three honest outcomes, and the exercise has failed if it could only ever have produced the first:

Go

The gaps are known and closeable, the scope is agreed, the resourcing is real. Request audit quotes on the scope and headcount you have now confirmed.

Adjust

The work is larger than assumed. Narrow the scope, move the date, or resource it properly. Usually the right answer, and the cheapest place to reach it.

Wait

The fundamentals are not there. Fix them as security work rather than certification work, and revisit. A certificate over an ISMS nobody runs fails in year two anyway.

Settle these before you request audit quotes

The gap analysis is where the two inputs that drive your audit quote get fixed. Leave either unresolved and every quote you collect is provisional.

  • The scope, in writing. Which services, systems, teams and locations sit inside the boundary. An ambiguous scope invites a defensive estimate from every body you ask.
  • The headcount, on the right definition. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. Contractors and freelancers inside the scope count. Undercounting here is the most common cause of a revised quote.

With both settled you can send an identical brief to several accredited bodies, which is the only way comparing their quotes means anything. How to source a defensible quote.

Frequently asked questions

How much does an ISO 27001 gap analysis cost?
It is quoted per engagement and no consultant publishes a rate, so a price range on this page would be assembled rather than reported. What decides the cost is the scope you ask them to assess, how many people they have to interview, and whether you want a report or a roadmap. Ask two or three assessors for a proposal against an identical brief. That gives you a real number for your organisation, which is the only number that matters, and it takes a few days.
What does an ISO 27001 gap analysis involve?
It assesses where you are today against what certification requires: the management system clauses of ISO 27001 and the Annex A controls you consider applicable. In practice that means document review, interviews with the people who actually operate the processes, and walkthroughs of systems. The output should tell you what is missing, what it will take to close, and what your scope ought to be. It is the exercise that converts a budget from a guess into an estimate.
Is a gap analysis required for ISO 27001?
No. The standard does not require one, and Stage 1 of the certification audit performs a similar function: it establishes whether your ISMS is designed and documented well enough to be audited at Stage 2. The argument for doing a gap analysis first is that Stage 1 is a poor place to discover you are not ready, because by then you have chosen a body, agreed a scope and set a date. A gap analysis is you finding out on your own timetable.
Can I do a gap analysis myself?
Yes, and it is a reasonable choice if someone internal genuinely knows what auditors accept as evidence. The constraint is not effort, it is judgement and objectivity: the hard part of a gap analysis is not listing controls, it is assessing honestly whether what you have would satisfy someone who does not already believe you. Teams routinely rate their own controls as implemented because they know the intent. An auditor sees only the evidence.
What should a gap analysis deliverable contain?
A control-by-control assessment against the controls you consider applicable, an assessment of the management system clauses, a clear recommendation on scope with the consequences of drawing it wider or narrower, findings prioritised so you know what to do first, and effort estimates specific enough to build a plan from. If it could have been written about another company, it tells you nothing. The scope recommendation is the most valuable part, because scope drives everything downstream.
How does a gap analysis change my audit cost?
Mainly through scope, which is the largest lever you control over audit time under ISO/IEC 27006-1:2024. A gap analysis is where you find out what tightening the scope would actually cost you commercially, and it is also where you should settle the headcount question, because the standard counts people doing work under your control inside the scope including contractors. Getting both right before you request audit quotes is the difference between a quote that holds and one revised after Stage 1.

Updated July 2026