" /> ISO 27001 Gap Analysis Tool 2026: free self-assessment with cost to certify
Guide

ISO 27001 Gap Analysis Tool: Free Self-Assessment Against Clauses 4 to 10 and Annex A (2026)

Free ISO 27001:2022 gap analysis: 20 questions on the management system and the Annex A themes, a readiness score, your biggest gaps and what closes each one with a price and a timeline to certification.

Updated · Oct 2026 By ITSECOPS Free · No signup

Free tool · Updated 6 October 2026

In short: Free ISO 27001:2022 gap analysis: 20 questions on the management system and the Annex A themes, a readiness score, your biggest gaps and what closes each one with a price and a timeline to certification.

ISO 27001:2022 is now the baseline customers in the EU, the UK and the Gulf write into contracts, and NIS2 supervisors in several member states accept a current certificate as evidence for Article 21. The transition from the 2013 edition closed on 31 October 2025, so audits now run against the 93 Annex A controls in four themes; most first-time SMB certifications take four to six months when the risk assessment and the Statement of Applicability are done properly first.

How it works

  1. Answer 20 questions: Six on the management system clauses, fourteen on the Annex A themes auditors sample first. About four minutes.
  2. See your score: A readiness percentage, a bar per theme and your three biggest gaps, free and without an email.
  3. Unlock the plan: The full table: what closes each gap, the ITSECOPS fixed-fee price, the typical consultancy price, totals and a realistic timeline, plus a copy by email within one business day.

Frequently asked questions

How much does ISO 27001 certification cost?

Three buckets: implementation support (US and EU consultancies typically $15,000 to $40,000; the ITSECOPS fixed-fee remote model runs 30 to 50 percent below), the certification body audit ($5,000 to $15,000, paid to the body), and annual surveillance audits of $3,000 to $8,000. The tool prices the first bucket per gap.

How long does it take?

Four to six months for a company under 250 people that starts with the risk assessment and the Statement of Applicability; a fintech case study on this site reached certification in four months with a fractional CISO.

Does the tool cover the 2022 Annex A?

Yes. The questions follow the four 2022 themes (organizational, people, physical, technological) and the controls auditors test first, such as A.8.7, A.8.8, A.8.13, A.8.15 and A.8.16.

Can VEDVERA hold the ISMS?

Yes. VEDVERA GRC runs inside your Microsoft 365 tenant with a live Statement of Applicability, risk register and evidence library; there are no per-user fees.

Related

ISO 27001 implementation services · ISO 27001 implementation plan · ISO 27001 vs SOC 2 · VEDVERA GRC platform · Client testimonials

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation
Popular guides and pricingCybersecurity price comparison 2026  ·  EDR pricing per endpoint  ·  MDR pricing per device  ·  Veeam vs Acronis vs Datto  ·  Remote IT support pricing  ·  White-label help desk pricing  ·  24/7 SOC monitoring cost  ·  Top MDR providers  ·  White-label NOC and SOC for MSPs  ·  Top ISO 27001 consulting firms  ·  ISO 27001 implementation plan  ·  CMMC readiness services  ·  Top CMMC consulting firms  ·  ISO 42001 AI certification  ·  Global laptop provisioning and MDM  ·  Security stack recommender  ·  Managed IT services Norway