Infosek
INFOSEK

ISO 27001 Checklist & Gap Assessment

Last updated: Jun 2026 Free — No login required 119 Controls

Covers: ISO/IEC 27001:2022 clauses  ·  All 93 Annex A controls  ·  ISMS certification readiness

Your assessment data is never sold or shared with any third party.
Start Self-Assessment
  • Home
  • Free Resources
  • ISO 27001 Checklist & Gap Assessment
ISO 27001 implementation readiness
How to Use

Answer each ISO 27001 control as Implemented, In Progress, Not Started, or Not Sure. The assessment then gives you a readiness score, top gaps, and a remediation report.

Control codes map to ISO/IEC 27001:2022. C means management system clause, A means Annex A control, and OPS means operational evidence needed to prove the control works. Example: C6.1.3 maps to risk treatment planning, while A8.24 maps to encryption use.

Note: This tool is a practical readiness checklist, not a certification audit. Final ISO 27001 certification readiness should be validated by a qualified auditor or consultant.

Step 1 — Answer each control question for your organisation

Overall
0 answered 0%
0% READY

0
Implemented
0
In Progress
0
Not Started
0
Not Sure
0
Total

Need help closing these ISO 27001 gaps?

Infosek helps fintechs, SaaS companies and regulated entities turn ISO 27001 requirements into working controls, policies and audit-ready evidence.