Black Shard

Insights6 October 2026

ISO 27001 readiness: the gap assessment, the Statement of Applicability and the first audit

ISO/IEC 27001 readiness runs in a fixed order: set the scope of the information security management system, assess the gaps against Clauses 4 to 10 and the 93 Annex A controls, write the risk treatment plan and the Statement of Applicability, then run the management system long enough to produce the records a certification auditor samples at stage two. The controls close on an engineering schedule. The management cycle needs months of operating history, and that history decides the audit date more often than the technical work.

What does ISO 27001 readiness involve?

ISO/IEC 27001:2022 certifies an information security management system, the ISMS: the policies, risk process, roles, controls and review cycle an organisation uses to manage information security. Readiness is the work between deciding to certify and passing the certification audit. It covers scoping, a gap assessment, risk assessment and treatment, control implementation, and enough operating time to generate evidence.

Certification is issued by a certification body. In Australia the body should be accredited by the Joint Accreditation System of Australia and New Zealand, JAS-ANZ, because procurement teams check accreditation and an unaccredited certificate fails that check. The certificate runs on a three-year cycle: an initial audit in two stages, surveillance audits in the following two years, then recertification.

Every certificate issued against the 2013 edition had to transition to the 2022 edition by 31 October 2025, so all live certificates now sit on ISO/IEC 27001:2022. An amendment in 2024 added climate change to the context clauses, asking organisations to decide whether it is a relevant issue for their ISMS.

How do you set the ISMS scope?

Scope decides cost and value at once. It names the information, systems, locations, people and processes inside the ISMS boundary, and the certificate states it. A software company certifying only its hosted product platform carries a lighter ISMS than one certifying the whole business, and a buyer can read the difference on the certificate.

The test is the question the buyer is asking. If enterprise customers want assurance over the platform that holds their data, a platform scope answers it. If a government panel asks for certification of the organisation, a narrow scope may fail the tender. Scope also has to hold up under audit: interfaces and dependencies with things outside the boundary, such as a shared Microsoft 365 tenant or an outsourced helpdesk, are documented and controlled.

What does a gap assessment measure?

A gap assessment reads the organisation against two sets of requirements. Clauses 4 to 10 are the management system: context and scope, leadership, planning including the risk method and objectives, support including competence and documented information, operation, performance evaluation through monitoring, internal audit and management review, and improvement. Every clause requirement is mandatory. Annex A is the reference control set, and each control is selected or excluded on the strength of the risk assessment.

Annex A in the 2022 edition has 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. Eleven were new in 2022, including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

Each requirement is rated as met, partly met or missing, with the evidence that exists today. The output is a prioritised gap list with an owner and an effort estimate per gap, ordered so that the management system starts running early.

AreaWhat is usually missingWhy it matters at audit
Clause 6.1, risk assessment and treatmentA repeatable method with criteria, and a register that changes over timeThe Statement of Applicability has to trace back to it
Clause 9.2, internal auditAn audit programme and a completed audit with findingsStage two samples the internal audit and what was done about it
Clause 9.3, management reviewA minuted review covering the required inputsThe auditor checks leadership saw the ISMS performance and decided on it
Annex A 5.19 to 5.23, suppliers and cloud servicesA supplier register with security requirements and review recordsMost organisations run on cloud services the ISMS has to govern
Annex A 8.9, configuration managementDefined baselines and evidence that systems match themNew in 2022 and rarely documented before readiness work

Where gap assessments most often find missing work

What goes in the Statement of Applicability?

The Statement of Applicability lists every Annex A control, whether it is included, the justification for including or excluding it, and whether it is implemented. Clause 6.1.3 requires it, and auditors read it as the organisation's own promise. Every included control has to exist and operate. Every exclusion has to be justified by the risk assessment or by scope.

Two mistakes recur. Excluding a control because it is hard, such as secure coding in an organisation that writes software, invites a nonconformity. Including every control by default commits the organisation to evidence for controls it never needed, such as physical security monitoring for premises outside the scope. A Statement of Applicability built from the risk register avoids both.

Which documents does the standard require?

The clauses name a set of documented information the ISMS must hold. An auditor checks each one exists, is controlled, and matches how the organisation runs. Most other documents, such as individual procedures, are required only where the organisation decides they are needed for the ISMS to work, and auditors accept short documents that are followed over long ones that are not.

  • The ISMS scope, Clause 4.3.
  • The information security policy, Clause 5.2.
  • The risk assessment process and the risk treatment process, Clauses 6.1.2 and 6.1.3.
  • The Statement of Applicability and the risk treatment plan, Clause 6.1.3.
  • The information security objectives, Clause 6.2.
  • Evidence of competence, Clause 7.2.
  • Operational planning and control records, and the results of risk assessments and risk treatment, Clauses 8.1 to 8.3.
  • Monitoring and measurement results, Clause 9.1.
  • The internal audit programme and audit results, Clause 9.2.
  • Management review results, Clause 9.3.
  • Nonconformities and corrective actions, Clause 10.2.

What does the auditor check at stage one and stage two?

Stage one reviews the documented ISMS: scope, policy, risk method and register, Statement of Applicability, objectives, and readiness for stage two. It often happens remotely and ends with a list of areas of concern. Stage two tests whether the ISMS operates as documented, by sampling records and interviewing the people who run the controls.

Stage two is where timing shows. The auditor will ask for the last internal audit, the management review that considered it, a quarterly access review, a change that went through change control, a supplier review, a training record, and a risk that moved on the register. Records cannot be backdated, so a management system switched on three weeks before the audit has nothing to sample. Most readiness programmes plan for at least one full internal audit and management review cycle before stage two.

How long does ISO 27001 readiness take?

The answer depends on the starting position more than the size of the organisation. A software company with infrastructure as code, single sign-on everywhere, documented change control and an Essential Eight programme already running has much of the technical evidence and needs the management system around it. An organisation with shared admin accounts, undocumented suppliers and no risk register has engineering work to do first.

The critical path is usually the operating record: the controls running long enough to produce the records stage two samples, an internal audit, and a management review. Booking stage two before those exist moves the risk to the audit. Organisations that also need SMB1001 or an Essential Eight maturity level can map one body of evidence to all three, since many Annex A technological controls overlap with the Essential Eight strategies.

Where does Black Shard fit?

Black Shard prepares organisations for certification, and an accredited certification body runs the audit, which keeps the readiness work and the audit independent. The team includes an ISO/IEC 27001:2022 Lead Auditor, and the firm's engineering side closes the technical gaps that usually stall readiness: identity, logging, configuration baselines, secure development and supplier controls in live systems.

ISO 27001 readiness runs as a defined programme with milestones toward the audit date: scope, gap assessment, risk register, Statement of Applicability, policy set, control implementation and a first internal audit. Where SMB1001 answers the buyer's question at lower cost, the SMB1001 and ISO 27001 comparison sets the two side by side. The starting point is a free 30-minute scoping call.

Tell us which framework you are preparing for.

Brisbane head office.

Open a briefinfo@blackshard.com.au