ISO 27001 gap assessment — fixed price, delivered in 2–3 weeks
Know exactly where your organisation stands against ISO 27001, and what it will take to close the gap — before your next tender deadline, audit, or client due-diligence review.
I'll reply personally within 4 business hours — no sales pitch, just a clear read on your options.
Delivered by an ISO 27001 Lead Auditor & Implementer, former NSW Government Chief Risk Officer.
Built for organisations facing a real ISO 27001 deadline
Government suppliers
Tender or procurement requires ISO 27001 as a baseline vendor standard.
SaaS & tech companies
An enterprise client's security questionnaire now demands it before contract sign-off.
APRA-regulated & finance-adjacent
Aligning with CPS 234 through a structured ISMS.
What's included in your ISO 27001 gap assessment
- 01Structured gap analysis against ISO/IEC 27001:2022's full control set, mapped to your current environment
- 02Written gap report — plain-language findings, not just a compliance checklist
- 03Prioritised roadmap to certification, with realistic timeframes and cost estimate for each stage
- 04A 30-minute walkthrough call to talk through findings and next steps
- 05Essential Eight transition mapping — if you've already invested in Essential Eight controls, we show you how that work carries forward under ISO 27001 and the incoming ASD Essentials series
Why a gap assessment first — not a full ISMS build
Most ISO 27001 engagements go wrong because organisations buy a full implementation before anyone has properly scoped what's actually missing. That's how a $15,000 job turns into $80,000 of billable hours.
A ISO 27001 gap assessment gives you a clear, written picture of where you stand, what's genuinely required, and what it will cost to close — before you commit to anything bigger. The report is yours either way.
Built on real board-level experience, not theory
Dr Edward Phelps directed enterprise-wide risk and corporate strategy across 26 divisions as Chief Risk Officer for a NSW Government department, established the department's enterprise risk framework and governance policy suite from the ground up, and briefed Ministers and boards directly for over a decade — including managing strategic risk across a $2.6 billion reform portfolio. This isn't a template pulled from a course. It's a system built and used at genuine scale.
Common questions
How much does a ISO 27001 gap assessment cost?
Fixed-price, quoted after a free 20-minute scoping call based on your organisation's size and current environment. No hourly billing surprises.
How long does full ISO 27001 certification take after the gap assessment?
Typically 4–9 months from gap assessment to certificate, depending on your starting maturity and scope.
We already have Essential Eight controls in place — does that help?
Yes. With the Essential Eight being retired over the next two years in favour of ASD's new Essentials series, we map your existing investment directly into your ISO 27001 roadmap so none of it is wasted.
Do you also deliver the full ISMS build, not just the assessment?
Yes — many clients continue into a fractional CISO engagement to implement the roadmap. This is a popular no waste service. Start my 90-day sprint →
Get a clear, written picture of your ISO 27001 gap — in 2–3 weeks
Request your fixed-price quote
Three quick fields — I'll come back to you personally within 4 business hours.
No sales pitch. Just a clear read on your options.