What is this Self‑Assessment Tool for? It is an Excel‑based gap analysis tool designed to help organisations prepare for ISO 27001:2022 certification by identifying compliance gaps across all 93 Annex A controls and clauses 4‑10.
Stop guessing your ISO 27001:2022 compliance status. This Self‑Assessment Tool gives you an auditor‑grade gap analysis across all 93 Annex A controls and clauses 4‑10.
Created by an ISO 27001 Certified Lead Auditor with 15+ years of experience protecting critical infrastructures, this Excel‑based tool goes far beyond a simple checklist. It tells you exactly where you stand, what evidence you are missing, and how to close each gap – step by step.
Why choose this tool?
• Auditor-Grade Expertise: Created by an ISO 27001 Certified Lead Auditor with 15+ years of experience protecting critical infrastructures.
• Turnkey Framework: Maps directly to all 93 ISO/IEC 27001:2022 Annex A controls and clauses 4‑10, from A.5.1 (Policies) and A.5.23 (Information security for use of cloud services) to A.8.34 (Technical compliance).
• Zero Risk: Macro‑free, stable Excel file tested on Office 2010+ – no crashes, no scripts, no hidden security risks.
What you get (macro‑free, stable Excel file, tested on Office 2010+):
• Complete control coverage – Every ISO 27001:2022 control is listed, from A.5.1 (Policies) to A.8.34 (Technical compliance). Each control includes a Compliance Status field (Compliant / Partially Compliant / Non‑Compliant).
• Evidence validation checklist – For every control, you will find a pre‑defined list of the exact evidence items an auditor will request (e.g., signed policies, access logs, training records). No more guessing what "proof" looks like.
• Purpose and format examples – Each evidence item is accompanied by its intended purpose and concrete format examples (e.g., "Standalone policy document signed by CEO"). This helps your team produce audit‑ready artifacts the first time.
• Remediation plan column – When a control is marked Non‑Compliant or Partially Compliant, the tool provides pre‑filled guidance on how to close the gap. You can assign an owner, set a due date, and track progress.
• Gap type classification – Identify whether the shortfall is due to missing documentation, lack of awareness, incomplete implementation, absent monitoring, or insufficient improvement processes.
• Dynamic results dashboard – The tool automatically calculates overall compliance percentages for ISO 27001 requirements (clauses 4‑10) and Annex A controls. Visual summaries are ready for management reviews and board presentations.
• Glossary and instructions – A built‑in Read Me sheet explains the logic, and a Glossary defines statuses (Compliant, Partially Compliant, Non-Compliant) and gap types (Documentation, Awareness, Implementation, Monitoring, Improvement). No training required.
Who is this for?
• Small and medium enterprises preparing for their first ISO 27001 certification
• Consultants who need a repeatable, credible gap analysis for clients
• Security practitioners who want to identify weaknesses before the official audit
• Already‑certified organisations conducting pre‑audit tests before surveillance audits or as part of ongoing ISMS maintenance
Who this is NOT for?
• Large enterprises looking for automated, integrated GRC platforms – this is a focused Excel tool, not a SaaS solution
• Users seeking a complete ISMS documentation suite – this is the Self‑Assessment Tool only
• Organisations tied to the old standard: Users looking specifically for the outdated ISO 27001:2013 framework – this tool is strictly mapped to the updated ISO 27001:2022 structure and its 93 controls
What this tool does not include – This listing is for the Self‑Assessment Tool only. It does not include the ISMS Manual, or full policy/procedure suite.
Immediate download – After purchase, you receive the editable Excel file. No waiting, no complex setup.
Got a question about the product? Email us at support@flevy.com or ask the author directly by using the "Ask the Author a Question" form. If you cannot view the preview above this document description, go here to view the large preview instead.
Source: Best Practices in ISO 27001, Audit Management Excel: ISO 27001:2022 Self‑Assessment Tool for Audits Excel (XLSX) Spreadsheet, Brahim Yahyaoui Consulting
|
Download our FREE Digital Transformation Templates
Download our free compilation of 50+ Digital Transformation slides and templates. DX concepts covered include Digital Leadership, Digital Maturity, Digital Value Chain, Customer Experience, Customer Journey, RPA, etc. |