Campaign

Limited sessions available — offer closes 82d 12h 32m
No obligation · No sales pitch

Free ISO 27001 Gap Assessment

A structured session with a Sphere consultant to assess your current controls against ISO 27001 Annex A — and give you an honest picture of what certification would actually take.

60-minute sessionRemote or on-siteNo commitment required

Does this sound familiar?

Most organisations don't fail ISO 27001 because they don't care about security. They fail because they don't know where the gaps are until an auditor finds them.

You've been told you need ISO 27001 but don't know where to start

A procurement requirement or contract is pushing you towards certification

You've started the process but stalled on the risk assessment or SoA

You're in the NHS or public sector and DSPT obligations are tightening

You've had a previous audit finding and need to close it before the next review

What's included

A genuine assessment, not a scoping call

The ISO 27001 Gap Assessment is a structured 60-minute session with a Sphere consultant. We review your current controls against the Annex A requirements and give you a clear, prioritised picture of where you stand.

Book your assessment
  • A structured review of your current controls against ISO 27001 Annex A
  • Identification of the gaps most likely to fail a Stage 1 or Stage 2 audit
  • A realistic view of what certification would take — time, effort, and cost
  • Plain-language findings: no jargon, no vendor agenda
  • Delivered by a consultant with hands-on experience in complex, asset-intensive environments
NHS and DSPT organisations

The NHS Data Security and Protection Toolkit requires organisations to demonstrate compliance with the National Data Guardian's 10 data security standards. ISO 27001 provides the governance framework that underpins a credible DSPT submission — and increasingly, ICBs and NHS trusts are requiring it from suppliers. If you're working towards DSPT compliance or responding to a supplier assurance request, the gap assessment will tell you exactly where you stand.

Who this is for

The gap assessment is designed for organisations facing a certification decision — or a compliance obligation they can't defer.

NHS and public sector

DSPT obligations, Cyber Essentials Plus requirements, or ICB procurement conditions are driving the need for ISO 27001.

Asset-intensive operators

Utilities, transport, and infrastructure organisations where information security governance is increasingly a board-level requirement.

Pre-certification organisations

You know you need to certify but haven't started, or you've started and stalled. You need an independent view before committing further.

Post-incident or post-audit

A security incident, audit finding, or supplier questionnaire has surfaced gaps you need to close with evidence.

Limited sessions available

Book your free ISO 27001 Gap Assessment

Sessions are available on a limited basis. Use the booking page to select a time that works for you.

82days
12hrs
32min
14sec
Book your session now

No obligation. No commitment. Just an honest assessment.