Free ISO 27001 Gap Assessment
A structured session with a Sphere consultant to assess your current controls against ISO 27001 Annex A — and give you an honest picture of what certification would actually take.
Does this sound familiar?
Most organisations don't fail ISO 27001 because they don't care about security. They fail because they don't know where the gaps are until an auditor finds them.
You've been told you need ISO 27001 but don't know where to start
A procurement requirement or contract is pushing you towards certification
You've started the process but stalled on the risk assessment or SoA
You're in the NHS or public sector and DSPT obligations are tightening
You've had a previous audit finding and need to close it before the next review
A genuine assessment, not a scoping call
The ISO 27001 Gap Assessment is a structured 60-minute session with a Sphere consultant. We review your current controls against the Annex A requirements and give you a clear, prioritised picture of where you stand.
Book your assessment- A structured review of your current controls against ISO 27001 Annex A
- Identification of the gaps most likely to fail a Stage 1 or Stage 2 audit
- A realistic view of what certification would take — time, effort, and cost
- Plain-language findings: no jargon, no vendor agenda
- Delivered by a consultant with hands-on experience in complex, asset-intensive environments
The NHS Data Security and Protection Toolkit requires organisations to demonstrate compliance with the National Data Guardian's 10 data security standards. ISO 27001 provides the governance framework that underpins a credible DSPT submission — and increasingly, ICBs and NHS trusts are requiring it from suppliers. If you're working towards DSPT compliance or responding to a supplier assurance request, the gap assessment will tell you exactly where you stand.
Who this is for
The gap assessment is designed for organisations facing a certification decision — or a compliance obligation they can't defer.
NHS and public sector
DSPT obligations, Cyber Essentials Plus requirements, or ICB procurement conditions are driving the need for ISO 27001.
Asset-intensive operators
Utilities, transport, and infrastructure organisations where information security governance is increasingly a board-level requirement.
Pre-certification organisations
You know you need to certify but haven't started, or you've started and stalled. You need an independent view before committing further.
Post-incident or post-audit
A security incident, audit finding, or supplier questionnaire has surfaced gaps you need to close with evidence.
Book your free ISO 27001 Gap Assessment
Sessions are available on a limited basis. Use the booking page to select a time that works for you.
No obligation. No commitment. Just an honest assessment.
