Stage 1 · Assessment

ISO 27001 Gap Analysis & Certification Roadmap

Your current state against ISO/IEC 27001:2022 and all 93 controls — with a realistic roadmap.

Duration:2–3 days
Price from:€4,900 excl. VAT
Enquirekontakt@maplee.de

from €4,900

excl. VAT · 2–3 days

Get in touch
Fixed price, fixed deliverable, fixed duration. Commission an implementation project within six months and we credit this assessment fee in full.

Most companies underestimate not the effort for technology, but for evidence, documentation, and management processes. In two to three days we assess your current state against ISO/IEC 27001:2022 and all 93 Annex A controls, and translate the result into a roadmap with numbers: what is missing, in what order, with how much internal and external effort, and by when.

Who it's for

  • Companies with a concrete certification goal, often triggered by a customer requirement or a tender
  • Companies whose ISO 27001:2013 certificate has lapsed and who need to plan the path back
  • NIS2-regulated companies for whom ISO 27001 is the pragmatic framework for compliance evidence
  • Companies with a grown, undocumented ISMS that needs to become audit-ready

The situation

Since 31 October 2025, certificates under ISO 27001:2013 are invalid — the transition period has expired. Those who missed it no longer need a delta audit but a full recertification with Stage 1 and Stage 2. At the same time, NIS2 makes a structured ISMS framework a de-facto necessity for tens of thousands of companies. Demand at certification bodies is rising accordingly — schedule early.

How it works

  1. 01

    Preparation — document review

    Existing policies, procedures, risk overviews, audit reports, management reviews.

  2. 02

    Day 1 — Management system (Clauses 4–10)

    Context of the organisation and interested parties · Leadership, security policy, roles · Planning, risk methodology, security objectives · Resources, competence, awareness, documented information · Operations · Performance evaluation, internal audit, management review · Improvement and nonconformity handling.

  3. 03

    Day 2 — Annex A: all 93 controls

    Assessment across the four theme areas — organisational, people, physical, and technological controls. Per control: maturity level, existing evidence, gap, and effort.

  4. 04

    Day 3 (optional) — Scope, SoA, and roadmap

    Definition of a defensible scope — this is where later effort is determined — plus creation of the draft SoA and calculation of the certification roadmap.

  5. 05

    Follow-up

    Report within ten working days, then a presentation of findings.

What you receive

ErgebnisForm
Gap report with maturity profile per clause and per control, including evidence statusPDF, 30–50 pages
Statement of Applicability (draft) — all 93 controls with applicability and justificationExcel, directly reusable
Certification roadmap — phases, milestones, internal and external effort, budget range, realistic target datePDF + Excel
Scope recommendation — with reasoning on why a narrow initial scope is often the faster pathin report
Guidance on selecting a certification body — what to look for, typical audit cost rangein report
Your control catalogue as a fillable register — importable to JiraCSV / Jira import

Details

Duration2 days (standard) or 3 days including scope workshop and draft SoA
ParticipantsCISO or project lead plus selected input from IT, HR, procurement, facilities
Formatremote or on-site
Pricefrom €4,900 excl. VAT · 3-day variant from €6,900 excl. VAT

Not included

The analysis assesses and plans. Not included are the creation of policies and evidence (that is the ISMS implementation), the internal audit per Clause 9.2, and the certification itself — which is conducted exclusively by an accredited certification body.

Frequently asked questions

With a clearly defined scope and existing IT hygiene: realistically six to twelve months. The roadmap gives you the number for your case, not an average.

Interested? Get in touch.

We typically respond within one working day.

kontakt@maplee.de