Annex A Control Assessment
7 Days

All 93 Annex A controls assessed, single scope, findings report rated by severity and effort.
All 93 Annex A controls assessed, single scope, findings report rated by severity and effort.
An ISO/IEC 27001:2022 gap analysis that tells you precisely which of the 93 Annex A controls you meet, which you do not, and what closing each one will actually take. Delivered by an accredited ISO 27001 Lead Auditor who has built a full ISMS from scope definition through Statement of Applicability, and who has carried an organization to a held certificate.
Organizations usually discover their gaps in the wrong order: during the certification audit, at the most expensive possible moment. A gap analysis moves that discovery forward to where it is still cheap to act on.
What you receive:
Control-by-control assessment across all 93 Annex A controls.
Clause 4 through 10 management system review.
Findings rated by severity and by effort to close.
A prioritized remediation sequence with realistic timelines.
Draft Statement of Applicability structure.
How I work. I assess what operates, not what is written down. A control with a policy and no evidence is a finding, and I record it as one, because that is exactly how a certification auditor will treat it. Findings are rated on two axes, severity and effort, so you can sequence the cheap high-impact work first.
Who this is for. Organizations targeting certification, teams that inherited an ISMS and do not know its true state, and businesses that have been told by a client or an insurer to get certified and need to know what that will cost before committing. Remote assessment based on documentation review and interviews.
7 Days
14 Days
21 Days

21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.
21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.








Terms and conditions apply