ISMS Gap & Remediation Tracker
Converts readiness findings into an owned, dated remediation plan sequenced against the certification audit date.
Available soon
- Format
- Excel
- Size
- 94 KB
- Length
- 9 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Gap Register
- Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Summary: set the as-at date (today's date, or =TODAY()), the planned Stage 1 and Stage 2 dates, the planned end of internal audit fieldwork and the management review date, and the number of requirements your readiness assessment covers. Replace every EXAMPLE value. |
| 2 | Lists: replace the EXAMPLE owners with your own (column 'OwnerList'); the Owner column offers them. |
| 3 | Gap Register: add one row for every requirement below Operating in the Certification Readiness Self-Assessment: its number (the title and blocker flag fill in), its readiness now (0, 1 or 2), the gap, the action, the owner and the weeks of work to put it in place. For a gap already In place, enter the date it went In place instead of weeks. |
| 4 | Agree the start and due dates with each owner (IS-08: "Every gap must have an owner and a date, sequenced so that blockers close before the Stage 2 date."). Use the forecast columns as the starting point: they assume the owner works through their gaps one at a time, blockers first. Column 'Due fits Stage 2?' says No when an agreed due date is later than the latest date the Stage 2 plan allows. |
| 5 | Update the tracker at least monthly (IS-10): status, weeks of work still left (reduce column J as work is done), readiness now, and the In place date once reached. Set the status to 'In place' and readiness to 2 when the action is done; set 'Closed' with the date only when the requirement is Operating — 3 months of records an auditor could sample. |
| 6 | Summary: read ISM-01 to ISM-04, the estimate and the owner workload. An overdue gap on the critical path is the first thing to raise with the executive sponsor. Nonconformities from the internal audit are corrective actions: record them here too, with the root cause in the Gap column (IS-09). |
| 7 | To remove the EXAMPLE: delete the EXAMPLE rows (whole table rows), replace the EXAMPLE owners on the Lists sheet and the EXAMPLE settings on the Summary sheet. The formulas keep working. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Readiness now: 0 Not started — Nothing exists yet. 1 Planned — Owner and approach agreed; not yet in place. 2 In place — Documented and working, but little or no record yet. A requirement at Operating (Working, with records covering at least [[3]] months, and an auditor could sample it.) is not a gap.
Status: Not started; In progress; In place (the action is done, records are building up); Closed (Operating, with the date). Overdue: not Closed and the agreed due date is before the as-at date.
Forecast. For a gap at 0 or 1: the as-at date plus the weeks of work of the owner's gaps up to and including this one, blockers first, then in the standard's order. For a gap at 2: its In place date. Forecast Operating: the forecast In place date plus 3 months (IS-05).
Latest In place for Stage 2: a blocker must be In place 3 months before the planned Stage 2 date (IS-05: "The ISMS must run for at least [[3]] months, producing records, before the Stage 2 audit."), so it can be Operating by then; any other gap by the Stage 2 date itself.
The estimate (Summary sheet) is the latest of (a) every gap In place, (b) the last blocker In place plus 3 months (IS-05), and (c) the internal audit and management review done (IS-06: "At least one full internal audit cycle and one management review must be completed before Stage 2."), the audit programme's forecast In place plus 4 weeks or your planned dates if later. Float is how many weeks a gap can slip before that date moves; a gap with float of 2 weeks or less is on the critical path. Weeks are calendar weeks.
EXAMPLE: a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30. Stage 1 is booked for 2027-01-18 and Stage 2 for 2027-03-01. Gaps already at In place are listed after the blockers with their In place date; GAP-006 (A.5.19) shows an overdue gap.
Tailoring — small organisation: one owner may hold most gaps. The forecast then shows plainly how long one person needs; either accept the date or bring in help. Merge small related gaps into one row if it keeps the tracker readable, but never merge a blocker into another gap.
Tailoring — regulated entity: certification to ISO/IEC 27001:2022 is evidence for a supervisor, not compliance with NIS2 or DORA in itself. Keep regulatory findings in the same tracker with their own reference in the notes, so one list is managed; a supervisor may ask for it.
Tailoring — IT run by a service provider: name as owner the person in your organisation who manages the provider, and record the provider's commitment (ticket or change reference) in the notes. The provider's delivery date is not your due date until you have agreed it.
Gap Register
One row per requirement below Operating. Yellow columns are yours; the rest is calculated. Blockers first (IS-08).
| Row | Gap ID | Requirement (clause or control) | Title (number and title only) | Blocker? | Readiness now (0–2) | Gap — what is missing | Action | Owner | Weeks of work left | In place since (readiness 2) | Agreed start | Agreed due | Status | Closed on | Forecast In place | Forecast Operating | Latest In place for Stage 2 | Due fits Stage 2? | Float (weeks) | Critical path? | Overdue? | Days overdue | Evidence, links and notes | Queue order (working) | Blocker In place (working) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | GAP-001 | 9.3.3 | Management review results | Yes | 1 | No review held, so no recorded decisions. | Confirm the date, attendees and minute-taker, and a template that records decisions and actions. | Chief Operating Officer | 1 | 30 Sep 2026 | 7 Oct 2026 | Not started | 7 Oct 2026 | 7 Jan 2027 | 1 Dec 2026 | Yes | 5.0 | No | 28 | 7 Oct 2026 | |||||
| EXAMPLE | GAP-002 | 6.2 | Information security objectives and planning to achieve them | Yes | 1 | Objectives drafted but not approved; no measure, owner or date for each. | Agree five to seven measurable objectives, each with an owner, a measure and a date; have top management approve them and communicate them. | Head of Information Security | 3 | 14 Sep 2026 | 21 Oct 2026 | In progress | 21 Oct 2026 | 21 Jan 2027 | 1 Dec 2026 | Yes | 3.0 | No | 11 | 21 Oct 2026 | |||||
| EXAMPLE | GAP-003 | 9.2.2 | Internal audit programme | Yes | 1 | Internal audit not started: the programme is drafted but not approved, and the contracted auditors are not yet confirmed. | Finish the audit programme so it covers every clause and the applicable controls before Stage 2, have the Chief Operating Officer approve it as sponsor, confirm the independent auditors (IS-07) and book the fieldwork. | Head of Information Security | 1 | 21 Sep 2026 | 28 Oct 2026 | In progress | 28 Oct 2026 | 28 Jan 2027 | 1 Dec 2026 | Yes | 2.0 | Yes | 25 | 28 Oct 2026 | |||||
| EXAMPLE | GAP-004 | 10.2 | Nonconformity and corrective action | Yes | 1 | Corrective actions are raised only for incidents; no procedure for nonconformities, root cause or effectiveness checks. | Approve a nonconformity and corrective action procedure (root cause, correction, corrective action, effectiveness check — IS-09) and start the log. | Head of Information Security | 2 | 28 Oct 2026 | 11 Nov 2026 | Not started | 11 Nov 2026 | 11 Feb 2027 | 1 Dec 2026 | Yes | 0.0 | Yes | 30 | 11 Nov 2026 | |||||
| EXAMPLE | GAP-005 | 6.1.3 | Information security risk treatment | Yes | 2 | In place since 2026-08-24; records cover less than 3 months. Statement of Applicability and risk treatment plan approved on 2026-08-24; treatment is under way. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Dec 2026 | Yes | 11.3 | No | 10 | 24 Aug 2026 | ||||
| EXAMPLE | GAP-006 | A.5.19 | Information security in supplier relationships | No | 1 | The Supplier Security Policy (P04 register SUP-001) is awaiting approval; supplier tiers not yet applied. | Obtain approval of the Supplier Security Policy (P04 register SUP-001), publish it, and tier the existing suppliers, using the supplier-assessment templates in the P06 pack. | Head of Procurement | 1 | 7 Sep 2026 | 25 Sep 2026 | In progress | 7 Oct 2026 | 7 Jan 2027 | 1 Mar 2027 | Yes | 18.1 | No | Overdue | 5 | EXAMPLE — started 2026-09-07; one week of work left at the as-at date. | 10049 | |||
| EXAMPLE | GAP-007 | 6.1.1 | General | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10008 | |||||
| EXAMPLE | GAP-008 | 8.1 | Operational planning and control | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10020 | |||||
| EXAMPLE | GAP-009 | A.5.6 | Contact with special interest groups | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10036 | |||||
| EXAMPLE | GAP-010 | A.5.11 | Return of assets | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | HR Director | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10041 | |||||
| EXAMPLE | GAP-011 | A.5.27 | Learning from information security incidents | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10057 | |||||
| EXAMPLE | GAP-012 | A.5.32 | Intellectual property rights | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Legal Counsel | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10062 | |||||
| EXAMPLE | GAP-013 | A.5.34 | Privacy and protection of PII | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Legal Counsel | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10064 | |||||
| EXAMPLE | GAP-014 | A.6.2 | Terms and conditions of employment | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | HR Director | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10069 | |||||
| EXAMPLE | GAP-015 | A.6.6 | Confidentiality or non-disclosure agreements | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | HR Director | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10073 | |||||
| EXAMPLE | GAP-016 | A.6.8 | Information security event reporting | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10075 | |||||
| EXAMPLE | GAP-017 | A.7.3 | Securing offices, rooms and facilities | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Office Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10078 | |||||
| EXAMPLE | GAP-018 | A.7.5 | Protecting against physical and environmental threats | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Office Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10080 | |||||
| EXAMPLE | GAP-019 | A.7.6 | Working in secure areas | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Office Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10081 | |||||
| EXAMPLE | GAP-020 | A.7.8 | Equipment siting and protection | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Office Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10083 | |||||
| EXAMPLE | GAP-021 | A.7.11 | Supporting utilities | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10086 | |||||
| EXAMPLE | GAP-022 | A.7.12 | Cabling security | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10087 | |||||
| EXAMPLE | GAP-023 | A.7.13 | Equipment maintenance | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10088 | |||||
| EXAMPLE | GAP-024 | A.8.17 | Clock synchronization | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10106 | |||||
| EXAMPLE | GAP-025 | A.8.34 | Protection of information systems during audit testing | No | 2 | In place since 2026-07-06; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-06 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 6 Jul 2026 | 6 Jul 2026 | 6 Oct 2026 | In place | 6 Jul 2026 | 6 Oct 2026 | 1 Mar 2027 | Yes | 31.4 | No | 10123 | |||||
| EXAMPLE | GAP-026 | A.5.8 | Information security in project management | No | 1 | Security is not a step in the project method. | Add a security checkpoint (risks and requirements) to the project start and go-live gates, with a short record. | Head of Engineering | 1 | 30 Sep 2026 | 7 Oct 2026 | Not started | 7 Oct 2026 | 7 Jan 2027 | 1 Mar 2027 | Yes | 18.1 | No | 10038 | ||||||
| EXAMPLE | GAP-027 | A.5.28 | Collection of evidence | No | 1 | No agreed way to collect and preserve evidence from an incident. | Write a one-page evidence-handling note (what to keep, who, how, chain of custody) and add it to the incident procedure. | Legal Counsel | 1 | 30 Sep 2026 | 7 Oct 2026 | Not started | 7 Oct 2026 | 7 Jan 2027 | 1 Mar 2027 | Yes | 18.1 | No | 10058 | ||||||
| EXAMPLE | GAP-028 | A.6.4 | Disciplinary process | No | 1 | The disciplinary procedure does not mention information security breaches. | Add security breaches to the disciplinary procedure and tell staff through the awareness programme. | HR Director | 1 | 30 Sep 2026 | 7 Oct 2026 | Not started | 7 Oct 2026 | 7 Jan 2027 | 1 Mar 2027 | Yes | 18.1 | No | 10071 | ||||||
| EXAMPLE | GAP-029 | 6.3 | Planning of changes | No | 1 | No agreed way to plan changes to the ISMS itself (scope, roles, processes). | Add a short ISMS change step to the steering group's agenda (the Chief Operating Officer chairs it): purpose, consequences, resources and who is responsible, recorded in the minutes. | Chief Operating Officer | 1 | 7 Oct 2026 | 14 Oct 2026 | Not started | 14 Oct 2026 | 14 Jan 2027 | 1 Mar 2027 | Yes | 17.1 | No | 10012 | ||||||
| EXAMPLE | GAP-030 | A.5.13 | Labelling of information | No | 0 | No labelling of classified information. | Apply the classification labels in the document and email tools, default to Internal, and brief staff. | Head of IT | 2 | 30 Sep 2026 | 14 Oct 2026 | Not started | 14 Oct 2026 | 14 Jan 2027 | 1 Mar 2027 | Yes | 17.1 | No | 10043 | ||||||
| EXAMPLE | GAP-031 | A.7.4 | Physical security monitoring | No | 1 | Camera coverage and alarm monitoring of the second office are not confirmed. | Agree monitoring of both offices with the landlord, confirm coverage of entrances and the equipment room, and record the check. | Office Manager | 2 | 30 Sep 2026 | 14 Oct 2026 | Not started | 14 Oct 2026 | 14 Jan 2027 | 1 Mar 2027 | Yes | 17.1 | No | 10079 | ||||||
| EXAMPLE | GAP-032 | 8.2 | Information security risk assessment | No | 2 | In place since 2026-07-20; records cover less than 3 months. The first full risk assessment was accepted by risk owners in July; the planned reassessment has not run yet. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10021 | |||||
| EXAMPLE | GAP-033 | A.5.3 | Segregation of duties | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10033 | |||||
| EXAMPLE | GAP-034 | A.5.9 | Inventory of information and other associated assets | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10039 | |||||
| EXAMPLE | GAP-035 | A.7.9 | Security of assets off-premises | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10084 | |||||
| EXAMPLE | GAP-036 | A.7.10 | Storage media | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10085 | |||||
| EXAMPLE | GAP-037 | A.8.1 | User endpoint devices | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10090 | |||||
| EXAMPLE | GAP-038 | A.8.3 | Information access restriction | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10092 | |||||
| EXAMPLE | GAP-039 | A.8.4 | Access to source code | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of Engineering | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10093 | |||||
| EXAMPLE | GAP-040 | A.8.19 | Installation of software on operational systems | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10108 | |||||
| EXAMPLE | GAP-041 | A.8.22 | Segregation of networks | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10111 | |||||
| EXAMPLE | GAP-042 | A.8.31 | Separation of development, test and production environments | No | 2 | In place since 2026-07-20; records cover less than 3 months. | Keep it running and keep its records; on 2026-10-20 check that an auditor could sample 3 months of them, then close. | Head of Engineering | 0 | 20 Jul 2026 | 20 Jul 2026 | 20 Oct 2026 | In place | 20 Jul 2026 | 20 Oct 2026 | 1 Mar 2027 | Yes | 29.4 | No | 10120 | |||||
| EXAMPLE | GAP-043 | 9.3.1 | General | No | 1 | No management review held or scheduled. | Schedule the first management review with top management after the internal audit report, and a yearly cycle after that. | Chief Operating Officer | 1 | 14 Oct 2026 | 21 Oct 2026 | Not started | 21 Oct 2026 | 21 Jan 2027 | 1 Mar 2027 | Yes | 16.1 | No | 10026 | ||||||
| EXAMPLE | GAP-044 | A.7.7 | Clear desk and clear screen | No | 1 | No clear desk and clear screen rule. | Publish the rule, set screen lock by policy on every device, and check the offices monthly. | Office Manager | 1 | 14 Oct 2026 | 21 Oct 2026 | Not started | 21 Oct 2026 | 21 Jan 2027 | 1 Mar 2027 | Yes | 16.1 | No | 10082 | ||||||
| EXAMPLE | GAP-045 | A.5.30 | ICT readiness for business continuity | No | 1 | Recovery objectives are set but the platform's recovery has not been tested. | Test the recovery of the production platform against its recovery objectives and record the result and the fixes. | IT Operations Manager | 4 | 30 Sep 2026 | 28 Oct 2026 | Not started | 28 Oct 2026 | 28 Jan 2027 | 1 Mar 2027 | Yes | 15.1 | No | 10060 | ||||||
| EXAMPLE | GAP-046 | A.5.31 | Legal, statutory, regulatory and contractual requirements | No | 1 | No register of legal, regulatory and contractual security requirements. | Build the register (including NIS2 duties and customer contract terms), with an owner for each and a yearly review. | Legal Counsel | 3 | 7 Oct 2026 | 28 Oct 2026 | Not started | 28 Oct 2026 | 28 Jan 2027 | 1 Mar 2027 | Yes | 15.1 | No | 10061 | ||||||
| EXAMPLE | GAP-047 | A.5.35 | Independent review of information security | No | 1 | No plan for independent review of the ISMS beyond the certification audit. | Record in the audit programme how and how often the ISMS is independently reviewed. | Chief Operating Officer | 1 | 21 Oct 2026 | 28 Oct 2026 | Not started | 28 Oct 2026 | 28 Jan 2027 | 1 Mar 2027 | Yes | 15.1 | No | 10065 | ||||||
| EXAMPLE | GAP-048 | A.8.11 | Data masking | No | 0 | Production data is copied to test without masking. | Mask personal and customer data in every copy made for testing, and block unmasked copies. | Head of Engineering | 3 | 7 Oct 2026 | 28 Oct 2026 | Not started | 28 Oct 2026 | 28 Jan 2027 | 1 Mar 2027 | Yes | 15.1 | No | 10100 | ||||||
| EXAMPLE | GAP-049 | 5.3 | Organizational roles, responsibilities and authorities | No | 2 | In place since 2026-08-03; records cover less than 3 months. Roles and responsibilities approved in August; control owners confirmed their roles in writing. | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Chief Operating Officer | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10007 | |||||
| EXAMPLE | GAP-050 | 7.4 | Communication | No | 2 | In place since 2026-08-03; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10016 | |||||
| EXAMPLE | GAP-051 | A.5.2 | Information security roles and responsibilities | No | 2 | In place since 2026-08-03; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10032 | |||||
| EXAMPLE | GAP-052 | A.5.4 | Management responsibilities | No | 2 | In place since 2026-08-03; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Chief Operating Officer | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10034 | |||||
| EXAMPLE | GAP-053 | A.5.18 | Access rights | No | 2 | In place since 2026-08-03; records cover less than 3 months. Quarterly access reviews started in August (see the P07 pack). | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10048 | |||||
| EXAMPLE | GAP-054 | A.8.2 | Privileged access rights | No | 2 | In place since 2026-08-03; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-03 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 3 Aug 2026 | 3 Aug 2026 | 3 Nov 2026 | In place | 3 Aug 2026 | 3 Nov 2026 | 1 Mar 2027 | Yes | 27.4 | No | 10091 | |||||
| EXAMPLE | GAP-055 | A.5.20 | Addressing information security within supplier agreements | No | 1 | Security clauses are missing from most key supplier contracts. | Add the security clauses for each supplier tier to the contracts of the Tier 1 suppliers at renewal, or by side letter. | Head of Procurement | 4 | 7 Oct 2026 | 4 Nov 2026 | Not started | 4 Nov 2026 | 4 Feb 2027 | 1 Mar 2027 | Yes | 14.1 | No | 10050 | ||||||
| EXAMPLE | GAP-056 | A.7.14 | Secure disposal or re-use of equipment | No | 1 | Disposal of laptops and drives is done by a supplier without certificates. | Require a destruction certificate for every disposed device and reconcile it with the asset inventory. | IT Operations Manager | 1 | 28 Oct 2026 | 4 Nov 2026 | Not started | 4 Nov 2026 | 4 Feb 2027 | 1 Mar 2027 | Yes | 14.1 | No | 10089 | ||||||
| EXAMPLE | GAP-057 | A.5.23 | Information security for use of cloud services | No | 2 | In place since 2026-08-10; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 10 Aug 2026 | 10 Aug 2026 | 10 Nov 2026 | In place | 10 Aug 2026 | 10 Nov 2026 | 1 Mar 2027 | Yes | 26.4 | No | 10053 | |||||
| EXAMPLE | GAP-058 | A.8.14 | Redundancy of information processing facilities | No | 2 | In place since 2026-08-10; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 10 Aug 2026 | 10 Aug 2026 | 10 Nov 2026 | In place | 10 Aug 2026 | 10 Nov 2026 | 1 Mar 2027 | Yes | 26.4 | No | 10103 | |||||
| EXAMPLE | GAP-059 | A.8.15 | Logging | No | 2 | In place since 2026-08-10; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 10 Aug 2026 | 10 Aug 2026 | 10 Nov 2026 | In place | 10 Aug 2026 | 10 Nov 2026 | 1 Mar 2027 | Yes | 26.4 | No | 10104 | |||||
| EXAMPLE | GAP-060 | A.8.21 | Security of network services | No | 2 | In place since 2026-08-10; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-10 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 10 Aug 2026 | 10 Aug 2026 | 10 Nov 2026 | In place | 10 Aug 2026 | 10 Nov 2026 | 1 Mar 2027 | Yes | 26.4 | No | 10110 | |||||
| EXAMPLE | GAP-061 | A.5.33 | Protection of records | No | 1 | Retention periods are not set for security records. | Set retention and protection for the ISMS and security records in the records schedule. | Legal Counsel | 2 | 28 Oct 2026 | 11 Nov 2026 | Not started | 11 Nov 2026 | 11 Feb 2027 | 1 Mar 2027 | Yes | 13.1 | No | 10063 | ||||||
| EXAMPLE | GAP-062 | A.8.9 | Configuration management | No | 1 | No approved baseline configurations for servers, laptops or cloud services. | Approve baseline configurations for the main system types, apply them, and check drift monthly. | Head of IT | 4 | 21 Sep 2026 | 11 Nov 2026 | In progress | 11 Nov 2026 | 11 Feb 2027 | 1 Mar 2027 | Yes | 13.1 | No | 10098 | ||||||
| EXAMPLE | GAP-063 | A.8.26 | Application security requirements | No | 1 | Security requirements are not written into feature specifications. | Add a security requirements section to the specification template and review it at design sign-off. | Head of Engineering | 2 | 28 Oct 2026 | 11 Nov 2026 | Not started | 11 Nov 2026 | 11 Feb 2027 | 1 Mar 2027 | Yes | 13.1 | No | 10115 | ||||||
| EXAMPLE | GAP-064 | A.5.12 | Classification of information | No | 2 | In place since 2026-08-17; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-17 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 17 Aug 2026 | 17 Aug 2026 | 17 Nov 2026 | In place | 17 Aug 2026 | 17 Nov 2026 | 1 Mar 2027 | Yes | 25.4 | No | 10042 | |||||
| EXAMPLE | GAP-065 | A.5.14 | Information transfer | No | 2 | In place since 2026-08-17; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-17 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 17 Aug 2026 | 17 Aug 2026 | 17 Nov 2026 | In place | 17 Aug 2026 | 17 Nov 2026 | 1 Mar 2027 | Yes | 25.4 | No | 10044 | |||||
| EXAMPLE | GAP-066 | 7.5.3 | Control of documented information | No | 1 | Two documents are past their review date (AUP-001, BKP-001) and one is awaiting approval (the Supplier Security Policy, P04 register SUP-001) in the policy register. | Complete the two overdue reviews, take the Supplier Security Policy (P04 register SUP-001) to its approver, and add a monthly check of review dates to the ISMS manager's routine. | Head of Information Security | 1 | 11 Nov 2026 | 18 Nov 2026 | Not started | 18 Nov 2026 | 18 Feb 2027 | 1 Mar 2027 | Yes | 12.1 | No | 10019 | ||||||
| EXAMPLE | GAP-067 | A.5.21 | Managing information security in the ICT supply chain | No | 1 | No check of the security of the software and cloud supply chain. | Ask Tier 1 technology suppliers about their own suppliers and components, and record the answers with the supplier assessment. | Head of Procurement | 2 | 4 Nov 2026 | 18 Nov 2026 | Not started | 18 Nov 2026 | 18 Feb 2027 | 1 Mar 2027 | Yes | 12.1 | No | 10051 | ||||||
| EXAMPLE | GAP-068 | A.8.6 | Capacity management | No | 1 | Capacity is watched but no thresholds or forecast exist. | Set capacity thresholds and alerts for the platform and review a quarterly forecast. | IT Operations Manager | 2 | 4 Nov 2026 | 18 Nov 2026 | Not started | 18 Nov 2026 | 18 Feb 2027 | 1 Mar 2027 | Yes | 12.1 | No | 10095 | ||||||
| EXAMPLE | GAP-069 | 4.4 | Information security management system | No | 2 | In place since 2026-08-24; records cover less than 3 months. The ISMS processes and how they connect are described in the ISMS manual; it has run as a whole only since late August. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10004 | |||||
| EXAMPLE | GAP-070 | 7.5.1 | General | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10017 | |||||
| EXAMPLE | GAP-071 | A.5.37 | Documented operating procedures | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10067 | |||||
| EXAMPLE | GAP-072 | A.8.24 | Use of cryptography | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10113 | |||||
| EXAMPLE | GAP-073 | A.8.25 | Secure development life cycle | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Engineering | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10114 | |||||
| EXAMPLE | GAP-074 | A.8.28 | Secure coding | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Engineering | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10117 | |||||
| EXAMPLE | GAP-075 | A.8.29 | Security testing in development and acceptance | No | 2 | In place since 2026-08-24; records cover less than 3 months. | Keep it running and keep its records; on 2026-11-24 check that an auditor could sample 3 months of them, then close. | Head of Engineering | 0 | 24 Aug 2026 | 24 Aug 2026 | 24 Nov 2026 | In place | 24 Aug 2026 | 24 Nov 2026 | 1 Mar 2027 | Yes | 24.4 | No | 10118 | |||||
| EXAMPLE | GAP-076 | A.8.27 | Secure system architecture and engineering principles | No | 1 | Architecture principles for security are not written down. | Write the secure architecture principles for the platform and apply them in design reviews. | Head of Engineering | 2 | 11 Nov 2026 | 25 Nov 2026 | Not started | 25 Nov 2026 | 25 Feb 2027 | 1 Mar 2027 | Yes | 11.1 | No | 10116 | ||||||
| EXAMPLE | GAP-077 | 7.2 | Competence | No | 2 | In place since 2026-09-01; records cover less than 3 months. Competence requirements for ISMS roles set in September; training records are in the HR system. | Keep it running and keep its records; on 2026-12-01 check that an auditor could sample 3 months of them, then close. | HR Director | 0 | 1 Sep 2026 | 1 Sep 2026 | 1 Dec 2026 | In place | 1 Sep 2026 | 1 Dec 2026 | 1 Mar 2027 | Yes | 23.3 | No | 10014 | |||||
| EXAMPLE | GAP-078 | 8.3 | Information security risk treatment | No | 1 | Treatment actions are under way but their completion and the residual risk are not recorded. | Record each completed treatment action and the residual risk it leaves in the risk register, and have risk owners accept it. | Head of Information Security | 2 | 18 Nov 2026 | 2 Dec 2026 | Not started | 2 Dec 2026 | 2 Mar 2027 | 1 Mar 2027 | Yes | 10.1 | No | 10022 | ||||||
| EXAMPLE | GAP-079 | A.5.22 | Monitoring, review and change management of supplier services | No | 1 | Supplier performance and changes are not reviewed for security. | Set a review interval per supplier tier and hold the first reviews of Tier 1 suppliers. | Head of Procurement | 2 | 18 Nov 2026 | 2 Dec 2026 | Not started | 2 Dec 2026 | 2 Mar 2027 | 1 Mar 2027 | Yes | 10.1 | No | 10052 | ||||||
| EXAMPLE | GAP-080 | A.8.10 | Information deletion | No | 1 | Customer data is not deleted on a set schedule after contracts end. | Define deletion periods for customer and internal data, automate the deletion job, and keep its log. | IT Operations Manager | 2 | 18 Nov 2026 | 2 Dec 2026 | Not started | 2 Dec 2026 | 2 Mar 2027 | 1 Mar 2027 | Yes | 10.1 | No | 10099 | ||||||
| EXAMPLE | GAP-081 | A.8.12 | Data leakage prevention | No | 0 | No controls to detect data leaving through email, storage or endpoints. | Turn on data loss prevention rules for customer data in email and cloud storage, in report-only mode first, then block. | Head of IT | 3 | 11 Nov 2026 | 2 Dec 2026 | Not started | 2 Dec 2026 | 2 Mar 2027 | 1 Mar 2027 | Yes | 10.1 | No | 10101 | ||||||
| EXAMPLE | GAP-082 | A.5.29 | Information security during disruption | No | 2 | In place since 2026-09-07; records cover less than 3 months. | Keep it running and keep its records; on 2026-12-07 check that an auditor could sample 3 months of them, then close. | IT Operations Manager | 0 | 7 Sep 2026 | 7 Sep 2026 | 7 Dec 2026 | In place | 7 Sep 2026 | 7 Dec 2026 | 1 Mar 2027 | Yes | 22.4 | No | 10059 | |||||
| EXAMPLE | GAP-083 | A.8.33 | Test information | No | 1 | No rules for selecting and protecting test data. | Set rules for choosing, protecting and deleting test data, together with the masking in A.8.11. | Head of Engineering | 2 | 25 Nov 2026 | 9 Dec 2026 | Not started | 9 Dec 2026 | 9 Mar 2027 | 1 Mar 2027 | Yes | 9.1 | No | 10122 | ||||||
| EXAMPLE | GAP-084 | A.5.36 | Compliance with policies, rules and standards for information security | No | 2 | In place since 2026-09-10; records cover less than 3 months. Security Exception & Waiver Standard EXC-STD approved on 2026-09-10. | Keep it running and keep its records; on 2026-12-10 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 10 Sep 2026 | 10 Sep 2026 | 10 Dec 2026 | In place | 10 Sep 2026 | 10 Dec 2026 | 1 Mar 2027 | Yes | 22.0 | No | 10066 | |||||
| EXAMPLE | GAP-085 | A.8.8 | Management of technical vulnerabilities | No | 2 | In place since 2026-09-10; records cover less than 3 months. Vulnerability & Exposure Management Standard VMS-001 approved on 2026-09-10 (see the P01 pack). | Keep it running and keep its records; on 2026-12-10 check that an auditor could sample 3 months of them, then close. | Head of IT | 0 | 10 Sep 2026 | 10 Sep 2026 | 10 Dec 2026 | In place | 10 Sep 2026 | 10 Dec 2026 | 1 Mar 2027 | Yes | 22.0 | No | 10097 | |||||
| EXAMPLE | GAP-086 | 7.3 | Awareness | No | 2 | In place since 2026-09-14; records cover less than 3 months. Awareness campaign launched in September; completion is tracked. | Keep it running and keep its records; on 2026-12-14 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 14 Sep 2026 | 14 Sep 2026 | 14 Dec 2026 | In place | 14 Sep 2026 | 14 Dec 2026 | 1 Mar 2027 | Yes | 21.4 | No | 10015 | |||||
| EXAMPLE | GAP-087 | A.6.3 | Information security awareness, education and training | No | 2 | In place since 2026-09-14; records cover less than 3 months. | Keep it running and keep its records; on 2026-12-14 check that an auditor could sample 3 months of them, then close. | Head of Information Security | 0 | 14 Sep 2026 | 14 Sep 2026 | 14 Dec 2026 | In place | 14 Sep 2026 | 14 Dec 2026 | 1 Mar 2027 | Yes | 21.4 | No | 10070 | |||||
| EXAMPLE | GAP-088 | 9.1 | Monitoring, measurement, analysis and evaluation | No | 1 | Measures are listed but not yet collected or reported; no one analyses the results. | Choose the measures, their owners and frequency; produce the first monthly report and take it to the steering group. | Head of Information Security | 3 | 2 Dec 2026 | 23 Dec 2026 | Not started | 23 Dec 2026 | 23 Mar 2027 | 1 Mar 2027 | Yes | 7.1 | No | 10023 | ||||||
| EXAMPLE | GAP-089 | A.8.16 | Monitoring activities | No | 1 | Logs are collected but not monitored for anomalies. | Define the alerts that matter, route them to the on-call rota, and record the weekly review. | Head of IT | 3 | 2 Dec 2026 | 23 Dec 2026 | Not started | 23 Dec 2026 | 23 Mar 2027 | 1 Mar 2027 | Yes | 7.1 | No | 10105 | ||||||
| EXAMPLE | GAP-090 | 9.2.1 | General | No | 1 | No check yet that each audit has set criteria and scope, an independent auditor and results reported to management. | After the first audit cycle, confirm each audit had criteria, scope and an independent auditor (IS-07) and that its results reached management; correct the programme where they did not. | Head of Information Security | 1 | 23 Dec 2026 | 30 Dec 2026 | Not started | 30 Dec 2026 | 30 Mar 2027 | 1 Mar 2027 | Yes | 6.1 | No | 10024 | ||||||
| EXAMPLE | GAP-091 | A.8.18 | Use of privileged utility programs | No | 1 | Use of privileged utility programs is not restricted. | List the utility programs that can override controls, restrict them to named administrators and log their use. | Head of IT | 1 | 23 Dec 2026 | 30 Dec 2026 | Not started | 30 Dec 2026 | 30 Mar 2027 | 1 Mar 2027 | Yes | 6.1 | No | 10107 | ||||||
| EXAMPLE | GAP-092 | 9.3.2 | Management review inputs | No | 1 | No template for the inputs the review must consider. | Prepare the review pack with every required input, from the Management Review Meeting Pack. | Head of Information Security | 1 | 30 Dec 2026 | 6 Jan 2027 | Not started | 6 Jan 2027 | 6 Apr 2027 | 1 Mar 2027 | Yes | 5.1 | No | 10027 | ||||||
| EXAMPLE | GAP-093 | A.8.23 | Web filtering | No | 1 | Web filtering is on in the offices only, not on remote devices. | Extend the web filter to every managed device wherever it connects. | Head of IT | 1 | 30 Dec 2026 | 6 Jan 2027 | Not started | 6 Jan 2027 | 6 Apr 2027 | 1 Mar 2027 | Yes | 5.1 | No | 10112 | ||||||
| EXAMPLE | GAP-094 | 10.1 | Continual improvement | No | 1 | Improvements are made but not recorded as such. | Keep an improvement log fed by audits, incidents, measures and suggestions, reviewed by the steering group. | Head of Information Security | 1 | 6 Jan 2027 | 13 Jan 2027 | Not started | 13 Jan 2027 | 13 Apr 2027 | 1 Mar 2027 | Yes | 4.1 | No | 10029 | ||||||
| EXAMPLE | GAP-095 | A.5.5 | Contact with authorities | No | 1 | No list of which authorities to contact, when, and who may do it. | Record the authorities (regulator, national incident response team, police, data protection authority), the route and who may contact them; link it from the incident procedure. | Head of Information Security | 1 | 13 Jan 2027 | 20 Jan 2027 | Not started | 20 Jan 2027 | 20 Apr 2027 | 1 Mar 2027 | Yes | 3.1 | No | 10035 | ||||||
| EXAMPLE | GAP-096 | A.5.7 | Threat intelligence | No | 1 | Threat information is read informally; nothing is recorded or acted on. | Choose two or three threat sources relevant to the platform, review them weekly, and record what was relevant and what was done. | Head of Information Security | 2 | 20 Jan 2027 | 3 Feb 2027 | Not started | 3 Feb 2027 | 3 May 2027 | 1 Mar 2027 | Yes | 1.1 | Yes | 10037 |
Summary
Tracker summary
The settings the forecasts use, the headline measures ISM-01 to ISM-04, the estimate of the earliest Stage 2 date — worked out as in the Certification Readiness Self-Assessment — and each owner's workload.
EXAMPLE: the example organisation's gaps, as at 2026-09-30. Delete the EXAMPLE rows and settings to use your own.
Settings
| As-at date | 30 Sep 2026 | EXAMPLE — the example's as-at date. Replace it with today's date, or type =TODAY(). Overdue and forecasts count from it. | ||||
| Planned Stage 1 audit | 18 Jan 2027 | EXAMPLE. For reference; the latest dates are set by Stage 2. | ||||
| Planned Stage 2 audit | 1 Mar 2027 | EXAMPLE. The date booked with your certification body. | ||||
| Internal audits end (planned) | 9 Dec 2026 | EXAMPLE. Leave blank if not yet planned. | ||||
| Management review (planned) | 6 Jan 2027 | EXAMPLE. After the audit report. | ||||
| Months of operation before Stage 2 (IS-05) | 3 | The [[3]] in IS-05. Keep it the same as in the Certification Readiness Self-Assessment. | ||||
| Check phase: audit programme in place to review done (weeks) | 4 | The Check phase in the ISO 27001 Implementation Methodology & Project Plan. | ||||
| Critical-path float (weeks) | 2 | A gap whose slip of this many weeks or fewer would move the estimate is on the critical path. | ||||
| Requirements assessed (clauses and applicable controls) | 122 | EXAMPLE — from the Certification Readiness Self-Assessment ('Everything assessed'). Used for ISM-02. | ||||
Headline measures
| Measure | Result | Target | ||||
|---|---|---|---|---|---|---|
| ISM-01 Blocking items operating | 3 of 8 blockers at Operating | All, before the Stage 2 date | ||||
| ISM-02 Requirements operating | 26 of 122 requirements at Operating (96 open gaps) | Rising monthly | ||||
| ISM-03 Gaps overdue | 1 gap overdue, 0 of them on the critical path | Zero on the critical path | ||||
| ISM-04 Weeks to certification | 20 weeks to the earliest Stage 2 date (planned: 22 weeks) | On or before the planned date | ||||
Estimated earliest Stage 2 date, step by step
| Step | Date | Working | ||||
|---|---|---|---|---|---|---|
| (a) Remaining work: every gap In place | 3 Feb 2027 | Last: A.5.7 (Head of Information Security), at the end of that owner's 18 weeks of work. | ||||
| (b) IS-05: last blocker In place + 3 months | 11 Feb 2027 | Last blocker In place: 10.2 on 2026-11-11, plus 3 months of records. | ||||
| (c) IS-06: internal audit and management review done | 6 Jan 2027 | Earliest end of the Check phase 2026-11-25; planned audit end 2026-12-09; planned review 2027-01-06. | ||||
| Estimated earliest Stage 2 date | 11 Feb 2027 | The latest of (a), (b) and (c): set by (b), IS-05. | ||||
| Planned Stage 2 date | 1 Mar 2027 | From the settings above. | ||||
| Verdict | On track: 2.6 weeks to spare before the planned Stage 2 date. | |||||
|---|---|---|---|---|---|---|
Gaps by status
| Status | All gaps | Blockers | Overdue | Critical path |
|---|---|---|---|---|
| Not started | 36 | 2 | 0 | 2 |
| In progress | 4 | 2 | 1 | 1 |
| In place | 56 | 1 | 0 | 0 |
| Closed | 0 | 0 | 0 | 0 |
Owner workload
| Owner | Open gaps | Weeks queued | Queue ends | On critical path | Overdue | Note |
|---|---|---|---|---|---|---|
| Chief Operating Officer | 6 | 4 | 28 Oct 2026 | 0 | 0 | |
| Head of Information Security | 27 | 18 | 3 Feb 2027 | 3 | 0 | Queue ends close to the estimate: this owner's gaps set the pace. |
| Head of IT | 22 | 14 | 6 Jan 2027 | 0 | 0 | |
| IT Operations Manager | 11 | 9 | 2 Dec 2026 | 0 | 0 | |
| Head of Procurement | 4 | 9 | 2 Dec 2026 | 0 | 1 | |
| HR Director | 5 | 1 | 7 Oct 2026 | 0 | 0 | |
| Head of Engineering | 10 | 10 | 9 Dec 2026 | 0 | 0 | |
| Office Manager | 6 | 3 | 21 Oct 2026 | 0 | 0 | |
| Legal Counsel | 5 | 6 | 11 Nov 2026 | 0 | 0 |
Owners come from the OwnerList on the Lists sheet. Weeks queued counts only gaps below In place; gaps already In place need time, not work.
Lists
| Status | ReadinessGap | OwnerList | Blockers | ReqId | ReqTitle |
|---|---|---|---|---|---|
| Not started | 0 | Chief Operating Officer | 4.3 | 4.1 | Understanding the organization and its context |
| In progress | 1 | Head of Information Security | 5.2 | 4.2 | Understanding the needs and expectations of interested parties |
| In place | 2 | Head of IT | 6.1.2 | 4.3 | Determining the scope of the information security management system |
| Closed | IT Operations Manager | 6.1.3 | 4.4 | Information security management system | |
| Head of Procurement | 6.2 | 5.1 | Leadership and commitment | ||
| HR Director | 9.2.2 | 5.2 | Policy | ||
| Head of Engineering | 9.3.3 | 5.3 | Organizational roles, responsibilities and authorities | ||
| Office Manager | 10.2 | 6.1.1 | General | ||
| Legal Counsel | 6.1.2 | Information security risk assessment | |||
| 6.1.3 | Information security risk treatment | ||||
| 6.2 | Information security objectives and planning to achieve them | ||||
| 6.3 | Planning of changes | ||||
| 7.1 | Resources | ||||
| 7.2 | Competence | ||||
| 7.3 | Awareness | ||||
| 7.4 | Communication | ||||
| 7.5.1 | General | ||||
| 7.5.2 | Creating and updating | ||||
| 7.5.3 | Control of documented information | ||||
| 8.1 | Operational planning and control | ||||
| 8.2 | Information security risk assessment | ||||
| 8.3 | Information security risk treatment | ||||
| 9.1 | Monitoring, measurement, analysis and evaluation | ||||
| 9.2.1 | General | ||||
| 9.2.2 | Internal audit programme | ||||
| 9.3.1 | General | ||||
| 9.3.2 | Management review inputs | ||||
| 9.3.3 | Management review results | ||||
| 10.1 | Continual improvement | ||||
| 10.2 | Nonconformity and corrective action | ||||
| A.5.1 | Policies for information security | ||||
| A.5.2 | Information security roles and responsibilities | ||||
| A.5.3 | Segregation of duties | ||||
| A.5.4 | Management responsibilities | ||||
| A.5.5 | Contact with authorities | ||||
| A.5.6 | Contact with special interest groups | ||||
| A.5.7 | Threat intelligence | ||||
| A.5.8 | Information security in project management | ||||
| A.5.9 | Inventory of information and other associated assets | ||||
| A.5.10 | Acceptable use of information and other associated assets | ||||
| A.5.11 | Return of assets | ||||
| A.5.12 | Classification of information | ||||
| A.5.13 | Labelling of information | ||||
| A.5.14 | Information transfer | ||||
| A.5.15 | Access control | ||||
| A.5.16 | Identity management | ||||
| A.5.17 | Authentication information | ||||
| A.5.18 | Access rights | ||||
| A.5.19 | Information security in supplier relationships | ||||
| A.5.20 | Addressing information security within supplier agreements | ||||
| A.5.21 | Managing information security in the ICT supply chain | ||||
| A.5.22 | Monitoring, review and change management of supplier services | ||||
| A.5.23 | Information security for use of cloud services | ||||
| A.5.24 | Information security incident management planning and preparation | ||||
| A.5.25 | Assessment and decision on information security events | ||||
| A.5.26 | Response to information security incidents | ||||
| A.5.27 | Learning from information security incidents | ||||
| A.5.28 | Collection of evidence | ||||
| A.5.29 | Information security during disruption | ||||
| A.5.30 | ICT readiness for business continuity | ||||
| A.5.31 | Legal, statutory, regulatory and contractual requirements | ||||
| A.5.32 | Intellectual property rights | ||||
| A.5.33 | Protection of records | ||||
| A.5.34 | Privacy and protection of PII | ||||
| A.5.35 | Independent review of information security | ||||
| A.5.36 | Compliance with policies, rules and standards for information security | ||||
| A.5.37 | Documented operating procedures | ||||
| A.6.1 | Screening | ||||
| A.6.2 | Terms and conditions of employment | ||||
| A.6.3 | Information security awareness, education and training | ||||
| A.6.4 | Disciplinary process | ||||
| A.6.5 | Responsibilities after termination or change of employment | ||||
| A.6.6 | Confidentiality or non-disclosure agreements | ||||
| A.6.7 | Remote working | ||||
| A.6.8 | Information security event reporting | ||||
| A.7.1 | Physical security perimeters | ||||
| A.7.2 | Physical entry | ||||
| A.7.3 | Securing offices, rooms and facilities | ||||
| A.7.4 | Physical security monitoring | ||||
| A.7.5 | Protecting against physical and environmental threats | ||||
| A.7.6 | Working in secure areas | ||||
| A.7.7 | Clear desk and clear screen | ||||
| A.7.8 | Equipment siting and protection | ||||
| A.7.9 | Security of assets off-premises | ||||
| A.7.10 | Storage media | ||||
| A.7.11 | Supporting utilities | ||||
| A.7.12 | Cabling security | ||||
| A.7.13 | Equipment maintenance | ||||
| A.7.14 | Secure disposal or re-use of equipment | ||||
| A.8.1 | User endpoint devices | ||||
| A.8.2 | Privileged access rights | ||||
| A.8.3 | Information access restriction | ||||
| A.8.4 | Access to source code | ||||
| A.8.5 | Secure authentication | ||||
| A.8.6 | Capacity management | ||||
| A.8.7 | Protection against malware | ||||
| A.8.8 | Management of technical vulnerabilities | ||||
| A.8.9 | Configuration management | ||||
| A.8.10 | Information deletion | ||||
| A.8.11 | Data masking | ||||
| A.8.12 | Data leakage prevention | ||||
| A.8.13 | Information backup | ||||
| A.8.14 | Redundancy of information processing facilities | ||||
| A.8.15 | Logging | ||||
| A.8.16 | Monitoring activities | ||||
| A.8.17 | Clock synchronization | ||||
| A.8.18 | Use of privileged utility programs | ||||
| A.8.19 | Installation of software on operational systems | ||||
| A.8.20 | Networks security | ||||
| A.8.21 | Security of network services | ||||
| A.8.22 | Segregation of networks | ||||
| A.8.23 | Web filtering | ||||
| A.8.24 | Use of cryptography | ||||
| A.8.25 | Secure development life cycle | ||||
| A.8.26 | Application security requirements | ||||
| A.8.27 | Secure system architecture and engineering principles | ||||
| A.8.28 | Secure coding | ||||
| A.8.29 | Security testing in development and acceptance | ||||
| A.8.30 | Outsourced development | ||||
| A.8.31 | Separation of development, test and production environments | ||||
| A.8.32 | Change management | ||||
| A.8.33 | Test information | ||||
| A.8.34 | Protection of information systems during audit testing |
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Gap | A requirement (clause requirement or applicable Annex A control) below Operating in the readiness assessment. |
| 0 — Not started | Nothing exists yet. |
| 1 — Planned | Owner and approach agreed; not yet in place. |
| 2 — In place | Documented and working, but little or no record yet. |
| 3 — Operating | Working, with records covering at least [[3]] months, and an auditor could sample it. |
| Blocker | One of the 8 clause requirements without which a Stage 2 audit cannot pass: 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2. Each must be Operating before the Stage 2 date. |
| Forecast In place | When the gap is expected to reach In place if its owner works through their gaps one at a time from the as-at date, blockers first. |
| Latest In place for Stage 2 | The last date the gap can reach In place and still allow the planned Stage 2 date: 3 months before it for a blocker (IS-05), the date itself for any other gap. |
| Float | Weeks a gap can slip before the estimated Stage 2 date moves. |
| Critical path | Gaps whose float is at or below the Summary setting. |
| Overdue | Not Closed, with an agreed due date before the as-at date. |
| Corrective action | An action to remove the cause of a nonconformity so it does not happen again (clause 10.2); record it here with its root cause (IS-09). |
| EXAMPLE | Values for the example organisation (a software services company with 240 staff in two offices, an NIS2 important entity) as at 2026-09-30. Delete them before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 10.2 — Nonconformity and corrective action | Gap Register: actions with owners, dates and a check that they worked; audit nonconformities recorded here (IS-09) |
| ISO/IEC 27001:2022 | Clause 6.1.3 — Information security risk treatment | Gap Register: the risk treatment plan's actions tracked to completion |
| ISO/IEC 27001:2022 | Clause 6.2 — Information security objectives and planning to achieve them | Summary: planning what will be done, by whom and when, towards the certification objective |
| NIST CSF 2.0 | ID.IM-03 — “Improvements are identified from execution of operational processes, procedures, and activities” | Gap Register: improvements identified while putting processes and controls in place |
| NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Whole workbook: improvements from the readiness assessment tracked to closure |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0