Skip to main content
Portfolio Case Study — 2026

ISO 27001 Gap Assessment
Certification Readiness

CloudBridge Technologies Inc. | SaaS Sector
Comprehensive gap assessment against ISO 27001:2022 for a high-growth supply chain SaaS platform. Full Annex A control evaluation, Statement of Applicability, risk assessment, and 12-month remediation roadmap.

ISO 27001:2022 ISO 27002:2022 NIST CSF 2.0
0[1] Annex A Controls Assessed
0[2] Findings Identified
0[3] ISMS Maturity (1-4)
0[4] Critical Gaps

Engagement Background

A comprehensive ISO 27001:2022 gap assessment for a high-growth SaaS supply chain visibility platform preparing for EU market expansion.

The Client: CloudBridge Technologies Inc. is a supply chain visibility platform that provides real-time tracking, predictive analytics, and vendor collaboration tools for enterprise logistics operations. Founded in 2019 and headquartered in Atlanta, GA, the company has grown to 250 employees with $35M ARR and over 500 customers across North America.

The Challenge: CloudBridge was preparing to expand into the European Union market, where enterprise customers increasingly require ISO 27001 certification as a prerequisite for vendor engagement. The organization had no formal Information Security Management System (ISMS) in place, no documented Statement of Applicability (SoA), and limited visibility into their compliance posture against the ISO 27001:2022 standard. With a lean security team of 3 people and rapid product development cycles, the organization needed a clear, prioritized path to certification.

My Role: Lead GRC Consultant — responsible for the full gap assessment lifecycle: engagement scoping, stakeholder interviews, Annex A control evaluation, SoA development, risk assessment, findings documentation, and remediation roadmap. I produced the complete assessment package over a 6-week engagement.

The Approach: A structured 4-phase methodology combining document review, personnel interviews, technical verification, and process observation. All 93 Annex A controls were assessed against a 4-level maturity scale with evidence-backed ratings. Findings were risk-rated and mapped to business impact to drive executive decision-making.

Framework

ISO 27001:2022

Duration

6 Weeks (Q3 2026)

Organization Size

250 Employees • 6 Departments

Compliance Driver

EU Market Expansion

Platform

SaaS Supply Chain Visibility

Annual Revenue

$35M ARR • 500+ Customers

Interviews Conducted

22 Stakeholder Sessions

Documents Reviewed

45+ Artifacts

How the Gap Assessment Was Conducted

A structured 6-week engagement combining document analysis, personnel interviews, technical verification, and process observation across all 93 Annex A controls.

01

Plan & Scope

Engagement charter, ISMS scope definition, stakeholder mapping, document request list, communication plan, project timeline

02

Discover & Document

Document collection (45+ artifacts), 22 stakeholder interviews, process walkthroughs, asset and data flow mapping

03

Assess & Evaluate

93 Annex A control ratings, maturity scoring (1-4), SoA development, risk assessment, evidence verification

04

Report & Roadmap

48 findings, gap analysis, Statement of Applicability, risk treatment plan, 12-month remediation roadmap, executive report

Four Methods of Verification

Every control was assessed using multiple independent evidence sources to ensure findings were corroborated and defensible.

Document Review

Policies, procedures, security architecture docs, contracts, and training records evaluated against ISO 27001:2022 requirements

Personnel Interviews

22 structured sessions across Executive, Engineering, DevOps, Product, HR, Legal, and IT roles using role-specific question banks

Technical Verification

Configuration review, access control testing, log analysis, encryption verification, network segmentation checks, and cloud security review

Process Observation

Change management, incident response, access provisioning, vendor onboarding, and development lifecycle walkthroughs

Annex A Theme Breakdown

All 93 Annex A controls assessed across 4 themes with maturity ratings and implementation status.

Theme 2022 Ref. Controls Implemented Partially Not Impl. N/A Maturity
Organizational5.1–5.37371413821.4
People6.1–6.8834102.0
Physical7.1–7.141466202.5
Technological8.1–8.34341291031.9

Maturity scored on a 1-4 scale (1=Initial, 2=Defined, 3=Managed, 4=Optimized). Target maturity for certification: 3.0 across all themes.

Assessment Findings Summary

48 findings identified across 4 Annex A themes. Each finding includes risk rating, evidence references, business impact, and specific actionable recommendations.

5 Critical
14 High
18 Medium
11 Low
Critical No Formal ISMS or Statement of Applicability Theme 1: Organizational

The organization operates without a documented ISMS framework. No Statement of Applicability exists, no information security policy framework is formally established, and there is no defined scope for the certification boundary. This is a foundational requirement for ISO 27001 certification and must be addressed before any formal certification audit.

Critical No Formal Risk Assessment or Risk Treatment Process Theme 1: Organizational

Risk management is performed informally within engineering teams using ad hoc methods. There is no documented risk assessment methodology, no risk register, no risk owner assignments, and no formal risk treatment plan. ISO 27001 requires a systematic risk assessment process as a core certification requirement.

Critical No Supplier Security Assessment Program Theme 1: Organizational

The organization relies on 15+ third-party vendors and sub-processors for critical infrastructure (cloud hosting, CDN, monitoring, payment processing) but has no formal supplier security assessment process. No vendor risk classification, no security requirements in contracts, and no ongoing monitoring of supplier security posture.

Critical No Business Continuity or Disaster Recovery Plan Theme 1: Organizational

The organization has no documented business continuity plan, no disaster recovery plan, and no BIA (Business Impact Analysis). While the platform has some technical redundancy (multi-AZ deployment), there are no documented procedures, no RTO/RPO definitions, and no testing or exercising of recovery capabilities.

Critical No Formal Incident Response Process Theme 1: Organizational

Incident detection relies on engineering alerts with no formal incident response plan, no defined incident categories, no escalation matrix, and no post-incident review process. The organization has no documented incident response procedures and no tabletop exercises have been conducted.

Critical No Asset Management or Classification Process Theme 1: Organizational

Information assets are not inventoried, classified, or assigned owners. There is no asset classification scheme, no handling procedures for different classification levels, and no asset lifecycle management process. This impacts multiple dependent controls including access control, media handling, and disposal.

High No Formal Access Review Process Theme 4: Technological

User access provisioning and de-provisioning is handled informally. No periodic access reviews are conducted. Former employee accounts remain active in several systems. No segregation of duties analysis has been performed for sensitive roles.

High No Cryptography Policy or Key Management Theme 4: Technological

While TLS is used for data in transit and some encryption is applied at rest, there is no documented cryptography policy, no key management procedure, and no inventory of cryptographic controls. Certificate management is ad hoc with no centralized oversight.

All 48 findings are documented in the full Findings Register with evidence references, risk ratings, and remediation recommendations.

12-Month Certification Path

A phased remediation plan organized into 4 phases over 12 months, prioritized by certification impact and implementation effort.

Phase 1

Foundation

Months 1-4
  • Define ISMS scope and certification boundary
  • Develop information security policy framework
  • Conduct formal risk assessment and develop risk treatment plan
  • Create Statement of Applicability (SoA)
  • Establish asset inventory and classification scheme
  • Deploy access review and recertification process
  • Implement incident response plan and procedures
Phase 2

Build & Implement

Months 5-8
  • Develop and implement supplier security assessment program
  • Create business continuity and disaster recovery plans
  • Conduct BIA and define RTO/RPO for critical services
  • Implement cryptography policy and key management procedures
  • Deploy formal change management process
  • Establish security awareness and training program
  • Implement vulnerability management and patching process
Phase 3

Mature & Certify

Months 9-12
  • Conduct internal audit (Stage 1 readiness)
  • Management review and ISMS performance evaluation
  • Remediate internal audit findings
  • Engage certification body for Stage 1 audit
  • Remediate Stage 1 findings
  • Stage 2 certification audit
  • Continual improvement framework and KPI monitoring
Phase 4

Sustain & Improve

Months 9-12+
  • Internal audit program and management review cycle
  • Corrective action tracking and closure
  • Continual improvement framework (KPIs, metrics, reporting)
  • Supplier security monitoring and re-assessment
  • Tabletop exercises and incident response testing
  • BCP/DR plan testing and update cycle
  • Pre-certification readiness assessment

Assessment Metrics & Analytics

Quantitative analysis of control implementation status, findings distribution, and maturity across all Annex A clauses.

Control Status Distribution

93 Annex A controls: 35 Implemented (38%), 32 Partially (34%), 21 Not Implemented (23%), 5 N/A (5%)

Findings by Severity

48 total findings: 5 Critical, 14 High, 18 Medium, 11 Low

Findings by Clause

Findings distribution across ISO 27001:2022 Annex A themes

Maturity by Clause

Current maturity (amber) vs. target maturity of 3.5 (blue) for certification readiness

Project Deliverables

Complete assessment package available on GitHub. All deliverables follow consulting-quality standards with version control and professional formatting.

Project Planning Document
Company Profile & Context
ISMS Scope Definition
System Boundary Document
Asset Inventory
Data Flow Diagram
Applicable Requirements
Assessment Methodology
Evidence Collection Plan
Audit Checklist
Interview Questions
Technical Verification Plan
Control Assessment Matrix
Statement of Applicability
Findings Register
Gap Analysis & Remediation Plan
Risk Assessment & Treatment Plan
Final Gap Assessment Report

Full Project Repository

All 18+ deliverables are available in the project directory, organized by phase with consistent naming conventions.


View on GitHub Back to GRC Projects

References

  1. Annex A Control Matrix — Full assessment of all 93 ISO 27001:2022 Annex A controls across 4 themes with evidence-backed maturity ratings.
  2. Findings Register — 48 findings documented with risk ratings (5 Critical, 14 High, 18 Medium, 11 Low), root cause analysis, and remediation recommendations.
  3. Maturity Assessment — 4-level maturity scoring (0-3) across all controls with evidence collection plan and stakeholder interview records.
  4. Statement of Applicability — Scope definition document mapping ISO 27001:2022 requirements to organizational context.

Full deliverables available in the project repository.