ISO 27001 Compliance Calculator
Score ISMS readiness against the 93 Annex A controls in their four themes plus clauses 4–10, and size the remaining certification gap.
Inputs
Clauses 9.2 and 9.3 — a certification body will ask for both records
ISMS Readiness Score
84.6%
Annex A Implementation
86.2%
Clause 4–10 Coverage
71.4%
Applicable Annex A Controls
87controls
Controls Not Yet Implemented
18controls
Indicative Remediation Effort
64person-days
Weakest Control Theme
A.8 Technological — 34 controls, the engineering half of Annex A
Certification Stage Verdict
Stage 1 documentation review achievable — close Annex A gaps before Stage 2
Step by step
Values used
A.5 organisational controls implemented (of 37) = 28 controls; A.6 people controls implemented (of 8) = 6 controls; A.7 physical controls implemented (of 14) = 11 controls; A.8 technological controls implemented (of 34) = 24 controls; Controls only partially implemented = 12 controls; Controls excluded with justification in the SoA = 6 controls; Clause 4–10 management-system requirements evidenced (of 7) = 5; Internal audit and management review completed = Yes
ISO 27001 Compliance
ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions.
Theme coverage
Theme coverage is scored separately against its own population: 37 organisational, 8 people, 14 physical and 34 technological controls.
ISMS Readiness Score
= 84.6
Annex A Implementation
= 86.2
Clause 4–10 Coverage
= 71.4
Applicable Annex A Controls
= 87 controls
Controls Not Yet Implemented
= 18 controls
Indicative Remediation Effort
= 64 person-days
How it works
The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A. Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.
Formulas
ISO 27001 Compliance
ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions.
- 93
- Annex A controls in ISO/IEC 27001:2022
- applicable
- 93 minus the controls excluded in the Statement of Applicability
- partialCredit
- Half credit for a control that is designed but not yet operating
Theme coverage
Theme coverage is scored separately against its own population: 37 organisational, 8 people, 14 physical and 34 technological controls.
- orgPct
- A.5 coverage
- peoplePct
- A.6 coverage
- physPct
- A.7 coverage
- techPct
- A.8 coverage
Frequently Asked Questions
How is ISO 27001 Compliance calculated?
ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions. The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A.
Why does ISO 27001 Compliance matter?
Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.
What values do I need to enter?
This calculator takes 8 inputs: A.5 organisational controls implemented (of 37), A.6 people controls implemented (of 8), A.7 physical controls implemented (of 14), A.8 technological controls implemented (of 34), Controls only partially implemented, Controls excluded with justification in the SoA, Clause 4–10 management-system requirements evidenced (of 7), Internal audit and management review completed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Does a high score mean I will pass certification?
No. Only an accredited certification body can decide that, and it decides on evidence sampled from your own records, not on a self-assessed count. Treat this as a planning estimate that tells you where the remaining work is and roughly how much of it there is.
How should I count a control that is excluded?
Exclude it only if the Statement of Applicability carries a written justification — typically that the risk does not apply to your scope. Excluded controls leave the denominator, which is why an aggressively trimmed SoA flatters the percentage and is the first thing an auditor tests.