Skip to content
Calcrivo

ISO 27001 Compliance Calculator

Score ISMS readiness against the 93 Annex A controls in their four themes plus clauses 4–10, and size the remaining certification gap.

Inputs

controls
controls
controls
controls
controls
controls

Clauses 9.2 and 9.3 — a certification body will ask for both records

ISMS Readiness Score

84.6%

Annex A Implementation

86.2%

Clause 4–10 Coverage

71.4%

Applicable Annex A Controls

87controls

Controls Not Yet Implemented

18controls

Indicative Remediation Effort

64person-days

Weakest Control Theme

A.8 Technological — 34 controls, the engineering half of Annex A

Certification Stage Verdict

Stage 1 documentation review achievable — close Annex A gaps before Stage 2

Step by step

  1. Values used

    A.5 organisational controls implemented (of 37) = 28 controls; A.6 people controls implemented (of 8) = 6 controls; A.7 physical controls implemented (of 14) = 11 controls; A.8 technological controls implemented (of 34) = 24 controls; Controls only partially implemented = 12 controls; Controls excluded with justification in the SoA = 6 controls; Clause 4–10 management-system requirements evidenced (of 7) = 5; Internal audit and management review completed = Yes

  2. ISO 27001 Compliance

    ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions.

  3. Theme coverage

    Theme coverage is scored separately against its own population: 37 organisational, 8 people, 14 physical and 34 technological controls.

  4. ISMS Readiness Score

    = 84.6

  5. Annex A Implementation

    = 86.2

  6. Clause 4–10 Coverage

    = 71.4

  7. Applicable Annex A Controls

    = 87 controls

  8. Controls Not Yet Implemented

    = 18 controls

  9. Indicative Remediation Effort

    = 64 person-days

How it works

The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A. Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.

Formulas

ISO 27001 Compliance

ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions.

93
Annex A controls in ISO/IEC 27001:2022
applicable
93 minus the controls excluded in the Statement of Applicability
partialCredit
Half credit for a control that is designed but not yet operating

Theme coverage

Theme coverage is scored separately against its own population: 37 organisational, 8 people, 14 physical and 34 technological controls.

orgPct
A.5 coverage
peoplePct
A.6 coverage
physPct
A.7 coverage
techPct
A.8 coverage

Frequently Asked Questions

How is ISO 27001 Compliance calculated?

ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions. The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A.

Why does ISO 27001 Compliance matter?

Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.

What values do I need to enter?

This calculator takes 8 inputs: A.5 organisational controls implemented (of 37), A.6 people controls implemented (of 8), A.7 physical controls implemented (of 14), A.8 technological controls implemented (of 34), Controls only partially implemented, Controls excluded with justification in the SoA, Clause 4–10 management-system requirements evidenced (of 7), Internal audit and management review completed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Does a high score mean I will pass certification?

No. Only an accredited certification body can decide that, and it decides on evidence sampled from your own records, not on a self-assessed count. Treat this as a planning estimate that tells you where the remaining work is and roughly how much of it there is.

How should I count a control that is excluded?

Exclude it only if the Statement of Applicability carries a written justification — typically that the risk does not apply to your scope. Excluded controls leave the denominator, which is why an aggressively trimmed SoA flatters the percentage and is the first thing an auditor tests.

You might also need