Score ISMS readiness against the 93 Annex A controls in their four themes plus clauses 4–10, and size the remaining certification gap.
The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A. Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.
ISO 27001 Compliance
ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions.
Theme coverage
Theme coverage is scored separately against its own population: 37 organisational, 8 people, 14 physical and 34 technological controls.
ISMS readiness = 0.60 × Annex A implementation + 0.25 × clause 4–10 coverage + 0.15 × management-system evidence, where Annex A implementation = (fully implemented + 0.5 × partial) ÷ applicable controls and applicable = 93 − justified exclusions. The 2022 revision collapsed the old 114 controls into 93 across four themes, so a credible percentage has to be measured against 93 minus whatever you excluded with justification in the Statement of Applicability. Partial controls earn half credit because a documented-but-unoperated control fails a Stage 2 test, and the clause 4–10 requirements are weighted separately because certification is granted against the management system, not against Annex A.
Certification bodies fail ISMS projects on the management system — scope, risk assessment, internal audit — far more often than on a missing technical control, and this number shows which of the two is actually behind. It is a management estimate for planning, not a certification decision.
This calculator takes 8 inputs: A.5 organisational controls implemented (of 37), A.6 people controls implemented (of 8), A.7 physical controls implemented (of 14), A.8 technological controls implemented (of 34), Controls only partially implemented, Controls excluded with justification in the SoA, Clause 4–10 management-system requirements evidenced (of 7), Internal audit and management review completed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. Only an accredited certification body can decide that, and it decides on evidence sampled from your own records, not on a self-assessed count. Treat this as a planning estimate that tells you where the remaining work is and roughly how much of it there is.
Exclude it only if the Statement of Applicability carries a written justification — typically that the risk does not apply to your scope. Excluded controls leave the denominator, which is why an aggressively trimmed SoA flatters the percentage and is the first thing an auditor tests.