ISO 27001 Gap Assessment Checklist for SaaS Companies
A SaaS gap assessment should test governance and technical evidence across the actual service boundary.
Start with the service boundary
Define which legal entity, product, cloud environment, offices, people and supporting services are in the proposed ISMS scope. A vague scope produces vague conclusions.
Review the governance layer
Check information-security policy, roles, risk methodology, risk register, risk treatment, Statement of Applicability, objectives, competence, internal audit, management review and corrective action.
Review technical control families
For a SaaS business this commonly includes identity and privileged access, cloud logging, secure development, vulnerability management, endpoint protection, backups, secrets, change control and supplier dependencies.
Demand operating evidence
Ask for real examples across the review period: completed access reviews, actual offboarding records, restore-test results, vulnerability remediation tickets, incident records, supplier reviews and approved production changes.
Prioritise by risk and certification impact
Not every gap deserves the same urgency. Rank deficiencies according to business risk, audit impact, dependency and the time needed to create operating evidence before certification.
Use the Readiness Review to define scope and the first assessment.