ISO 27001 in Egypt: what the gap analysis really looks for

ISMS certification path from gap analysis to certification audit

Companies usually come to ISO/IEC 27001 because a customer asked for it. A tender requires it, an international parent expects it, or a large client has added it to their supplier terms. That is a perfectly good reason to start, but it shapes the wrong expectation — that certification is a document exercise that can be completed in a few weeks.

It is not. It is a management system, and the gap analysis at the start is where you find out how far your current practice is from one.

What the gap analysis examines

A useful gap analysis is not a questionnaire. It looks at four things, in this order:

  1. Scope. Which parts of the business, which locations, which systems. Getting this wrong is the most expensive mistake available, because it determines everything that follows.
  2. Existing practice. What you actually do today, observed rather than described. The gap between the two is usually the interesting part.
  3. Documentation. Policies, procedures, records. Not whether they exist, but whether they match what people do.
  4. Evidence. Whether you can demonstrate, with records, that a control operated over time rather than on the day someone looked.

What usually fails

Across the certification work we have supported, the same handful of gaps come up:

  • Asset register. Annex A requires you to know what you are protecting. Very few companies have a current one. See our note on asset management — this is usually the first real piece of work.
  • Access reviews. Accounts are created diligently and removed casually. Leavers still have mailboxes; contractors from two projects ago still have VPN.
  • Supplier management. The standard cares about your suppliers’ security. Most companies have no record of which suppliers touch their data.
  • Incident records. Incidents happen and are fixed, but nothing is written down, so there is no evidence the process works.
  • Backup verification. Backups run. Restores are not tested, and there is no record either way.

How long it honestly takes

For a company of 50 to 300 staff with a reasonably contained scope, a realistic timeline is nine to fourteen months from gap analysis to certification audit. The distribution is not what people expect:

  • Gap analysis and scoping: 3–5 weeks
  • Remediation — policy, process and technical: 4–8 months, and this is where the real work is
  • Operating the system to generate evidence: at least 3 months, because auditors need to see controls working over time, not on the day
  • Internal audit and management review: 3–4 weeks
  • Certification audit, stage 1 and stage 2: 4–8 weeks apart

Anyone offering certification in eight weeks is either selling a document or planning to hand you something you cannot sustain.

Do the internal audit properly

The internal audit is not a formality before the real one. It is your chance to find non-conformities while they are cheap. We would rather write a difficult internal audit report than watch a client be surprised in stage 2 — and the auditors themselves respond well to an organisation that has already found and recorded its own problems.

The part that outlasts the certificate

The certificate is valid for three years with surveillance audits along the way. What actually keeps you certified is whether the management system became how you work or stayed a folder. The companies that struggle at surveillance are the ones who treated it as a project. The ones that sail through treated it as a change to operations.

We have taken client environments through ISO 27001, PCI DSS, SOC and TISAX — from gap analysis to the certification audit itself. ISMS & Compliance →