Blog/ISO 9001 Gap Analysis Guide

ISO 9001 gap analysis: how to do it yourself (step-by-step)

Tablet showing management system assessment content

A gap analysis is the first practical step towards ISO 9001 certification. It tells you where you stand today and where you need to focus. Most businesses pay a consultant $3,000–$8,000 for this step — but you can do the initial assessment yourself.

What is a gap analysis?

An ISO 9001 gap analysis is a systematic comparison of your current quality management practices against the requirements of ISO 9001:2015. For each requirement, you assess whether your organisation has processes in place and how effective they are.

The output is a list of gaps — areas where your current practices don't meet the standard — along with recommendations for closing each gap.

Step 1: Understand the seven clauses

ISO 9001:2015 is organised into seven requirement clauses (4–10). Each clause covers a different aspect of your quality management system:

  • Clause 4 — Context: Understanding your organisation, stakeholders, and scope
  • Clause 5 — Leadership: Top management commitment, policy, and roles
  • Clause 6 — Planning: Risk-based thinking, quality objectives, and change planning
  • Clause 7 — Support: Resources, competence, communication, and documented information
  • Clause 8 — Operation: Planning, design, production, and supplier management
  • Clause 9 — Performance Evaluation: Monitoring, internal audit, and management review
  • Clause 10 — Improvement: Nonconformity, corrective action, and continual improvement

Step 2: Break requirements into questions

Each clause contains multiple sub-clauses, and many sub-clauses contain multi-part requirements (e.g., “8.3.2 a) b) c) d)”). The key to an effective gap analysis is breaking each requirement into a discrete, answerable question.

For example, Clause 7.1.5 on “Monitoring and measuring resources” becomes multiple questions: Do you maintain a register of measurement equipment? Are instruments calibrated at defined intervals? Is calibration status identified on each instrument?

ISO 9001 has 269 individually assessable requirements when fully decomposed. This is what separates a thorough gap analysis from a superficial checklist.

Step 3: Score each requirement

For each question, assess your current maturity level:

  • Not defined (0%) — no process or documentation exists
  • Defined but not implemented (25%) — documented but not followed in practice
  • Implemented but not effective (50%) — in use but inconsistent or producing poor results
  • Partially effective (75%) — working but with known gaps or inconsistencies
  • Effective (100%) — consistently applied and producing intended results

Be honest. The value of a gap analysis depends entirely on the accuracy of your self-assessment. Overstating your readiness defeats the purpose.

Step 4: Identify and prioritise gaps

Any requirement scored below “Effective” is a potential gap. But not all gaps are equal. Prioritise based on:

  • Clause weight: Clauses 5 (Leadership) and 8 (Operation) carry the most weight
  • Blocker status: A score of zero in Clause 5 blocks certification entirely
  • Effort to close: Some gaps need a single document; others need process redesign
  • Impact on customers: Gaps in operational clauses directly affect service quality

Step 5: Build your remediation plan

For each gap, document what needs to change, what evidence an auditor will look for, and a realistic timeline. Start with critical and high-priority gaps in blocker clauses, then work through the rest systematically.

Or use Cert Ready

Cert Ready does all of this for you. All 269 questions are pre-built, scoring is automatic, and you get a prioritised gap report with specific recommendations, evidence requirements, and effort estimates. Start your assessment.

Ready to assess your ISO readiness?

Start your self-guided assessment today. No consultants, no surprises.

Get started
Start free assessment →