ISO 9001 gap analysis: how to do it yourself (step-by-step)

A gap analysis is the first practical step towards ISO 9001 certification. It tells you where you stand today and where you need to focus. Most businesses pay a consultant $3,000–$8,000 for this step — but you can do the initial assessment yourself.
What is a gap analysis?
An ISO 9001 gap analysis is a systematic comparison of your current quality management practices against the requirements of ISO 9001:2015. For each requirement, you assess whether your organisation has processes in place and how effective they are.
The output is a list of gaps — areas where your current practices don't meet the standard — along with recommendations for closing each gap.
Step 1: Understand the seven clauses
ISO 9001:2015 is organised into seven requirement clauses (4–10). Each clause covers a different aspect of your quality management system:
- Clause 4 — Context: Understanding your organisation, stakeholders, and scope
- Clause 5 — Leadership: Top management commitment, policy, and roles
- Clause 6 — Planning: Risk-based thinking, quality objectives, and change planning
- Clause 7 — Support: Resources, competence, communication, and documented information
- Clause 8 — Operation: Planning, design, production, and supplier management
- Clause 9 — Performance Evaluation: Monitoring, internal audit, and management review
- Clause 10 — Improvement: Nonconformity, corrective action, and continual improvement
Step 2: Break requirements into questions
Each clause contains multiple sub-clauses, and many sub-clauses contain multi-part requirements (e.g., “8.3.2 a) b) c) d)”). The key to an effective gap analysis is breaking each requirement into a discrete, answerable question.
For example, Clause 7.1.5 on “Monitoring and measuring resources” becomes multiple questions: Do you maintain a register of measurement equipment? Are instruments calibrated at defined intervals? Is calibration status identified on each instrument?
ISO 9001 has 269 individually assessable requirements when fully decomposed. This is what separates a thorough gap analysis from a superficial checklist.
Step 3: Score each requirement
For each question, assess your current maturity level:
- Not defined (0%) — no process or documentation exists
- Defined but not implemented (25%) — documented but not followed in practice
- Implemented but not effective (50%) — in use but inconsistent or producing poor results
- Partially effective (75%) — working but with known gaps or inconsistencies
- Effective (100%) — consistently applied and producing intended results
Be honest. The value of a gap analysis depends entirely on the accuracy of your self-assessment. Overstating your readiness defeats the purpose.
Step 4: Identify and prioritise gaps
Any requirement scored below “Effective” is a potential gap. But not all gaps are equal. Prioritise based on:
- Clause weight: Clauses 5 (Leadership) and 8 (Operation) carry the most weight
- Blocker status: A score of zero in Clause 5 blocks certification entirely
- Effort to close: Some gaps need a single document; others need process redesign
- Impact on customers: Gaps in operational clauses directly affect service quality
Step 5: Build your remediation plan
For each gap, document what needs to change, what evidence an auditor will look for, and a realistic timeline. Start with critical and high-priority gaps in blocker clauses, then work through the rest systematically.
Or use Cert Ready
Cert Ready does all of this for you. All 269 questions are pre-built, scoring is automatic, and you get a prioritised gap report with specific recommendations, evidence requirements, and effort estimates. Start your assessment.