GlossaryCompliance operations

Gap analysis

Short answer

A gap analysis compares an organisation's current security practices with the requirements of a framework such as ISO 27001, ENS or SOC 2, to identify what is missing and what needs to be done before an audit.

What it looks at

A gap analysis reviews policies, processes, technical controls and evidence against each requirement of the chosen framework. For each one, it records whether it is met, partially met or missing, and what would be needed to close the gap.

What you get

The output is a list of gaps ranked by effort and risk, which becomes the roadmap for the project. It also gives a realistic estimate of how long certification will take and what resources it needs.

Gap analysis vs risk assessment

A gap analysis measures compliance with a standard. A risk assessment measures exposure to threats. Both are needed: the gap analysis tells you what the framework asks for, the risk assessment tells you what your business actually needs to protect.

When to do one

At the start of an ISO 27001, ENS, SOC 2 or NIS2 project, when adding a new framework to an existing programme, or before an audit to check readiness.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub