What it looks at
A gap analysis reviews policies, processes, technical controls and evidence against each requirement of the chosen framework. For each one, it records whether it is met, partially met or missing, and what would be needed to close the gap.
What you get
The output is a list of gaps ranked by effort and risk, which becomes the roadmap for the project. It also gives a realistic estimate of how long certification will take and what resources it needs.
Gap analysis vs risk assessment
A gap analysis measures compliance with a standard. A risk assessment measures exposure to threats. Both are needed: the gap analysis tells you what the framework asks for, the risk assessment tells you what your business actually needs to protect.
When to do one
At the start of an ISO 27001, ENS, SOC 2 or NIS2 project, when adding a new framework to an existing programme, or before an audit to check readiness.




