Auditen
Home / Glossary / Gap assessment

Gap assessment

Also known as: Gap analysis, Readiness assessment, Compliance baseline review

A gap assessment is a comparison between an organization's current security or compliance posture and a specific target standard, such as ISO 27001 or SOC 2. It identifies the "gap" between existing controls and those required for full compliance. The process results in a prioritized list of missing requirements that must be addressed to reach the desired state.

Why it matters

Skipping this step often leads to unexpected failures during formal certification audits, resulting in costly last-minute remediation efforts. An auditor may conclude that an organization lacks a systematic approach to risk management if gaps are discovered by chance rather than design. For data protection, failure can lead to regulatory fines under GDPR or the loss of customer trust following a breach. Ultimately, the CISO or Compliance Officer is held accountable for these blind spots and any resulting financial or legal penalties.

In practice

An internal auditor or external consultant typically conducts this exercise during the planning phase of a compliance project. They request evidence such as existing policy documents, system configuration screenshots, and access logs to verify current capabilities. The primary output is a Gap Analysis Report or a Remediation Roadmap that maps missing controls to specific action items. In a first-year engagement, the process is comprehensive, covering every requirement of the framework. For repeat engagements, it shifts to a "delta assessment," focusing only on new regulatory changes or modified business processes since the last review.

Worked example

In January 2023, a fictional payment processor called PaySwift sought SOC 2 Type 1 certification. The auditor reviewed their logical access controls and requested evidence that all administrative accounts used multi-factor authentication (MFA). Upon reviewing the Active Directory logs from December, the auditor found that while MFA was enabled for most users, six legacy service accounts remained exempt. This created a "gap" between PaySwift's current state and the SOC 2 Trust Services Criteria. The outcome was a high-priority remediation task to migrate those services to modern authentication by March 1st to avoid a qualified audit report.

Common mistakes

  • Treating it as a full audit by assigning pass/fail grades instead of identifying areas for improvement.
  • Relying solely on management's verbal assertions without requesting technical evidence or documentation.
  • Listing every single missing item with the same priority, rather than weighting gaps based on actual risk to the business.
  • Failing to define a clear "target state," which leads to vague findings that cannot be measured or remediated.

Frequently asked questions

What is the difference between a gap assessment and an audit?

A gap assessment is a diagnostic tool used for preparation, identifying what needs to be fixed without a formal grade. An audit is a formal examination to verify compliance and provide a certified opinion on whether requirements are met.

When is the best time to perform one?

It should be done before starting any major remediation project or at least six months prior to a scheduled certification audit. This provides enough lead time to implement missing controls and generate evidence.

What specific evidence is usually requested during this process?

Auditors look for "artifacts" such as written policies, standard operating procedures (SOPs), system screenshots, organizational charts, and samples of completed logs or tickets.

How do I prioritize the gaps found in a report?

Rank them by risk level—critical, high, medium, or low—based on the likelihood of a threat exploiting that gap and the potential impact on the organization.

Can an internal employee perform a gap assessment?

Yes, but they must be independent of the systems they are assessing to avoid conflicts of interest. For formal certifications, many organizations hire external firms to ensure objectivity and validate their findings.

More terms

Risk appetite  ·  Right to be forgotten  ·  Conformity assessment  ·  Subprocessor  ·  Statement of Applicability  ·  Attestation  ·  Essential and important entities  ·  Control deficiency