Gap Analysis

Systematic comparison between current state and required compliance level to identify missing controls.

A gap analysis compares where you are against what a standard requires, one requirement at a time, and produces a list of what is missing. It is normally the first thing you do in a certification project, because it converts "we should get ISO 27001" into a scope, a cost and a timeline.

Score each requirement, not the whole standard

A single overall percentage tells you nothing you can act on. Give every requirement one of four verdicts, because the work to close each is entirely different.

VerdictWhat it means, and what it costs to close
MetDone and evidenced. Note where the evidence lives, or you will look for it again during the audit.
Met but undocumentedYou do it, you cannot show it. Usually the largest group and the cheapest to fix: write it down.
Partially metIn place somewhere but not everywhere, or done irregularly. Needs consistency, not new tooling.
Not metAbsent. The only group that needs real project work, and usually far smaller than people fear.

Splitting "met but undocumented" from "not met" is what makes the output believable. Collapsing them makes a mature organisation look unprepared and turns a documentation exercise into an implementation budget.

What the output has to contain

A gap analysis that lists gaps is only half finished. For each one, record the owner, the effort, and what evidence will prove it closed. Without those three, the report gets read once and then sits in a folder.

Order the result by risk rather than by the standard's numbering. Annex A order tells you nothing about which gap would hurt you first, and working through it top to bottom means spending early effort on whatever happens to be listed first.

When to run one

Before a certification project, obviously. Also worth repeating when your scope changes, when a new framework lands on you, and roughly a quarter before the audit, when it stops being planning and becomes a rehearsal.

The same method works against any requirement-based framework: ISO 27001, SOC 2 or NIS2. Only the requirement list changes. Maturity models such as the Safety Culture Ladder work differently, because there you are measuring a level rather than checking requirements off.

Frequently asked questions

What is a gap analysis in compliance?
A gap analysis is a systematic comparison between your current controls and the requirements of a standard or regulation, to identify what is missing before certification or against a target state.
Why do a gap analysis?
It shows exactly where you fall short of a framework such as ISO 27001 or SOC 2, so you can plan and prioritise the work needed to become compliant.
When should you do a gap analysis?
Typically at the start of a certification project, and again periodically to check ongoing conformity.