Gap Analysis

Systematic comparison between current state and required compliance level to identify missing controls.

A

B

C

D

E

F

G

A gap analysis is a structured assessment that compares an organisation's current security posture, policies and controls against the requirements of a target compliance framework or standard. It systematically evaluates each control requirement to determine whether it is fully met, partially met or not addressed at all, producing a detailed report that highlights the specific gaps between the current state and the desired compliance level.

Gap analysis is typically the first step in any compliance programme, providing a clear roadmap for remediation by identifying which controls need to be implemented, enhanced or documented. It enables organisations to prioritise their compliance efforts based on risk, allocate resources effectively and set realistic timelines for achieving certification. Regular gap analyses also help organisations track their progress and adapt to evolving framework requirements over time.

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is a gap analysis in compliance?
A gap analysis is a systematic comparison between your current controls and the requirements of a standard or regulation, to identify what is missing before certification or against a target state.
Why do a gap analysis?
It shows exactly where you fall short of a framework such as ISO 27001 or SOC 2, so you can plan and prioritise the work needed to become compliant.
When should you do a gap analysis?
Typically at the start of a certification project, and again periodically to check ongoing conformity.