A gap analysis compares where you are against what a standard requires, one requirement at a time, and produces a list of what is missing. It is normally the first thing you do in a certification project, because it converts "we should get ISO 27001" into a scope, a cost and a timeline.
Score each requirement, not the whole standard
A single overall percentage tells you nothing you can act on. Give every requirement one of four verdicts, because the work to close each is entirely different.
| Verdict | What it means, and what it costs to close |
|---|---|
| Met | Done and evidenced. Note where the evidence lives, or you will look for it again during the audit. |
| Met but undocumented | You do it, you cannot show it. Usually the largest group and the cheapest to fix: write it down. |
| Partially met | In place somewhere but not everywhere, or done irregularly. Needs consistency, not new tooling. |
| Not met | Absent. The only group that needs real project work, and usually far smaller than people fear. |
Splitting "met but undocumented" from "not met" is what makes the output believable. Collapsing them makes a mature organisation look unprepared and turns a documentation exercise into an implementation budget.
What the output has to contain
A gap analysis that lists gaps is only half finished. For each one, record the owner, the effort, and what evidence will prove it closed. Without those three, the report gets read once and then sits in a folder.
Order the result by risk rather than by the standard's numbering. Annex A order tells you nothing about which gap would hurt you first, and working through it top to bottom means spending early effort on whatever happens to be listed first.
When to run one
Before a certification project, obviously. Also worth repeating when your scope changes, when a new framework lands on you, and roughly a quarter before the audit, when it stops being planning and becomes a rehearsal.
The same method works against any requirement-based framework: ISO 27001, SOC 2 or NIS2. Only the requirement list changes. Maturity models such as the Safety Culture Ladder work differently, because there you are measuring a level rather than checking requirements off.