Agent Registry·Assessment·Compliance Gap Analyzer
Assessmentclaude-opus-4-6Open source · Free to copy

Compliance Gap Analyzer

Maps your current controls to framework requirements. Shows exactly what is missing.

Reads your policies, SSP, and evidence directory, then maps each control against the target framework's requirements. Produces a gap register with severity, remediation effort estimate, and sequenced roadmap.

Tools:readgrepglob
Frameworks:CMMC L2SOC 2ISO 27001FedRAMPHIPAANIST 800-171
Use case 1
Adding a new framework on top of an existing one (SOC 2 to ISO 27001, ISO 27001 to CMMC, etc.)
Sees what you can reuse, what you need to build fresh, and a sequenced plan that minimizes duplicate evidence work
Use case 2
Onboarding a new client and you need to know readiness before quoting work
Gap register in 30 minutes, mapped to specific control IDs, with effort estimates and POA&M-eligibility per gap
Use case 3
Periodic re-baseline after a significant change (M&A, new product line, new cloud region)
Drift report showing where controls fell out of compliance and what to fix first to restore your posture

Try a sample prompt:

compliance-gap-analyzer · live demo · gemini-flash
◇ Curated sample output (real format)

Gap Register · CMMC L2 · 2026-05-09

Total gaps: 14 (3 Critical · 5 High · 4 Medium · 2 Low)

Conformant practices: 96 / 110 · Projected SPRS: 78 / 110

Certification readiness: NOT READY — 3 critical practices are POA&M-ineligible


AC.L2-3.1.5 · Least Privilege · CRITICAL · POA&M-eligible: NO

Requirement (NIST 800-171 Rev 2 §3.1.5): Employ the principle of least privilege, including for specific security functions and privileged accounts.

Current state: Domain Admin group has 11 members. No just-in-time access. No quarterly access review documented since Q2 2024.

Gap: Three of five AOs not met: [b] privileged accounts not separated from standard accounts for 8 of 11 admins; [d] no documented review process; [e] no enforcement of need-to-know.

Remediation effort: 4–6 weeks

Sequence: Fix BEFORE any AC.L2-3.1.6/7/12 (depends on this baseline)

Evidence needed: PAM tool config showing JIT activation, quarterly review attestation, separation-of-duties matrix.

IA.L2-3.5.3 · MFA Enforcement · CRITICAL · POA&M-eligible: NO

Requirement: Use multifactor authentication for local and network access to privileged accounts and network access to non-privileged accounts.

Current state: MFA enforced for VPN and M365 admin only. Five internal applications (HR, finance, ticketing, monitoring, backup console) have password-only access.

Gap: AOs [b] and [c] not met for non-privileged network access.

Remediation effort: 8–12 weeks (depends on app modernization)

Sequence: Fix in parallel with AC.L2-3.1.5

Evidence needed: SSO config showing MFA enforcement on all five apps, exception register if any cannot be MFA-enabled.

MP.L2-3.8.3 · Sanitize Media · CRITICAL · POA&M-eligible: NO

Requirement: Sanitize or destroy system media containing CUI before disposal or release for reuse.

Current state: No documented sanitization policy. IT team verbally states they wipe drives but no records exist.

Gap: AOs [a], [b], [c] all NOT MET — policy missing, procedure missing, records missing.

Remediation effort: 2 weeks

Sequence: Fix immediately — paper-only fix (write policy, retroactive attestation, start log)

Evidence needed: Approved sanitization policy, NIST SP 800-88 method assignments per media type, disposal log.


High-Severity Gaps (POA&M-eligible if needed)

PracticeGapEffortSPRS Impact
AU.L2-3.3.5No correlated log review4 wk−3
CM.L2-3.4.6No baseline config6 wk−5
IR.L2-3.6.3No IR test in 12 mo1 wk−3
SI.L2-3.14.2No malware protection on 4 servers2 wk−3
SC.L2-3.13.11FIPS crypto not validated4 wk−5

Sequenced Remediation Roadmap

1. Week 1–2: MP.L2-3.8.3 policy work (cheapest critical)
2. Week 1–4: AC.L2-3.1.5 least privilege + PAM rollout
3. Week 3–10: IA.L2-3.5.3 MFA expansion to remaining apps
4. Week 4–8: AU + CM gap closure
5. Week 10–14: Re-audit and submit SPRS

What you can defend at audit today

96 practices fully conformant with assessment-ready evidence. SPRS at 78 is sufficient for DOD contract eligibility under SPRS-only path. Certification requires closing the 3 POA&M-ineligible practices first.

Cmd+Enter to send