Gap Analysis Methodology
A gap analysis is the foundation of any compliance program. Here is a methodology that produces actionable results across any framework.
Purpose of Gap Analysis
A gap analysis compares your current state against the requirements of a target framework or standard. The output is a prioritized list of gaps with remediation recommendations. It is the foundation step for any compliance program: you cannot fix what you have not identified.
Gap analysis serves three purposes:
- Identify what is missing: Controls not implemented or only partially implemented
- Inform program planning: Effort, cost, and timeline to reach compliance
- Establish baseline: Starting point for measuring progress over time
Gap analysis is appropriate before starting a new framework, after major organizational changes, or when frameworks are updated (e.g., ISO 27001:2013 to 2022 transition, NIST 800-53 Rev 4 to Rev 5).
Reference the assessment workflow module for hands-on gap analysis patterns.
Scoping the Gap Analysis
Before assessing controls, define the scope:
- Target framework: Which framework or standard is the benchmark? Specific version if applicable.
- Organizational scope: Which business units, locations, or product lines are included?
- System scope: Which systems, networks, applications, and data flows?
- People scope: Which roles, teams, and external relationships?
- Process scope: Which business processes are evaluated?
Scope decisions affect everything downstream. Too narrow a scope and the gap analysis misses important areas. Too broad a scope and the analysis becomes unwieldy and produces vague findings.
For first-time programs, align scope with the eventual audit scope. Assess the systems that will be in the SOC 2 system description, the ISO 27001 ISMS scope, or the CMMC CUI boundary. This makes the gap analysis directly actionable for compliance preparation.
Assessment Methodology
For each control or requirement in scope, assess current state using three methods:
- Examine: Review documentation: policies, procedures, configurations, prior audit reports, system diagrams
- Interview: Talk to control owners and operators: What do you actually do? How is it documented? What evidence exists?
- Test: Verify operation directly: Pull a sample, observe a process, check a configuration
Triangulate across methods. Documentation that says one thing while interviews suggest another and testing reveals a third indicates either a documentation gap, a process gap, or a tool gap. Identify which.
For each control, determine status:
- Implemented and effective: Operating as designed with evidence
- Implemented but ineffective: Operating but with deficiencies
- Partially implemented: Some elements in place but incomplete
- Not implemented: No control activity in this area
- Not applicable: Control does not apply (with justification)
Scoring and Prioritization
Raw findings without prioritization overwhelm program teams. Score each gap on:
- Compliance impact: Will this gap result in audit findings? Severity of finding?
- Risk impact: What is the underlying security or business risk?
- Remediation effort: How much work to close the gap? (low/medium/high)
- Dependencies: Does this gap need to be closed before others can be addressed?
Combine scores into a priority matrix. Common prioritization tiers:
- Critical / blocker: Must close before audit; significant security risk
- High priority: Should close before audit; meaningful risk reduction
- Medium priority: Plan to address; moderate impact
- Low priority: Track but defer; limited impact
Sequence remediation by priority and dependency. Start with critical gaps, then high priority, working through medium and low as time and resources allow.
Gap Analysis Deliverables
Produce three deliverables from the gap analysis:
- Detailed findings report: Full list of controls assessed with current state, gaps identified, evidence reviewed, and recommendations. 50-200 pages depending on scope.
- Executive summary: 5-10 page summary for leadership: overall posture, critical gaps, recommended program plan, estimated cost and timeline. This is what gets read; make it strong.
- Remediation plan: Prioritized backlog of remediation activities with owners, target dates, and dependencies. This is what drives the program.
Deliver the executive summary first, the remediation plan second, the detailed findings third. Leaders need the summary to make program decisions. Operations teams need the plan to start work. The detailed findings are the reference document for both.
Update the gap analysis as remediation progresses. Closed gaps move to a closed log. New gaps from changes are added. The gap analysis becomes a living view of compliance posture.
Frequently Asked Questions
Related Articles
Compliance Framework Comparison
There are dozens of compliance frameworks. Here is how the major ones compare on scope, audit rigor, cost, and customer demand to help you choose the right ones for your business.
Control Mapping Across Frameworks
Control mapping lets you implement a control once and satisfy multiple frameworks. Here is how to build a mapping that holds up across audits and stays maintainable.
Evidence Collection Best Practices
Evidence quality determines audit speed and outcome. These patterns apply across SOC 2, ISO 27001, CMMC, and any other framework you operate.