Gap Assessment
Structured comparison of current state against your target framework.
What it is
A gap assessment compares your existing controls, policies and evidence against a chosen framework — ISO 27001, SOC 2, NIST, or a regulator’s expectations — identifying what exists, what is partial and what is missing, prioritised by risk and effort.
Coverage
- Framework scoping and applicability
- Control-by-control current-state review
- Policy and evidence sampling
- Risk and effort prioritisation
- Remediation roadmap
How we deliver
- Scope — framework, entities and systems.
- Review — documents, interviews and samples.
- Rate — maturity per control area.
- Prioritise — risk-weighted gaps.
- Roadmap — sequenced remediation plan.
Outcomes
- Clear, honest current-state picture
- Prioritised gap register
- Fundable remediation roadmap
- Basis for readiness and audit planning