Compliance Gap Analysis
An assessment that compares an organisation's current policies, processes and controls with the requirements of a chosen standard or regulation, identifying gaps and the actions needed to close them.
A gap analysis starts by defining the framework and scope, such as ISO/IEC 27001 for a business unit or PCI DSS for a payment environment. Assessors review documents, interview staff, inspect configurations and sample evidence, then rate each requirement as met, partially met or not met. The result is a gap register with risk ratings, owners and effort estimates, and a prioritised remediation roadmap.
Organisations commission gap analyses before pursuing certification or attestation, when new regulations such as NIS2, the Cyber Resilience Act or India's DPDP Act take effect, after mergers and acquisitions, and when customers request assurance. Mapping requirements across frameworks, for example between ISO/IEC 27001, the NIST Cybersecurity Framework and SOC 2, allows one set of controls and evidence to satisfy several obligations.
A gap analysis is a snapshot and is only as reliable as the evidence examined; documented policies that are not followed in practice are a common hidden gap. It is distinct from a formal certification audit, although it often precedes one, and it does not replace legal interpretation of regulatory obligations. Progress is typically tracked through the number and severity of open gaps over time.
Key points
- Compares current controls with a framework's requirements.
- Produces a prioritised remediation roadmap with owners.
- Commonly precedes certification audits and new regulatory obligations.
- Control mapping lets one control set serve several frameworks.
Where AiVibe comes in
AiVibe's security services include compliance gap analysis, and AiVibe is itself ISO/IEC 27001:2022 certified.
Related terms
- ISO/IEC 27001Cybersecurity & Compliance
- SOC 2Cybersecurity & Compliance
- NIST Cybersecurity Framework (CSF)Cybersecurity & Compliance
- NIS2 DirectiveCybersecurity & Compliance
- Digital Personal Data Protection Act, 2023 (DPDP Act)Cybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance