What is a gap assessment?
A gap assessment compares your current controls and practices with the requirements of a framework or regulation to identify what is missing. Here is how to run one.
A gap assessment (or gap analysis) compares an organization's current controls, policies, and practices with the requirements of a framework, regulation, or target state, and records where they fall short. The output is a list of gaps, each with a severity and a plan to close it, often used to prepare for a first audit or certification.
- You are trying to get a straight answer before you sit through a sales call
- You need language you can take to a CISO, auditor, or procurement
How to run one
- Pick the targetThe framework or requirements you are measuring against.
- Gather evidenceDocuments, tool data, and interviews.
- AssessEach requirement: met, partially met, or not met.
- PrioritizeRate each gap by risk.
- PlanOwners, fixes, and dates.
When this becomes a buying decision
A gap assessment that does not become a living findings list is a slide. The tool should pre-fill from what you already have and keep the gaps owned.
If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.
Questions
What is the difference between a gap assessment and an audit?
A gap assessment is an internal readiness exercise; an audit is a formal, independent evaluation.
See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.