Learn

What is a gap assessment?

A gap assessment compares your current controls and practices with the requirements of a framework or regulation to identify what is missing. Here is how to run one.

In short

A gap assessment (or gap analysis) compares an organization's current controls, policies, and practices with the requirements of a framework, regulation, or target state, and records where they fall short. The output is a list of gaps, each with a severity and a plan to close it, often used to prepare for a first audit or certification.

This page is for you if
  • You are trying to get a straight answer before you sit through a sales call
  • You need language you can take to a CISO, auditor, or procurement

How to run one

  1. Pick the targetThe framework or requirements you are measuring against.
  2. Gather evidenceDocuments, tool data, and interviews.
  3. AssessEach requirement: met, partially met, or not met.
  4. PrioritizeRate each gap by risk.
  5. PlanOwners, fixes, and dates.

When this becomes a buying decision

A gap assessment that does not become a living findings list is a slide. The tool should pre-fill from what you already have and keep the gaps owned.

If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.

Questions

What is the difference between a gap assessment and an audit?

A gap assessment is an internal readiness exercise; an audit is a formal, independent evaluation.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.