A common compliance mistake is to start writing policies and buying tools before understanding the current position. Gap analysis addresses this blind spot: it objectively compares existing operations with target requirements and provides a prioritised action list. Here is the method, step by step.
What is gap analysis, and why start with it?
Gap analysis systematically identifies the difference between current and required performance. It shows where you stand and what remains to be done, whether you are preparing for NIS2 or ISO/IEC 27001.
Without it, subsequent decisions lack a reliable basis. Organisations may:
- struggle to estimate time and cost realistically;
- fix the most visible issues instead of the most serious risks;
- duplicate work where effective controls already exist.
The assessment provides the compliance project’s roadmap and budget foundation.
What do we assess?
We examine how existing controls, processes and evidence meet each requirement. The assessment spans three layers:
- Governance: policies, procedures, roles, responsibilities, management commitment and the risk framework.
- Processes: actual incident, access, supplier, change and continuity management.
- Technology: logging, encryption, multifactor authentication, backup and recovery, network segmentation and actual configurations.
Documented intent is not enough. The assessment needs evidence of how controls work in practice.
How does the assessment work?
Six stages build on one another. The method is consistent across NIS2, ISO 27001 and DORA; the reference requirements change.
1. Define scope and objectives
Establish the units, sites, systems and assets to examine, and the objective: certification, regulatory compliance or greater maturity. Avoid a scope that is unnecessarily broad or leaves important areas out.
2. Select the requirements
For ISO 27001, use the management system requirements and Annex A controls. For NIS2, use the applicable risk management measures; for DORA, the ICT risk and resilience requirements.
3. Gather evidence
Collect facts through three channels:
- interviews with process owners and management;
- document review, including policies, logs, minutes and contracts;
- technical assessment of configurations, access rights, logging and system settings.
4. Assess each control
Use one consistent scale against the evidence to make results objective and repeatable:
| Compliance level | Meaning | Typical characteristics |
|---|---|---|
| Absent | The control is missing | No policy, process or tool |
| Partial | Initial or incomplete | A principle exists, but practice is irregular or undocumented |
| Largely in place | Operational, with gaps | Implemented but incomplete or untested |
| Complete | Effective and demonstrable | Documented, operating and supported by evidence |
5. Prioritise the gaps
Rank findings by risk and effort, not by the order in which they were discovered.
6. Create an action plan and schedule
Assign each gap a concrete action, owner, estimated effort and deadline. This becomes the delivery plan for the compliance project.
How should gaps be prioritised?
Assess the risk created by each gap and the effort needed to close it:
| Lower effort | Higher effort | |
|---|---|---|
| Higher risk | 1. Address immediately | 2. Plan as a priority project |
| Lower risk | 3. Schedule around required deadlines | 4. Assess options where requirements permit |
High-risk, low-effort actions offer substantial risk reduction quickly. High-risk work needing more resources should receive a dedicated project. Mandatory measures cannot be omitted simply because assessed risk is low. Deferral or risk acceptance is an option only where requirements and deadlines allow it.
The real value lies in the priorities: knowing where limited resources will achieve the greatest risk reduction.
What are the deliverables?
Management should receive a package it can act on:
- Compliance snapshot: control-by-control findings and overall maturity.
- Prioritised gap register: organised by risk and effort.
- Action plan and timetable: owners, effort estimates and deadlines.
- Executive briefing: major risks and next steps.
These outputs inform the project budget and schedule. They are especially useful for NIS2 incident reporting: missing owners and procedures are clear gaps against the 24-hour early warning, 72-hour notification and one-month final report requirements.
The first two periods run from awareness of a significant incident; the month for the final report runs from notification. See our incident reporting guide for exceptions and ongoing incidents.
What is the risk of skipping the assessment?
Failures to meet requirements may lead to regulatory action and fines, depending on classification, the infringement and applicable Hungarian rules. Management oversight and traceable actions are essential to a defensible compliance programme.
How zemITis helps
Our CISA, CISM, ISO 27001 and ISO 42001 Lead Auditor expertise supports an objective, repeatable assessment with independent peer review. We guide the process through to a prioritised action plan and can support full implementation, including through an outsourced security officer. Visit our NIS2 or ISO/IEC 27001 page to discuss your next steps in a free consultation.