How to run a security gap assessment for a client
Updated
A security gap assessment compares how a client actually operates with what a framework requires, then lists the gaps and what it takes to close them. Clients ask for one before a first ISO 27001 certification, a SOC 2 examination, a PCI DSS assessment or a CMMC or CPCSC requirement in a contract. The value to the client is a defensible list of what is missing. The value to the consultant is a scoped remediation project that follows naturally from it.
1. Fix the scope in writing
Agree on the framework and version, the business units, systems and locations in scope, and the period the evidence should cover. Record exclusions with a reason. For ISO 27001, the scope of the information security management system and the Statement of Applicability decide which Annex A controls apply. For PCI DSS, the cardholder data environment decides almost everything else.
2. Request evidence, not answers
Questionnaires tell you what the client believes. Evidence tells you what happens. For each control, ask for the artifact that would show it operating: an identity provider export for MFA, signed access reviews for each quarter, a patch compliance report, a sample of change tickets. Ask once for evidence that several frameworks share, rather than once per framework.
3. Assess each requirement against its own wording
Record a result for every requirement in scope:
| Result | Meaning | Client action |
|---|---|---|
| Met | Evidence shows the requirement operating across the scope and period | Keep the evidence for the audit |
| Partially met | Some of the scope, some of the period, or intent without full implementation | Extend or formalize the practice |
| Not met | Evidence shows the practice is absent | Implement, then evidence it |
| Not yet assessed | No usable evidence was provided | Collect evidence before concluding |
Keep “not yet assessed” separate from “not met”. The first is a collection task, the second is remediation, and mixing them inflates the gap count.
4. Build the gap register
For each gap, record the requirement, what the evidence shows, what is missing, the risk if it stays open and the owner. Add a maturity score where the client wants a roadmap rather than only an audit decision.
5. Turn the register into a remediation plan
Group related gaps into workstreams, order them by audit impact and effort, and mark the items that block the audit date. Plan a short re-assessment after the main fixes, against the same scope, so the client can see the gaps close.
Framework notes
- ISO 27001 gap analysis. Cover the management system clauses 4 to 10 as well as the Annex A controls. Clients often have reasonable technical controls and no evidence of risk assessment, internal audit or management review.
- SOC 2 readiness assessment. Map evidence to the Trust Services Criteria in scope. For a Type II examination, check that evidence covers the whole period, not a single date.
- PCI DSS gap assessment. Confirm scope and segmentation first. Unclear scope is a frequent finding in itself.
- CMMC gap assessment. Level 2 maps to the 110 security requirements of NIST SP 800-171 Rev. 2. A plan of action is allowed only for some requirements and has to close within a set time, so identify which gaps can wait.
- CPCSC gap assessment. Canadian defence suppliers assess against ITSP.10.171. See the CPCSC guide for the levels and the evidence each requires.
How Control+s runs a gap assessment
- Scoping questions per framework set the controls in scope and record exclusions with their justification.
- Evidence requests are tied to controls, and each uploaded file is mapped across every framework in the assessment.
- Each control gets a draft result with a rationale that cites the evidence, names the gaps and recommends next steps. You review, add observations and override.
- The report includes scope, findings, a gap register and remediation guidance, and a scoped share link lets the client follow progress.
Frequently asked questions
Is a gap assessment the same as a readiness assessment?
They overlap. A gap assessment compares current practice with a framework and lists what is missing. A readiness assessment asks the narrower question of whether the client is ready for a specific audit or certification, such as a SOC 2 examination or an ISO 27001 certification audit, and usually ends in a go or not-yet recommendation.
How long does a security gap assessment take?
It depends mostly on scope and how quickly the client produces evidence. Evidence collection is usually the longest step. Asking for evidence once and reusing it across every framework in scope shortens the engagement more than anything else.
Can a gap assessment replace the certification audit?
No. It is an independent view that prepares the client for the audit. Only an accredited certification body can certify against ISO 27001, only a licensed CPA firm can issue a SOC 2 report, and CMMC Level 2 certification assessments are performed by authorized C3PAOs.
Should the gap assessment include maturity scores?
Often, yes. A met or not-met result tells the client what blocks the audit. A maturity score tells them how far each practice has to develop, which helps prioritize the remediation plan.