Step 3 · Gap analysis
Gap analysis Target against actual, per framework.
A gap analysis compares what a framework requires with what you have in place. The result is your implementation status per framework and a list of gaps.
What it is about
For each requirement you record: met, partly met, not met or not applicable – each with a justification. For ISO/IEC 27001 you check the requirements in clauses 4 to 10 and the 93 controls in Annex A; the controls later form the basis of the Statement of Applicability. For NIS2 you check the ten areas in Section 30(2) BSIG and the duties on reporting (Section 32), registration (Section 33) and management (Section 38). A gap analysis does not replace a risk assessment. It shows where to start.
Answers · 120
- Yes 54
- Partly 31
- No 21
- Open 14
Sample values
How to go about it
- 01
Derive the applicable requirements from your scope.
- 02
Record status and justification for each requirement.
- 03
Choose “not applicable” only with a traceable reason.
- 04
Prioritise gaps and move them into the action plan.
Common mistakes
- “Partly” becomes the comfortable answer.
- Exclusions have no justification.
- Each framework is analysed separately although the requirements overlap.
What an auditor wants to see
- Assessed requirement list with justifications
- Implementation status per framework
- Prioritised gap list
How UniqSuite helps
UniqSuite asks one question per requirement. If an answer applies to several frameworks, the weakest implementation counts. The status per framework is recalculated after every answer.
References
- ISO/IEC 27001, clauses 4 to 10 and Annex A
- Sections 30, 32, 33, 38 BSIG
- The same approach applies to ISO/IEC 42001, the AI Act and the CRA with their own catalogues.
Frequently asked questions
How long does a gap analysis take?
It depends on size and prior work. Well prepared, you can complete a first full pass in a few working days.
Who answers the questions?
The people who know: IT, HR, purchasing, facilities. Information security coordinates and reviews the justifications.
Is a gap analysis mandatory?
Neither ISO 27001 nor the BSIG explicitly requires one. It is, however, the quickest way to see where you stand and where to start.
How does it differ from an internal audit?
A gap analysis is a stocktake, often a self-assessment. An internal audit checks objectively and against evidence whether the requirements are effectively met.
Do the answers need evidence?
Always a justification, and evidence where possible. Refer to the document or setting that proves the status – it saves time in the later audit.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
