Step 3 · Gap analysis

Gap analysis Target against actual, per framework.

A gap analysis compares what a framework requires with what you have in place. The result is your implementation status per framework and a list of gaps.

What it is about

For each requirement you record: met, partly met, not met or not applicable – each with a justification. For ISO/IEC 27001 you check the requirements in clauses 4 to 10 and the 93 controls in Annex A; the controls later form the basis of the Statement of Applicability. For NIS2 you check the ten areas in Section 30(2) BSIG and the duties on reporting (Section 32), registration (Section 33) and management (Section 38). A gap analysis does not replace a risk assessment. It shows where to start.

Step 3Gap analysis
  • NIS262 %
  • ISO 2700148 %
  • AI Act35 %

Answers · 120

  • Yes 54
  • Partly 31
  • No 21
  • Open 14

Sample values

How to go about it

  1. 01

    Derive the applicable requirements from your scope.

  2. 02

    Record status and justification for each requirement.

  3. 03

    Choose “not applicable” only with a traceable reason.

  4. 04

    Prioritise gaps and move them into the action plan.

Common mistakes

  • “Partly” becomes the comfortable answer.
  • Exclusions have no justification.
  • Each framework is analysed separately although the requirements overlap.

What an auditor wants to see

  • Assessed requirement list with justifications
  • Implementation status per framework
  • Prioritised gap list

How UniqSuite helps

UniqSuite asks one question per requirement. If an answer applies to several frameworks, the weakest implementation counts. The status per framework is recalculated after every answer.

References

  • ISO/IEC 27001, clauses 4 to 10 and Annex A
  • Sections 30, 32, 33, 38 BSIG
  • The same approach applies to ISO/IEC 42001, the AI Act and the CRA with their own catalogues.

Frequently asked questions

How long does a gap analysis take?

It depends on size and prior work. Well prepared, you can complete a first full pass in a few working days.

Who answers the questions?

The people who know: IT, HR, purchasing, facilities. Information security coordinates and reviews the justifications.

Is a gap analysis mandatory?

Neither ISO 27001 nor the BSIG explicitly requires one. It is, however, the quickest way to see where you stand and where to start.

How does it differ from an internal audit?

A gap analysis is a stocktake, often a self-assessment. An internal audit checks objectively and against evidence whether the requirements are effectively met.

Do the answers need evidence?

Always a justification, and evidence where possible. Refer to the document or setting that proves the status – it saves time in the later audit.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.