Skip to content

Readiness practice

How to run a gap assessment that actually produces action

A gap assessment is the step that converts a requirement list into a plan. Done well, it ends with a small number of owned, dated findings and a defensible sequence. Done badly, it ends with a colour-coded spreadsheet that everyone agrees is accurate and nobody does anything with.

Last updated 4 August 2026 · ISAREADY Editorial Team

What the assessment is for

The purpose is prioritisation. You almost certainly cannot do everything at once, and the point of the exercise is to decide what to do first with something better than intuition.

That framing changes how you run it. If the goal is prioritisation, precision matters less than coverage and honesty. A rough score across the whole scope beats a precise score across a third of it.

Fix the scope before you start

Assessing against an undefined scope produces findings nobody can act on, because the first question about any finding is “where does this apply?”

Write down the sites, legal entities, systems and information types in scope, and the additional scopes that apply — prototype protection or data protection, where relevant. If the scope is genuinely uncertain, that uncertainty is your first finding.

Judge current state, not intended state

The single biggest determinant of whether a gap assessment is useful is whether people answer about today or about the version of the organisation they are working towards.

Three questions that keep the answers honest:

  • Is it defined? Is there something written that says what should happen?
  • Is it applied everywhere in scope, or only where someone champions it?
  • Could you show a recent record that it happened, without reconstructing anything?

An affirmative on the first and a negative on the third is the most common pattern we see, and it is exactly the pattern a document review will miss.

ISAREADY recommendation These three questions are our formulation, not a framework requirement. They map onto the graded scale used in our self-assessment: implemented, partially implemented, planned, not implemented.

What a usable finding looks like

A finding that leads to action has five things. Most findings have two.

  • The gap — stated as a difference, not as a topic. “Access reviews” is a topic. “Access rights are not reviewed for the three production systems in scope” is a gap.
  • The impact — why it matters here, in a sentence.
  • An owner — a person, not a department.
  • A target date — a real one.
  • The evidence that would close it — decided now, while you are thinking about it, rather than in a hurry later.

Sequence by dependency, not by score

It is tempting to start with the lowest scores. Often that is wrong, because some findings are prerequisites for others.

Scope and ownership usually come first — not because they score badly, but because everything else depends on them. Risk method comes before risk treatment. Evidence definitions come before the activities that will generate evidence, otherwise you run the activities twice.

A practical ordering we use: governance and scope, then risk method and register, then the themes with the lowest scores, then evidence structure across everything, then internal audit to verify, then management review to close the loop.

The second pass

Re-run the assessment after the first block of work. Two things matter about the re-run: it uses the same scale so the comparison is meaningful, and it is done with the same honesty, which is harder the second time because now there is something to defend.

If every score improved, be suspicious. Genuine improvement usually reveals new gaps, because implementing something properly exposes what it depends on.

For the mechanics of grading consistently between passes, see maturity assessment.

Frequently asked questions

What is the difference between a gap assessment and a gap analysis?
In practice the terms are used interchangeably. We prefer "gap assessment" because it implies a judgement about current state rather than only a comparison of two lists. What matters is the output: findings with an owner, a priority and a target date, not a colour-coded spreadsheet.
Who should run it?
Someone close enough to know how things actually work and independent enough to say so. A process owner assessing their own process tends to score generously — not dishonestly, but optimistically. Pairing the process owner with a second person from outside that area usually produces a more useful baseline.
How detailed should the first pass be?
Less detailed than you expect. A first pass that covers the whole scope roughly is more useful than a deep review of a quarter of it, because sequencing decisions need breadth. Depth comes on the second pass, once you know which themes matter most.
Should we score maturity or just yes/no?
A graded scale is more useful, because most real answers are "partly". Binary scoring forces everything into either complacency or alarm. What a graded scale must not become is a debate about whether something is a 2 or a 3 — the score is a prioritisation aid, not the deliverable.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.