---
title: Gap Assessment to Identify Compliance Gaps | Ostendio Compliance Playbook
description: Identify what’s missing before your audit. Learn how to perform a comprehensive gap assessment to prepare for SOC 2, ISO 27001, HIPAA, and more.
image: https://www.ostendio.com/hubfs/Deliver%20Compliance%20Like%20a%20Pro%20M.png
---

# Step 5: Conduct a Gap Assessment

# Prioritize What’s Next

![Myopic Mike_BLUE-png-1](https://www.ostendio.com/hs-fs/hubfs/Myopic%20Mike_BLUE-png-1.png?width=1085&height=767&name=Myopic%20Mike_BLUE-png-1.png)

## Your Compliance GPS

![](https://www.ostendio.com/hs-fs/hubfs/Pro-png.png?width=2330&height=1407&name=Pro-png.png)

**Reveal what’s missing. Prioritize what’s next**

Too many organizations dive into security and compliance without knowing their starting point. 

A gap assessment shows exactly where you are and how far you have to go.

It’s where clarity replaces guesswork, and smart prioritization replaces wasted motion.

Whether you're aiming for SOC 2, HIPAA, NIST, ISO 27001, or other frameworks, this step is where your plan becomes real.

## A gap assessment helps you...

 

![](https://www.ostendio.com/hs-fs/hubfs/Contrarian%20Colleen_BLUE-png-2.png?width=200&height=285&name=Contrarian%20Colleen_BLUE-png-2.png)

- **Understand Scope**: What’s in and what’s out?
- **Understand Scope**: What’s in and what’s out?
- **Surface Gaps Early**: Before your auditor finds them.
- **Deploy Resources Wisely:** By focusing on the high-impact fixes first.

###### What Should a Gap Assessment Include?

A great gap assessment connects that missing piece to risk, control requirements, and operational impact. Here's what to include:

🗺️

# Framework Mapping

---

**Break your framework into control-level requirements. This might include:**

---

- SOC 2 Trust Services Criteria
- NIST CSF or 800-53
- HIPAA Security Rule
- ISO 27001 Annex A controls 

📈

# Control-by-Control Review

---

**Address the following questions each control: **

---

- Are you currently meeting it? Fully, partially, or not at all?
- What evidence exists (or is missing)?
- Are there written policies and proof of implementation?
- Are controls formalized or just tribal knowledge?

⚠️

# Risk Context

---

**Overlay your risk assessment results to add teeth to your findings:**

---

- Gaps in high-risk areas = top priority
- Gaps in low-impact areas = schedule for later
- The above steps ensure your compliance roadmap is risk-aligned, not checkbox-driven.

📝

# Scoring & Prioritization

---

**Don’t treat every gap the same. Score gaps by:**

---

-  Severity (How far off are you?)
- Risk impact (If unaddressed, what’s the consequence?)
- Effort level (Is this a quick win or a long-term project?)
- Dependency (Does this block other progress?)

⏱️

# Ownership & Deadlines

---

**Assign every gap a clear owner and a realistic due date.**

---

- Add gaps to your compliance tracker or task list.
- Gaps with no owners tend to stay gaps.

⚠️

# Leadership Summary

---

**Create a simplified report for execs:**

---

- Number of gaps by category
- Top 5 critical gaps
- High-effort vs. low-effort wins
- Progress toward readiness

## How to Run a Gap Assessment

No need to boil the ocean. Follow this playbook to get it done:

![Insider Syed_BLUE-png](https://www.ostendio.com/hs-fs/hubfs/Insider%20Syed_BLUE-png.png?width=95&height=110&name=Insider%20Syed_BLUE-png.png)

#### Select Your Framework(s)

---

Choose the standards you’re targeting: SOC 2, HIPAA, ISO, etc. If multiple, pick a “primary” and map others to it.

![ALIEN_D_BLUE-png](https://www.ostendio.com/hs-fs/hubfs/ALIEN_D_BLUE-png.png?width=80&height=108&name=ALIEN_D_BLUE-png.png)

#### Inventory Your Current State

---

Document your policies, procedures, tools, vendors, and evidence repositories. Collect what you have before you focus on what’s missing.

 

![Naïve Niamh_BLUE-png](https://www.ostendio.com/hs-fs/hubfs/Na%C3%AFve%20Niamh_BLUE-png.png?width=136&height=105&name=Na%C3%AFve%20Niamh_BLUE-png.png)

#### Evaluate Gaps

---

Use your GRC platform (or Gap Tracker) to score each control (Fully Met, Partially Met, Not Met) and include notes, evidence links, and screenshots. 

![Procrastinator Pete_BLUE-2](https://www.ostendio.com/hs-fs/hubfs/Procrastinator%20Pete_BLUE-2.png?width=100&height=98&name=Procrastinator%20Pete_BLUE-2.png)

#### Score and Prioritize

---

Mark each gap with severity, effort, risk, and urgency. Focus your team on high-risk, low-effort wins first.

![Myopic Mike_BLUE-3](https://www.ostendio.com/hs-fs/hubfs/Myopic%20Mike_BLUE-3.png?width=140&height=99&name=Myopic%20Mike_BLUE-3.png)

#### Assign and Track

---

Add each gap to a tracker or GRC platform, assign an owner, and monitor progress in weekly standups or reviews.

![Complacent Colin_BLUE-png](https://www.ostendio.com/hs-fs/hubfs/Complacent%20Colin_BLUE-png.png?width=63&height=99&name=Complacent%20Colin_BLUE-png.png)

#### Review with Leadership

---

Show them a clear picture: where you are, what’s missing, and what the team is doing to get you audit-ready.

## Ready to Create Your Action Plan?

Now that you know your gaps, it’s time to close them. 

We’ll guide you through creating and updating the policies, controls, and safeguards that fill those gaps and keep you compliant.

[Create Your Remediation Plan](https://www.ostendio.com/playbook-for-audit-readiness/create-your-remediation-plan)

[Return to Roadmap Home](https://www.ostendio.com/healthcare-security-compliance-ostendio)

![Create Your Remediation Plan](https://www.ostendio.com/hs-fs/hubfs/Create%20Your%20Remediation%20Plan.png?width=880&height=1100&name=Create%20Your%20Remediation%20Plan.png)

## You Might Be Wondering...![Kevin Brown, ISO & Director of Professional Services, Ostendio](https://www.ostendio.com/hs-fs/hubfs/Kevin%20Brown%2c%20ISO%20%26%20Director%20of%20Professional%20Services.png?width=1080&height=1080&name=Kevin%20Brown%2c%20ISO%20%26%20Director%20of%20Professional%20Services.png)

**Kevin Brown**

 ISO & Director of Professional Services

---

Kevin responds to your common questions.

 

Still not sure where to turn? [Schedule a chat](https://www.ostendio.com/contact-us-direct) with Kevin or one of our GRC experts. 

##### When should I perform a gap analysis?

Ideally, right after your risk assessment—and anytime you’re planning for a new framework or upcoming audit.

It’s especially useful in early program stages to build a focused remediation roadmap.

Many teams also revisit it quarterly or annually to track progress and adjust priorities.

##### Do I need cybersecurity expertise to run one?

Not necessarily—but it helps. You can start with a structured template or checklist, but experienced security or compliance professionals can provide valuable insight into what’s missing and what matters most.

Some organizations partner with CaaS (Compliance-as-a-Service) providers or GRC software companies (like Ostendio) who offer professional services to deliver expert-led gap assessments without hiring a full team.

##### How does this differ from a risk assessment?

A risk assessment evaluates threats and their potential impact.

A gap analysis looks at requirements and whether you’re meeting them.

Risk is about what could go wrong; a gap assessment is about what you're currently not doing that you should be.

##### What resources can I use to help identify security gaps?

Tools like GRC platforms, automated control mappers, and audit readiness checklists can help compare your current practices to framework requirements.

Many organizations also use spreadsheets or internal assessments early on—but these can get messy fast without structure.

[View All](https://www.ostendio.com/playbook-for-audit-readiness/conduct-a-gap-assessment#)

##### Everyone Secure.

**Learn more by speaking to one of our experts* ***

[Chat with an Expert](https://www.ostendio.com/contact-us-direct)

[Compliance Glossary](https://www.ostendio.com/glossary-of-infosec-compliance-terms-ostendio-compliance-playbook)

Copyright ©2025 OSTENDIO, INC. · All rights reserved · [Privacy Policy](https://www.ostendio.com/privacy-policy?hsLang=en) · [Terms Of Use](https://www.ostendio.com/terms-of-use?hsLang=en) · [Acceptable Use Policy](https://www.ostendio.com/acceptable-use-policy?hsLang=en)

![websights](https://ws.zoominfo.com/pixel/62570e04c2a4d2001c41c059) ![](https://segment.prod.bidr.io/associate-segment?buzz_key=metadata&segment_key=metadata-175&value=) ![](https://segment.prod.bidr.io/associate-segment?buzz_key=metadata&segment_key=metadata-166&value=)