Compliance Gap Assessment: How to Measure Your Current State Against NIST CSF and ISO 27001

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
A gap assessment is a structured comparison of your current security controls against the requirements of a target framework. It produces two outputs: a current-state baseline (what is in place, partially in place, or missing) and a prioritized remediation roadmap (what to fix first, based on risk and certification timelines).
Most organizations run gap assessments as documentation exercises — collect policies, check a spreadsheet column, mark 'yes' or 'no.' This approach produces an optimistic view of current state (documents exist, but controls may not actually function) and a remediation list with no prioritization. A rigorous gap assessment validates that controls actually function through testing, interviews, and evidence review, and produces a remediation roadmap that sequences work by risk rather than alphabetical order.
Scoping decisions before starting a gap assessment
Poor scope definition is the most common cause of gap assessments that produce useless outputs. Define scope before any evidence collection begins.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The NIST CSF 2.0 gap assessment methodology
NIST CSF 2.0 organizes security outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function contains categories and subcategories — 106 subcategories in total — that represent specific security outcomes.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The ISO 27001:2022 gap assessment methodology
ISO 27001:2022 gap assessment has two components: clause requirements (organizational requirements for the ISMS) and Annex A controls (the specific security controls). Both must be assessed.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Building the remediation roadmap from gap assessment output
The gap assessment output is a list of gaps. The remediation roadmap converts that list into a sequenced, resourced plan that leadership can fund and the security team can execute.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
A compliance gap assessment produces value proportional to the rigor of the evidence collection and the quality of the remediation roadmap. Document-only assessments produce optimistic current-state views that fail under auditor scrutiny. Control testing and evidence validation produce accurate current-state baselines. A remediation roadmap sequenced by risk, type, and certification timeline converts the gap list into a funded, executable security improvement program — the ultimate output of a gap assessment done correctly.
Frequently asked questions
How often should we run a compliance gap assessment?
For organizations targeting ISO 27001 certification: run a gap assessment 9-12 months before your target certification date, allowing time for remediation before the formal audit. After certification, ISO 27001 requires annual surveillance audits and a full recertification audit every 3 years — run internal assessments 3-6 months before each external audit to identify and remediate gaps before the auditor arrives. For NIST CSF: run annual self-assessments to track maturity progression over time. Organizations in regulated industries (financial services, healthcare, critical infrastructure) may have more frequent external assessment requirements driven by regulatory frameworks (FFIEC, HIPAA, NERC CIP).
What is the difference between a gap assessment and a risk assessment?
A gap assessment measures the distance between current controls and framework requirements — it is framework-centric. A risk assessment identifies threats, vulnerabilities, and potential impacts to your organization's specific assets — it is risk-centric. ISO 27001 requires both: a risk assessment to identify what risks to treat, and a gap assessment (the SoA) to document which controls are implemented to treat those risks. NIST CSF integrates both in a single framework. In practice, they are complementary: the risk assessment identifies what needs protecting; the gap assessment confirms whether the controls protecting it meet the required standard.
Can we use the same gap assessment for multiple frameworks?
Yes — with a control crosswalk. NIST, ISO 27001, SOC 2, and other frameworks share significant control overlap. A single evidence collection effort can feed multiple framework gap assessments if you map the control evidence to each framework's requirements. Tools that support multi-framework management (Vanta, Drata, Secureframe, OneTrust) maintain a single control library and map each control to its corresponding requirements in ISO 27001, SOC 2, NIST CSF, PCI DSS, and others — reducing the evidence collection effort by 40-60% compared to running separate gap assessments for each framework.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
