COMPLIANCE | SECURITY GOVERNANCE
11 min read

Compliance Gap Assessment: How to Measure Your Current State Against NIST CSF and ISO 27001

NIST CSF 2.0
released February 2024 — the updated framework adds a new Govern function and expands from 5 to 6 core functions, requiring organizations to reassess prior CSF 1.1 gap assessments
Annex A
ISO 27001:2022 has 93 controls in 4 themes (Organizational, People, Physical, Technological) — down from 114 controls in 14 domains in ISO 27001:2013
3-6 months
typical duration for a structured external gap assessment for an organization of 500-2000 employees — internal-only assessments often complete faster but with lower objectivity
30-40%
average gap rate found in first-time ISO 27001 gap assessments at organizations with informal security programs — most gaps are in documentation, not technical controls

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

A gap assessment is a structured comparison of your current security controls against the requirements of a target framework. It produces two outputs: a current-state baseline (what is in place, partially in place, or missing) and a prioritized remediation roadmap (what to fix first, based on risk and certification timelines).

Most organizations run gap assessments as documentation exercises — collect policies, check a spreadsheet column, mark 'yes' or 'no.' This approach produces an optimistic view of current state (documents exist, but controls may not actually function) and a remediation list with no prioritization. A rigorous gap assessment validates that controls actually function through testing, interviews, and evidence review, and produces a remediation roadmap that sequences work by risk rather than alphabetical order.

Scoping decisions before starting a gap assessment

Poor scope definition is the most common cause of gap assessments that produce useless outputs. Define scope before any evidence collection begins.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The NIST CSF 2.0 gap assessment methodology

NIST CSF 2.0 organizes security outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function contains categories and subcategories — 106 subcategories in total — that represent specific security outcomes.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

The ISO 27001:2022 gap assessment methodology

ISO 27001:2022 gap assessment has two components: clause requirements (organizational requirements for the ISMS) and Annex A controls (the specific security controls). Both must be assessed.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Building the remediation roadmap from gap assessment output

The gap assessment output is a list of gaps. The remediation roadmap converts that list into a sequenced, resourced plan that leadership can fund and the security team can execute.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

A compliance gap assessment produces value proportional to the rigor of the evidence collection and the quality of the remediation roadmap. Document-only assessments produce optimistic current-state views that fail under auditor scrutiny. Control testing and evidence validation produce accurate current-state baselines. A remediation roadmap sequenced by risk, type, and certification timeline converts the gap list into a funded, executable security improvement program — the ultimate output of a gap assessment done correctly.

Frequently asked questions

How often should we run a compliance gap assessment?

For organizations targeting ISO 27001 certification: run a gap assessment 9-12 months before your target certification date, allowing time for remediation before the formal audit. After certification, ISO 27001 requires annual surveillance audits and a full recertification audit every 3 years — run internal assessments 3-6 months before each external audit to identify and remediate gaps before the auditor arrives. For NIST CSF: run annual self-assessments to track maturity progression over time. Organizations in regulated industries (financial services, healthcare, critical infrastructure) may have more frequent external assessment requirements driven by regulatory frameworks (FFIEC, HIPAA, NERC CIP).

What is the difference between a gap assessment and a risk assessment?

A gap assessment measures the distance between current controls and framework requirements — it is framework-centric. A risk assessment identifies threats, vulnerabilities, and potential impacts to your organization's specific assets — it is risk-centric. ISO 27001 requires both: a risk assessment to identify what risks to treat, and a gap assessment (the SoA) to document which controls are implemented to treat those risks. NIST CSF integrates both in a single framework. In practice, they are complementary: the risk assessment identifies what needs protecting; the gap assessment confirms whether the controls protecting it meet the required standard.

Can we use the same gap assessment for multiple frameworks?

Yes — with a control crosswalk. NIST, ISO 27001, SOC 2, and other frameworks share significant control overlap. A single evidence collection effort can feed multiple framework gap assessments if you map the control evidence to each framework's requirements. Tools that support multi-framework management (Vanta, Drata, Secureframe, OneTrust) maintain a single control library and map each control to its corresponding requirements in ISO 27001, SOC 2, NIST CSF, PCI DSS, and others — reducing the evidence collection effort by 40-60% compared to running separate gap assessments for each framework.

Sources & references

  1. NIST CSF 2.0 Self-Assessment Methodology
  2. ISO/IEC 27001:2022 Standard Information
  3. CISA Cyber Performance Goals

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.