Gap Analysis


Control by control. Framework by framework. No gaps left unexplained.

You tell us the standard you need to meet. We tell you exactly where you stand against it and what it takes to get there.

A gap analysis starts with a specific question: are we compliant with this framework and where exactly are the gaps?

When a customer asks for your SOC 2 report. When a federal contract requires NIST 800-171 compliance. When your card processor demands PCI DSS evidence. When a regulator wants ISO 27001 alignment. When CMMC certification is the difference between winning and losing a defense contract, these are the moments that require a gap analysis, not a general assessment.

We assess your organization control by control against whichever framework applies. We define the scope with you upfront, conduct the assessment through interviews and evidence review, and deliver a structured report that gives you exactly what you need; a clear picture of where you are, where you're short, and what remediation looks like for each gap.

We work across every major cybersecurity and privacy framework. If the framework exists and your organization needs to meet it, we can assess you against it. The frameworks we're regularly engaged on include PCI DSS, NIST SP 800-171, NIST SP 800-53, NIST CSF 2.0, ISO 27001, SOC 2, and CMMC. If yours isn't on that list, ask anyway.

WHO THIS IS FOR

Defense contractors preparing for CMMC. Companies handling cardholder data under PCI DSS. Federal contractors with NIST 800-171 obligations. Organizations pursuing ISO 27001 certification. Companies preparing for a SOC 2 Type 2 audit. Any organization facing a specific compliance requirement driven by a customer, regulator, insurer, or M&A buyer.

WHAT TO EXPECT

We begin by defining scope precisely; which systems, processes, and locations are in scope for the assessment, and which framework controls apply. From there, we conduct the assessment through structured interviews and evidence review. Each control gets a current-state rating: compliant, partially compliant, or non-compliant, with findings and remediation guidance documented for each gap. Final deliverable is a structured report your team can take directly into a remediation plan. Typical engagement runs two to five weeks depending on framework complexity and scope.

Not sure where to start? Let us help you