What is a gap analysis? Meaning, steps and examples
A gap analysis is a structured comparison between how things are today and how they should be. The difference between the two is the gap. The yardstick can be a business goal, a standard such as ISO 27001, a law or a skills profile; the output is a list of what's missing, written so the gaps can be prioritized and fixed.
The term shows up everywhere from finance to HR, but the principle never changes: define the target state, measure the current state honestly, and write down the difference. The most common place to meet it right now is information security, where it has become the standard first step toward ISO 27001 and NIS2. First, the word itself.
What does gap analysis mean?
The gap is the distance between two states: a current state (where you actually stand) and a target state (where you need to be). You will also see the same exercise called a gap assessment; the two mean the same thing. A current-state analysis is the related concept that stops at describing where you are, while a gap analysis always compares against a defined target.
Three components are always present: the current state, the target state, and the gap itself, phrased so it can be closed. Without a clear target state there is no gap to measure, only a general sense of unease.
How to run a gap analysis in five steps
The method is simple. The discipline is the hard part.
- 1. Pick the yardstick. Decide exactly what you are comparing against. A vague yardstick gives you a vague analysis.
- 2. Set the scope. Decide which part of the organization the analysis covers before you assess anything; otherwise every answer becomes "it depends".
- 3. Map the current state honestly. Talk to the people doing the work, not just the documents. A routine existing on paper doesn't mean it's followed.
- 4. Record every gap with a justification. Six months later, the justification is the only thing that explains the assessment.
- 5. Prioritize and turn it into a plan. Start with the gaps that expose you most, give every action an owner and a target date, and re-measure after a while. The trend between two measurements says more than any single snapshot.
Gap analysis or risk analysis?
The two get mixed up constantly. A gap analysis measures your distance to an external yardstick. A risk analysis starts from your own operations instead and asks what could go wrong, how likely it is and how bad it would be. In ISO 27001 you need both: the gap analysis shows where you stand against the standard's requirements, the risk assessment decides which security measures your particular organization needs.
If you have to pick an order, run the gap analysis first. It's cheaper and faster, and it gives you the basis for deciding whether and how to proceed at all.
Example: a gap analysis in information security
The most common context for the term today is information security. There the yardstick is ISO 27001, with its 93 Annex A controls and the management-system requirements in clauses 4 to 10, or a law such as the EU's NIS2 directive. The deadlines are real: in Sweden, for example, the national NIS2 implementation starts enforcing its security-measure and management-training requirements on 1 October 2026, and a gap analysis is the fastest way to find out how far off you stand.
For the full method, there's a practical guide to running an ISO 27001 gap analysis, with a free Excel template covering all 93 controls and the management-system requirements, and a comparison of NIS2 vs ISO 27001 if the law is what's driving you. In Aquil the working model is built in: the Compliance Assistant keeps the assessment per control with a status, a justification and evidence, and the GDPR tier is free if you want to try the model before taking on ISO 27001.
One last thing, and it's the part most people miss: a gap analysis is perishable. It describes your organization on the day it was made, and the value sits in re-measuring against the same yardstick at regular intervals. Why that changes the whole way of working is the subject of your gap analysis should be a living thing.