Skip to content
faviconHow Could Expert Insight Transform Your Business Today?

Learn how our comprehensive services tackle your challenges, from technology to cybersecurity

GET STARTED

Cybersecurity Gap Assessment: A Step-by-Step Guide
Sep 9, 2026

Cybersecurity Gap Assessment: A Step-by-step Guide

Abstract:
  • A cybersecurity gap assessment is an evidence-based evaluation of how an organization’s existing security practices measure against the outcomes, obligations, or controls it intends to achieve.
  • Useful findings distinguish control deficiencies from business risk, because missing, incomplete, ineffective, or poorly evidenced controls can require different responses.
  • A defensible assessment links requirements to evidence, validates findings with owners, and prioritizes remediation using business significance, obligations, dependencies, feasibility, and resources.
  • The resulting roadmap should assign ownership, target dates, dependencies, and closure evidence, with reassessment confirming whether remediation actually moved the current state toward the target.

_____________________________________________________________________________________________________________________________

Security teams may have extensive checklists of controls, but still can’t answer the question leadership cares most about: what should we fix first? That question can be answered through a cybersecurity gap assessment, which compares an organization’s current cybersecurity state to a defined target state and translates the differences into prioritized actions.

The need for that prioritization is especially relevant for resource-constrained teams. ISACA’s State of Cybersecurity research found that 55% of cybersecurity teams are understaffed and 65% have unfilled positions. A gap assessment is not one universally prescribed methodology; NIST CSF 2.0’s Current and Target Organizational Profiles provide one authoritative approach for comparing current and desired cybersecurity outcomes.

For the assessment to be useful, however, identified gaps must connect evidence to business risk, ownership, remediation, and validation. That starts with defining exactly what the assessment measures and how it differs from adjacent security reviews.

What a cybersecurity gap assessment measures

A cybersecurity gap assessment compares an organization’s current cybersecurity practices with a defined target state. That target might reflect desired security outcomes, contractual or customer obligations, certification requirements, internal policies, or a combination of these. Under NIST CSF 2.0, for example, organizations can use Current and Target Organizational Profiles to compare existing practices against the cybersecurity outcomes they want to achieve.

A gap assessment is related to, but distinct from, other types of review:

Assessment

Primary focus

Gap assessment

Differences between current and target cybersecurity states

Risk assessment

Threats, likelihood, impact, and resulting risk

Maturity assessment

How developed and repeatable the cybersecurity capabilities are

Vulnerability assessment

Technical weaknesses that could be exploited

Audit

Evidence of conformity with defined criteria or requirements


Control assessment and risk assessment answer different questions. Control assessment evaluates whether controls are implemented correctly, operating as intended, and achieving their intended outcomes, while risk assessment evaluates the likelihood and potential impact of adverse events. A control gap can therefore inform risk analysis without itself constituting a risk rating. Depending on the evidence, a gap may reflect a missing control, incomplete implementation, ineffective operation, or insufficient evidence, and each condition may require a different remediation response.

When to conduct a cybersecurity gap assessment

A cybersecurity gap assessment is most useful when there is a clear business decision or change that requires a defensible view of the current security state. Typical triggers are preparing for an audit, certification, customer security review, or cyber-insurance renewal, and responding to an incident or material control failure. Organizations may also do one in setting a new program baseline, merging an acquisition, adopting a new framework, or making significant changes to technology, vendors, or operating models.

The same applies after remediation. Reassessing previously identified gaps helps determine whether corrective actions actually changed the current state, rather than simply closing tasks on a project plan.

There is no universal annual cadence that fits every organization. The trigger should determine the scope, benchmark, evidence requirements, and target state. A review driven by customers might look at contractual controls, while a review after an incident might look at the systems and processes involved. Timing therefore should reflect the organization’s obligations, material changes and risk, not the calendar.

How to perform a cybersecurity gap assessment

Here’s what a good cybersecurity gap assessment looks like: mapping framework requirements to evidence, findings, business impact, ownership, remediation, and validation. It is not simply about finding missing controls. The goal is to provide outcomes that leaders can understand, prioritize, fund, delegate and ultimately sign off on.

1. Define the decision, scope, and sponsor

Start by clarifying why the assessment is being conducted and what decision its results need to support. The scope should identify the relevant systems, data, business units, locations, vendors, and other dependencies, along with any explicit exclusions.

The assessment should also have an accountable sponsor and a defined deadline. A review intended to support a customer requirement may have a different scope than one that is triggered by an acquisition, incident, or broader program-maturity concern. Early boundary setting maintains the focus of the assessment and prevents teams from gathering evidence that isn’t material to the decision they are making.

2. Select the benchmark and target state

Next, define what “good” looks like. NIST SP 1301 provides a practical model for doing this through CSF 2.0 Organizational Profiles. A Current Profile describes the cybersecurity outcomes the organization is achieving today, while a Target Profile describes the outcomes it wants to achieve. Comparing the two provides a structured basis for identifying gaps and developing an action plan.

Yet, the target state in question should still reflect the true purpose and responsibilities of the organization. It may combine certain CSF results with contract, certification, internal policy, or organization-specific standards. Document which requirements are applicable and which are not and why, so that the assessment measures against a relevant target and not an oversized generic checklist.

3. Build the evidence plan

Before evaluating controls, determine what evidence will support each conclusion. Map individual requirements or outcomes to expected evidence, responsible contributors, interviewees, relevant systems, and any tests that need to be performed.

NIST SP 800-53A provides a useful evidence model through three assessment methods: examine, interview, and test. Evidence in practice may include policies, procedures, service tickets, configurations, logs, contracts, training records, scan results, and past findings.

By planning for evidence ahead of time, you can discover unclear ownership, missing records, and third party dependencies before they become bottlenecks in the assessment. It also reduces the risk of reaching conclusions based mainly on stakeholder assertions rather than on evidence that substantiates how a control is designed and operates.

4. Assess the current state

Evaluate how controls work in practice using methods appropriate to the scope. That can include document review, interviews, observation, configuration review, sampling, and technical testing. This aligns with NIST SP 800-53A’s broader approach to gathering evidence and determining whether controls are implemented and achieving their intended outcomes.

Different evidence answers different questions. A policy can establish that a control is formally defined, but it does not prove consistent operation. An interview can explain how a process is supposed to work, but records or testing may be needed to demonstrate that it actually does.

Where an organization needs a practical starting point for prioritization, for organizations seeking an additional prioritized baseline, particularly in or supporting critical infrastructure sectors, CISA’s voluntary Cross-Sector Cybersecurity Performance Goals can help identify high-impact practices with known risk-reduction value. They should be used as appropriate to the organization and scope, not as a universal replacement for the selected benchmark.

5. Compare current and target states

Compare the evidence-supported current state with the selected target state, and document any material differences. For every identified gap, record the applicable requirement, evidence reviewed, relevant scope limitations, and assessment status.

It is also important to distinguish the nature of the gap. AA control may be missing, inadequately designed, inconsistently operated, or functioning as intended but insufficiently evidenced. Such conditions should not automatically be assigned the same finding or recommendation for remediation.

For scoring, consistently follow Vistrada’s established assessment methodology within Apptega. Using different labels, scales or thresholds can make it harder to compare and manage results over time.

6. Validate findings with the control and business owners

Findings should be validated before they become final recommendations. Discuss them with the people responsible for the controls and the business processes they support.

Such validation should verify factual accuracy, identify compensating controls, surface technical or operational dependencies, and capture business context that may have been opaque on first pass. This is also an opportunity to clarify contested or incomplete evidence.

Validation does not mean legitimate findings should be weakened simply because stakeholders dispute them. It ensures that conclusions reflect how the environment actually works and that scoring and recommendations are based on the most complete evidence possible.

7. Determine business significance and risk

A framework gap and a business risk are related but not interchangeable. Once material gaps are identified, evaluate their implications for the organization using its approved risk methodology.

Connect each significant finding to the relevant assets or processes, threat scenarios, existing safeguards, likelihood, and potential impact. A missing control protecting highly sensitive data may warrant very different treatment from a similar framework gap affecting a lower-impact environment.

This step prevents teams from simply ranking findings according to framework status. It helps leadership understand which deficiencies have the greatest business significance and where remediation effort is most justified.

8. Prioritize and build the remediation roadmap

Convert significant findings into specific, owned work. NIST SP 1301’s Current-to-Target Profile approach is useful here because the identified differences are intended to inform an action plan for moving toward the Target Profile.

Each remediation item should identify the required action, responsible owner, priority, dependencies, resource needs, target date, any interim safeguards, and clear closure criteria—including the evidence required to demonstrate that remediation is complete.

Prioritization should consider business risk, contractual and regulatory obligations, dependencies, implementation feasibility, and available resources. CISA’s CPGs can be a reference point for teams seeking broadly applicable practices with known risk-reduction value, especially when building or improving a baseline.

9. Report, track, and reassess

Where used, a detailed finding register should capture the supporting evidence, limitations and the assessment score that applies. The end product should be of value to practitioners and executives alike. Leaders need a simple snapshot of material gaps, priorities, decisions, ownership and resource implications. Control owners need enough traceable detail to execute remediation and demonstrate that the identified gap has actually been addressed.

Track remediation through Apptega and the organization’s established governance process. Closure should be supported by appropriate evidence rather than task status alone. Where there is residual risk, record acceptance of the residual risk through the appropriate governance process.

Reassessment then completes the Current Profile – Target Profile cycle: the evidence is refreshed and it is determined whether the current state has moved toward the desired target following significant remediation or material changes in technology, vendors, operations, or risk.

What the final report and remediation roadmap should include

The final report should turn assessment findings into decisions and owned work. Begin with an executive summary that identifies the most material gaps, required decisions, and priority actions. The report should also document the purpose, scope, exclusions, methodology, benchmark, and applicability decisions of the assessment to allow the reader to understand how the conclusions were derived.

When using NIST CSF, include a clear summary of the Current and Target Organizational Profiles, along with the gaps between them. This comparison is the basis for prioritizing improvements and developing an action plan in NIST SP 1301.

A detailed finding register should capture supporting evidence, limitations, and the standard Apptega score where applicable. From there, translate the findings into a risk-ranked remediation roadmap with accountable owners, target dates, dependencies, resource needs, and closure criteria. Exceptions that are accepted, residual risk and expectations for reassessment should be recorded.

Leaders need both the executive view and the traceable detail. A dashboard is valuable for governance, but it does not substitute for documented ownership, decisions, and follow-through across the larger cybersecurity roadmap.

Common mistakes that make findings hard to act on

A gap assessment isn’t worth much when the method makes the findings hard to believe, hard to prioritize or hard to close. Some common pitfalls are selecting a benchmark that is too broad, failure to define scope and exclusions, and relying on interviews and policies without evidence that controls are working as intended. Conversely, a lack of documentation should be distinguished from the absence of control. Missing documentation may be an evidence problem, control failures may be design or operating weaknesses.

Scoring can create similar issues when teams rate findings before the evidence is sufficiently complete or before control and business owners have validated the underlying facts. Where Apptega is used, teams should also apply the engagement’s defined assessment criteria, labels, and scoring approach consistently so results remain comparable over time. Framework gaps should not automatically be treated as equivalent business risks.

Also, assessments are less actionable when cloud, SaaS, MSP, and supplier dependencies are overlooked or when recommendations lack accountable owners, resources, and closure tests. For example, “improve access reviews” is a non-starter but “assign quarterly access reviews to the IAM owner and verify completion through retained review records” is doable. Finally, assessment readiness should not be confused with certification or evidence of compliance.

When an independent assessment adds value

Where the scope is narrow and internal teams have time, objectivity, knowledge of the framework, and access to the evidence required, a self-assessment may be appropriate. It can provide a useful baseline, particularly when the organization already has mature ownership and governance in place.

Independent support is more useful when the assessment covers multiple business functions, the evidence is contested, leadership needs an independent view, or the organization lacks dedicated security leadership. It may also be appropriate where a customer, an insurer, a board or an audit process requires a higher level of assurance than can be provided by an internally led review.

This work is made possible by Vistrada’s team-based vCISO model, which brings together CISO-level leadership with subject matter expertise in areas like gap assessments, compliance reviews, and ongoing cybersecurity program operations. This allows organizations to move from assessment to prioritization and remediation without the review becoming an exercise in itself.

An advisory cybersecurity gap assessment, however, is not the same as an independent audit or certification and does not replace validation performed by an authorized body.

Turn the gap report into owned security work.

A cybersecurity gap assessment is valuable when its findings result in clear decisions and responsible action. Leadership needs to identify the gaps that matter most to the business, decide what to tackle first, assign ownership, allocate funds, and confirm that remediation changed the current state, not just closed a task.

That takes follow-through beyond the assessment. Vistrada’s vCISO model is a team-based approach that supports organizations through the full cycle of gap assessments and executive prioritization, specialist validation, policy and control development, remediation support, GRC visibility via Apptega, and ongoing cybersecurity governance. This helps keep findings connected to owners, evidence, and measurable progress, rather than allowing the report to become a static point-in-time document.

For organizations that need an independent view or additional security leadership, talk to a Vistrada vCISO about structuring a cybersecurity gap assessment and remediation roadmap that can be carried through to validation.

avatar

Matt Malone

Matt is a proven CISO with over 20 years of Computer Networking and Information Security expertise. Matt has helped hundreds of companies build security programs and grown information security practices into nationwide security solutions providers, worked with companies who have experienced breaches for information security regulation issues, and consulted with the FBI and NYPD on security threats and attacks assisting with investigation, documentation, and pursuit of offenders. Matt has extensive experience in dealing with the payment card and healthcare industries assisting organizations both pre-and post breaches. Matt has experience working at large corporations (e.g., Emerson Electric, En Pointe Technologies, Northrop-Grumman, etc.), mid-size corporations (Veridyn, SLAIT Consulting), and small corporations (Vintage IT, Pivot Networks, etc.). Through this experience, Matt has helped build and define services from network design and installation, troubleshooting, regulatory compliance, and service development. Matt has designed technical network architectures, developed policies and procedures, and implemented physical security controls for companies in health care, financial, and energy verticals, including Fortune 500 and 1000 companies. Matt has served on several advisory boards for technology companies. Matt is a sought-after keynote speaker and published author who frequently appears on national newscasts such as NBC Nightly News, Squawk Box, The Today Show, and many others concerning security and technology issues such as social engineering and security programs.
authentic-small-youthful-marketing-agency-2
SUBSCRIBE

Join Our Newsletter

Sign up today  and be the first to get notified on new updates.

RELATED ARTICLES