Most teams start a certification project by booking the audit. They pick a date, tell the auditor they're ready, and only then discover how much work sits between where they are and what the framework expects. The audit turns into an expensive way to learn about their own gaps.
A gap analysis flips that order. Before you commit to a timeline, you compare what you're already doing against what a framework requires, and you find the holes while you still have time to fix them. This guide walks through how to run one, how to prioritize what you find, and how OptiTech turns a pile of gaps into a roadmap you can actually work through.
What a gap analysis is
A gap analysis is a structured comparison between your current state and a target. For certification, the target is a framework: SOC 2 Type II, ISO 27001, GDPR, NIS2, or DORA. You go requirement by requirement and ask a simple question for each one: are we doing this, partly doing it, or not doing it at all?
The output isn't a pass or fail grade. It's a list of gaps, each one tied to a specific requirement, with enough detail to act on. A good gap analysis tells you what's missing, how far off you are, and what it would take to close each item. That's the difference between "we're probably fine" and a plan you can staff and schedule.
It also sets your scope. Not every control in a framework applies to every company, and a gap analysis is where you decide what's in and what's out, with a reason recorded for each call.
Compare your controls to the requirements
Start with the framework's requirements as the spine. Each framework breaks down into controls, and each control describes something you're supposed to have in place: a policy, a process, a technical safeguard, or evidence that it's working.
For every requirement, gather what you already have and match it up:
- Fully met. You have the control, it's operating, and you can point to evidence.
- Partially met. The control exists but it's informal, inconsistent, or undocumented.
- Not met. There's nothing in place yet.
The partially met items are where teams fool themselves. You might have access reviews that happen when someone remembers, or a backup process that works but was never written down. An auditor treats "we do it but can't prove it" the same as "we don't do it." Evidence is the point, so be honest about what you can actually show.
Watch for overlap between frameworks too. If you're chasing both ISO 27001 and SOC 2 Type II, many controls answer both. Mapping that overlap once means you fix a gap in one place and satisfy several requirements at the same time.
Prioritize gaps by risk and effort
A raw gap list is overwhelming, and treating every item as equally urgent is how projects stall. Sort what you find along two axes: risk and effort.
Risk is about consequence. A missing access control or an unencrypted data store carries more weight than a policy that needs a signature. Ask what a gap exposes you to: a breach, a failed audit, a regulatory finding, or a lost deal.
Effort is about the work to close it. Some gaps are a document you write in an afternoon. Others need a new tool, a vendor change, or a process the whole company has to adopt.
Start where risk is high and effort is low
Plot your gaps on a simple grid. High-risk, low-effort items are your quick wins, so do them first. High-risk, high-effort items need to start early because they take the longest. Low-risk, low-effort items can wait, and low-risk, high-effort items are often where you decide something is out of scope.
This is also where you catch dependencies. You can't demonstrate a control operating over time if you only turned it on last week, so anything that needs an observation period has to move to the front of the line.
Build a remediation roadmap
Once your gaps are prioritized, turn them into a plan. A remediation roadmap assigns every gap an owner, a due date, and a clear definition of done. Without an owner, a gap is just a complaint. With one, it's a task someone is accountable for.
Group the work into phases rather than one giant list. A first phase closes the quick wins and kicks off the long-lead items. A second phase works through the heavier controls. A final phase collects evidence and runs a readiness check before you invite the auditor in.
Be specific about what "done" means for each item. "Improve access management" is a wish. "Enable multi-factor authentication on all admin accounts and document the policy" is a task you can finish and prove.
Estimate time to certification
With a roadmap in hand, you can finally give an honest date. Two things drive it: how long remediation takes, and how long you need to run controls before the audit.
For SOC 2 Type II, the auditor looks at how your controls operated across a window, often three to twelve months. You can't shortcut that observation period, so it usually sets the floor for your timeline. ISO 27001 wants a working management system with a couple of internal cycles behind it. GDPR, NIS2, and DORA each expect processes that have actually run, not ones you stood up the week before.
Add your remediation time to the observation period and you get a realistic target instead of a hopeful one. It's better to tell a customer "next quarter" and hit it than to promise "next month" and miss.
How OptiTech surfaces and tracks gaps
This is where a spreadsheet falls apart. OptiTech maps each framework's requirements to controls in your program, so a gap analysis is built in rather than a side project. You can see, control by control, what's met, what's partial, and what's missing against SOC 2 Type II, ISO 27001, GDPR, NIS2, or DORA.
Each gap becomes a tracked task with an owner and a due date, so your remediation roadmap lives in the same place as the analysis. As you attach evidence and close controls, your readiness updates in real time in the OptiTech Console instead of waiting for a manual recount. When one control satisfies several frameworks, OptiTech reflects that overlap, so you don't fix the same thing twice.
And because the work connects to your trust center, the progress you make toward certification becomes something you can show buyers along the way, not just after the certificate lands.
Getting started
You don't need the whole framework memorized to begin. A realistic first pass looks like this:
- Pick your target framework and confirm your scope.
- Run the comparison control by control, and be honest about partial items.
- Prioritize by risk and effort so you know what to do first.
- Assign owners and dates so every gap becomes a task.
A gap analysis turns certification from a leap of faith into a project you can plan. Find the holes early, close them in the right order, and walk into the audit already knowing the answer.
Ready to see your gaps against a framework? Book a demo and see how OptiTech turns a gap analysis into a tracked remediation roadmap.
