Ask five compliance leads what a gap assessment actually is and you'll get five overlapping but slightly different answers. Strip away the consulting language and it comes down to this: you take what a standard says you must be doing, you take what you're actually doing, and you write down the difference — in specific, evidence-backed terms. Not “we have a policy.” Which policy, approved by whom, last reviewed when, enforced how.
That distinction matters more this year than it has in a while. NIS2 enforcement steps up substantially in October 2026, pulling in a far wider set of organizations than before — in Germany alone, the companies in scope climb from roughly 4,500 to about 29,500 (Kymatio, 2026 compliance manual). DORA has been live since January 2025, and its incident-reporting clock doesn't negotiate: a four-hour window for the initial notification of a major incident (Digital Chiefs). The AI Act's high-risk obligations land in August 2026, and most organizations it covers aren't ready for them. None of this cares what your intentions were. It cares what you can show.
Fixing the wrong things first

Skip the assessment and jump straight to remediation, and you'll fix the visible problems instead of the ones an auditor actually tests. Recent audit research keeps circling back to the same six failure patterns: scope failure, inventory failure, identity failure, testing failure, evidence failure, and third-party failure (DeepStrike, 2026 compliance statistics). Every one of those is something a proper gap assessment surfaces before the auditor does. The assessment isn't the compliance work itself. It's the map that tells you which piece of compliance work is worth doing first.
Stop running five separate projects

The other shift worth noting is that treating each framework as its own standalone project has become the expensive way to do this. ISO 27001, NIS2, DORA, GDPR/DPDP, and the EU AI Act share enough structural DNA — risk assessment, incident response, access control, vendor oversight — that mapping them in one pass beats running five separate exercises that quietly duplicate most of each other's evidence. DPO Consulting's 2026 guidance puts it plainly: treating NIS2, DORA, and ISO 27001 in silos is the costliest mistake organizations are making this year. If your ISMS is solid, it becomes the hub; each new regulation's extra requirements slot in around it instead of starting from a blank page every time a new acronym shows up.
AI is closing gaps and opening new ones
AI is genuinely changing how gap assessments get done — continuous control monitoring, automated evidence collection, and predictive gap flagging are real and useful additions to a GRC program, not hype. But the same wave of research that celebrates this points at an uncomfortable number sitting right next to it.
68% of organizations breached in the past year had no AI governance policy at all, and barely one in five had security and AI governance teams actually talking to each other — per IBM's 2026 Cost of a Data Breach findings, as summarized by ComplexDiscovery.
If your assessment scope doesn't include the AI tools your own staff are quietly using — the browser extension summarizing customer emails, the free chatbot someone pasted a spreadsheet into — you haven't finished the exercise. You've just relocated the blind spot.
Running one, in five steps

You don't need an outside firm to do a first pass, though an outside, adversarial eye tends to catch what internal teams talk themselves out of flagging. In practice, it comes down to five steps, and the order matters:
1. Inventory what you actually have — systems, data, vendors, and the AI tools nobody officially approved.
2. Fix your reference points before you start — the frameworks that genuinely apply, mapped against each other, not tackled one at a time.
3. Score every control honestly — evidenced, partial, or missing. “In progress” isn't a status; it's a missing control with a note attached.
4. Prioritize by exposure, not alphabetically — an untested incident response plan outranks a stale visitor-log policy every time.
5. Turn the list into a dated roadmap with a named owner per item — or it becomes shelfware within a quarter.
Frequently Asked Questions:
What is a compliance gap assessment?
A compliance gap assessment compares what an applicable standard or regulation requires with what an organization is actually doing. The assessment documents the differences in specific, evidence-backed terms so the organization can understand which controls are effective, partial, or missing.
Why is a gap assessment the first step toward compliance?
A gap assessment provides a practical map of where an organization stands before remediation begins. It helps identify weaknesses in areas such as scope, asset inventories, identity controls, testing, evidence, and third-party oversight so remediation efforts can focus on the highest-priority exposures.
Can one gap assessment cover multiple compliance frameworks?
Yes. Frameworks such as ISO/IEC 27001, NIS2, DORA, GDPR or DPDP, and the EU AI Act share several common areas, including risk assessment, incident response, access control, and vendor oversight. Mapping these requirements together can reduce duplicated assessment and evidence-collection work.
How should compliance gaps be prioritized?
Gaps should be prioritized according to their exposure and potential impact rather than simply working through a checklist in order. For example, an untested incident response plan may represent a more significant risk than a lower-impact administrative policy that needs updating.
What evidence is needed during a compliance gap assessment?
Evidence depends on the applicable framework and control, but can include approved policies, review records, technical configurations, testing results, incident records, access reviews, vendor documentation, inventories, and other records demonstrating that controls are actually implemented and operating.
Should AI tools used by employees be included in a gap assessment?
Yes. The assessment should account for AI tools that employees are using, including unsanctioned or unofficial tools. AI-related usage can create additional security, privacy, and governance risks when sensitive information is entered into external AI services without appropriate controls.
Can AI automate compliance gap assessments?
AI can support gap assessments through continuous control monitoring, automated evidence collection, and predictive identification of potential gaps. However, automated capabilities should complement rather than replace human review and control validation.
What should happen after a compliance gap assessment?
The findings should be converted into a dated remediation roadmap with clear priorities and a named owner for each action. Without ownership, deadlines, and follow-up, a gap assessment can become a static report rather than a practical compliance improvement program.










