We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Gap assessment
IT and security gap assessment, UAE

A gap assessment is only as useful as the target state. Most are run against a framework nobody chose, which is why the findings never get funded.

The assessment compares your current position against a defined target and produces the work between them. The value depends entirely on whether the target is one your organisation actually has to meet, and on whether the output is a plan somebody owns rather than a list of differences.

Book a gap assessmentSee how we run it
IT and security gap assessment for UAE organisations
  • Target firstChosen deliberately, not inherited
  • Evidence basedArtefacts rather than assurances
  • Effort estimatedSo the plan is deliverable
  • Owner per gapOtherwise nothing closes
How we run it

Eight things that determine whether a gap assessment leads anywhere.

Every gap assessment has the same structure: a target, a current position and the distance between them. The differences between a useful one and a shelved one are entirely in how the target is chosen, how the current position is established and what form the output takes.

The target is chosen before anything is assessed

A regulatory obligation, a customer requirement, a certification you intend to pursue, a framework you have adopted, or an internal standard. Where an organisation has several, they are reconciled first. Running an assessment against a framework nobody has committed to produces findings with no sponsor, which is the most common reason gap reports are never actioned.

Frameworks are reconciled rather than stacked

Most organisations face several demands at once. The CIS Critical Security Controls at version 8.1 are described as prescriptive and prioritised, with version 8.1 adding updated alignment to evolving industry standards and frameworks. Using one as the working framework and mapping outwards is considerably cheaper than assessing separately against each.

The current position is established from evidence

An artefact, a configuration export, a report, a screenshot with a date. Not a workshop answer, because the person answering describes the intent and the evidence describes the reality, and the two differ without anybody being dishonest. Evidence-based assessment produces findings that survive an auditor rather than findings that surprise one.

A gap is described as work, not as a difference

The output of a comparison is a difference. The output of a useful gap assessment is a specific piece of work with a scope, an owner and an estimate. Improve access management is a difference. Implementing the account management and access control provisions for the named populations, with a completion test, is work somebody can plan.

Effort is estimated so the plan is deliverable

A list of forty gaps with no effort estimate cannot be sequenced, funded or committed to. Estimating each, even roughly, is what allows the organisation to distinguish the six that can be done this quarter from the four that are programmes, and it is what turns a report into something a budget cycle can absorb.

Every gap gets an owner, agreed rather than assigned

Gaps without owners do not close, and gaps owned by whoever commissioned the assessment do not close either. Agreeing ownership during the assessment, with the people concerned present, is uncomfortable and it is the single most reliable predictor of whether anything changes in the following year.

Accepted gaps are recorded as decisions

Some gaps will not be closed, for good reasons: cost, timing, business impact or a judgement that the risk is acceptable. That is a legitimate outcome provided it is recorded as a decision with a name and a review date, rather than left as an open item that quietly becomes permanent and is described afterwards as an oversight.

A re-assessment is scheduled at the outset

The second assessment is what makes the first one a programme rather than a document. Booking it before the first is delivered changes behaviour, because closing a gap stops being optional once there is a known date on which the same comparison will be run again in the same format.

The question to settle first

Against what? If the answer is a framework nobody chose, the findings will not be funded.

A gap assessment inherits its authority from the target. Choose the target carelessly and the report has no sponsor, however good the analysis is.

  • A regulatory obligation gives the findings a deadline and an external consequence. A customer requirement gives them a commercial one. A certification you intend to pursue gives them a date. All three produce funded work.
  • A framework selected because it seemed comprehensive produces findings whose only advocate is the person who commissioned the assessment, and that advocacy runs out at the first budget conversation. The analysis is not wrong, it is unsponsored.
  • Where an organisation faces several demands at once, which is normal, the answer is to reconcile rather than to stack. Assess once against a working framework and map outwards, which version 8.1 of the CIS Controls explicitly supports through its updated alignment to other standards and frameworks.
  • That conversation takes an hour at the start and it determines everything afterwards. It is also the part most likely to be skipped, because agreeing the target requires the sponsor to commit to something before the findings are known.
Ask us to help choose the target
How we approach it

Four things that make a gap assessment produce funded work.

Gap assessments have a poor reputation because most of them are structurally unable to lead anywhere. Each point below addresses one of the reasons.

We settle the target before we assess anything

Including whether the sponsor has committed to it. An assessment against a framework the organisation has not adopted produces findings whose only advocate is the commissioner, and that advocacy does not survive a budget conversation. An hour spent agreeing the target determines whether the rest of the work matters.

We ask for the artefact, not the assurance

Evidence-based assessment produces a position that survives an auditor. Interview-based assessment produces a position that surprises one. The difference is not honesty, it is that people describe what is intended and evidence describes what is operating, and the gap between those two is frequently the finding.

We write gaps as work with a completion test

A difference is not actionable. A scoped piece of work with an owner, an estimate and a test that determines whether it is finished can be planned, funded and closed. Writing the completion test at the same time as the gap is what prevents an item being marked complete when the intent has been addressed rather than the requirement.

We agree ownership in the room and book the re-assessment

Ownership assigned in a report is ownership nobody accepted. Ownership agreed with the person present is a commitment. Booking the re-assessment before delivering the first report converts the whole exercise from a description into a measurement with a known second data point, which is what makes remediation happen.

How an assessment runs

Four phases, and the first one is a conversation rather than an analysis.

The assessment work is the middle. What determines whether it produces change is the target agreed at the start and the ownership agreed at the end.
  1. 01
    Week 1

    Agree the target and the scope

    What you are assessing against and why, which entities and environments are in scope, who the audience for the output is, and what decision the assessment is meant to support. Where several frameworks apply, they are reconciled into one working framework with mappings rather than assessed separately.

    • A target state agreed and written down
    • Scope defined by entity, environment and system
    • The audience and the decision the output supports
    • Framework mappings where several obligations apply
  2. 02
    Weeks 2 to 4

    Establish the current position on evidence

    Artefacts, configuration exports, reports and demonstrations rather than workshop answers. Where evidence cannot be produced, that is recorded as the finding rather than filled in with an assurance, because an assessment that accepts intent as evidence produces a position that will not survive an auditor.

    • A position against every requirement, with evidence cited
    • Requirements where evidence could not be produced, recorded as such
    • Partial compliance distinguished from full and from absent
    • Evidence retained in a form reusable for the next assessment
  3. 03
    Weeks 5 to 6

    Turn differences into work

    Each gap written as a specific piece of work with a scope and a completion test, an effort estimate sufficient to sequence and fund it, and an owner agreed with the person concerned present. Quick wins separated from programmes so the first quarter shows movement rather than mobilisation.

    • Gaps expressed as scoped work with completion tests
    • Effort estimated well enough to sequence and fund
    • An owner agreed for each, in the room
    • Accepted gaps recorded as decisions with review dates
  4. 04
    Ongoing

    Track closure and re-assess

    Progress reported in the same format as the assessment, so movement is directly visible. Then a re-assessment at the interval agreed at the outset, producing a comparable position. That comparison is the artefact that funds the following year, and it only exists if the first assessment was structured for it.

    • Progress reported in the assessment format
    • Re-assessment scheduled from the start
    • A directly comparable second position
    • Remaining gaps re-prioritised rather than re-discovered
Where this fits

Six UAE situations where a gap assessment is the right engagement.

The common feature is a defined target and an undefined distance. Where the target is unclear, the right first engagement is deciding it rather than assessing against a guess.

A firm that has been given a regulatory expectation to meet

The clearest case, because the target is external, the sponsor is obvious and there is usually a date. The assessment maps each requirement to a control, establishes the position on evidence, and produces the work between. That work has a deadline attached, which materially improves the chance of it being resourced.

A business that has decided to pursue certification

The target is the standard and the date is the intended certification. What matters here is that documentation, process and evidence of operation are assessed alongside technical controls, because a management system standard is satisfied by demonstrable operation rather than by configuration alone.

An organisation answering an increasing number of customer questionnaires

Each questionnaire is a different target expressed differently. The efficient approach is one assessment against a working framework, mapped outwards, so the second and third questionnaires cost a fraction of the first. Version 8.1 of the CIS Controls explicitly supports this through its updated framework alignment.

An operator with an internal standard nobody has written down

A common and awkward case. The organisation has a view of how things should be, held collectively and inconsistently. The first phase here is writing the target down, and that exercise frequently produces more value than the assessment that follows, because it surfaces disagreements nobody knew existed.

A group standardising across several entities

The same assessment, run identically across each entity, produces a comparable position that a group function can act on. Assessing entities against different targets, or by different methods, produces documents that cannot be compared and therefore cannot support a group-level decision.

An organisation that has had a gap assessment and done nothing with it

Worth diagnosing before repeating. Usually the target was inherited rather than chosen, the gaps were written as differences rather than work, or nobody owned them. Re-running the same assessment fixes none of those, and the second report meets the same fate as the first.

Three positions

How UAE organisations use gap assessments.

The middle column is the most common outcome, and it is not a failure of analysis. The assessment was competent, the findings were accurate, and nothing about the structure made them actionable.
Target chosen deliberately
Targeted, evidenced and ownedYes
Assessed, reported, filedInherited
No formal assessmentNot applicable
Position established on evidence
Targeted, evidenced and ownedYes
Assessed, reported, filedOn interviews
No formal assessmentNo
Gaps expressed as scoped work
Targeted, evidenced and ownedYes
Assessed, reported, filedAs differences
No formal assessmentNo
Effort estimated
Targeted, evidenced and ownedYes
Assessed, reported, filedNo
No formal assessmentNo
Owner agreed per gap
Targeted, evidenced and ownedYes
Assessed, reported, filedNo
No formal assessmentNo
Accepted gaps recorded as decisions
Targeted, evidenced and ownedYes
Assessed, reported, filedLeft open
No formal assessmentNot applicable
Progress reported in the same format
Targeted, evidenced and ownedYes
Assessed, reported, filedNo
No formal assessmentNo
Re-assessment scheduled
Targeted, evidenced and ownedYes
Assessed, reported, filedNo
No formal assessmentNo
Findings funded
Targeted, evidenced and ownedUsually
Assessed, reported, filedRarely
No formal assessmentNot applicable
Value a year later
Targeted, evidenced and ownedA programme
Assessed, reported, filedA document
No formal assessmentNone
Feature
Targeted, evidenced and owned
Assessed, reported, filed
No formal assessment
Target chosen deliberately
YesInheritedNot applicable
Position established on evidence
YesOn interviewsNo
Gaps expressed as scoped work
YesAs differencesNo
Effort estimated
YesNoNo
Owner agreed per gap
YesNoNo
Accepted gaps recorded as decisions
YesLeft openNot applicable
Progress reported in the same format
YesNoNo
Re-assessment scheduled
YesNoNo
Findings funded
UsuallyRarelyNot applicable
Value a year later
A programmeA documentNone
Common targets

Seven target states, and what each implies for the assessment.

Which target you choose determines the method, the evidence and the audience for the output. These are the ones UAE organisations most often assess against.
Target stateWhat it implies for the assessment
A prescriptive control frameworkSpecific findings against named controls, with a prioritised order already built in
A management system standard for certificationDocumentation, process and evidence of operation as much as technical controls
A payment card obligationScope definition first, since what is in scope determines most of the work. PCI DSS v4.0.1 is current
A regulatory expectationMapping each requirement to a control, and evidence of operation rather than of intent
A customer security requirementAnswering their questionnaire directly, with evidence behind each answer
Application security expectationsAssessment against the current published list, which is the OWASP Top Ten 2025
An internal standard or an architecture targetThe target has to be written down first, because most internal standards are implicit
How an engagement runs

Five steps, and the first is a conversation about the target.

Typically four to eight weeks depending on scope and how readily evidence can be produced. The assessment is the middle. The target and the ownership are what determine the outcome.
  1. 1

    Agree the target, the scope and the audience

    What you are assessing against, who requires it, whether there is a date, which entities and environments are in scope, who reads the output and what decision it supports. Where several obligations apply they are reconciled into one working framework with mappings, rather than assessed separately at several times the cost.

  2. 2

    Collect evidence rather than answers

    Artefacts, configuration exports, reports and demonstrations. Where evidence cannot be produced, that is recorded as the finding. Partial compliance is distinguished from full and from absent, because the three imply different amounts of work and collapsing them makes the plan unusable.

  3. 3

    Establish the position against every requirement

    With the evidence cited against each, so the assessment can be reviewed rather than trusted. Evidence is retained in a form that can be reused at the next assessment, which is what makes the second one substantially cheaper than the first.

  4. 4

    Convert gaps into scoped, owned, estimated work

    Each written as a specific piece of work with a completion test, an effort estimate sufficient to sequence and fund it, and an owner agreed with that person present. Quick wins separated from programmes, and gaps the organisation chooses not to close recorded as decisions with names and review dates.

  5. 5

    Report progress in the same format, and re-assess

    So movement is directly visible rather than described. The re-assessment is scheduled at the outset, and it produces a comparable position rather than a fresh discovery. That comparison is the artefact that supports the following year investment case, and it only exists if the first assessment was built for it.

Straight answers

What organisations ask about gap assessments.

Whatever you are actually required to meet, which is usually a regulatory obligation, a customer requirement or a certification you intend to pursue. Where none of those exists, a prescriptive control framework is a reasonable default, and the CIS Critical Security Controls at version 8.1 are explicitly described as prescriptive and prioritised, which makes the output actionable.

No, and doing so is expensive and produces inconsistent positions. Assess once against a working framework and map the results outwards to each obligation. Version 8.1 of the CIS Controls adds updated alignment to evolving industry standards and frameworks specifically to support this, and it means one evidence collection serves several audiences.

An audit tests compliance against a standard, usually to a formal method and frequently by an accredited party. A gap assessment measures distance to a target you have chosen and produces the work to close it. An audit tells you whether you pass. A gap assessment tells you what to do, which is a different and usually earlier need.

Because people describe what is intended and evidence describes what operates, and the difference is not dishonesty. A control designed correctly, communicated properly and running with an exception nobody documented will be described as implemented and evidenced as partial. An assessment that accepts the description produces a position that will surprise an auditor.

A scope, an owner, an estimate and a completion test. Improve access management is a difference. Implementing account management and access control for the named populations, owned by a named person, estimated at a given effort, with a defined test for completion, is work. Only the second can be planned, funded or closed.

Four to eight weeks for most organisations, driven by scope and by how readily evidence can be produced. Where documentation is current and access is available it moves quickly. Where evidence has to be created during the assessment, that is itself the first significant finding and the timeline reflects it honestly.

There is an argument both ways and the practical answer depends on scale. Assessment by the team that will remediate is faster and risks optimism. Independent assessment is more rigorous and slower to translate into work. Where the assessment supports an external commitment, independence matters more. Where it is internal planning, speed usually wins.

Record it as an accepted gap, with a named person who has the authority to accept it, a reason and a review date. That is a legitimate outcome and it is defensible. What is not defensible is an open item that quietly becomes permanent, because after an incident it is described accurately as something the organisation knew about and did not decide on.

Four things, and each addresses a specific failure mode. A target the sponsor has committed to. Gaps written as work rather than differences. An owner agreed in the room rather than assigned in a document. And a re-assessment booked before the first report is delivered, which converts the findings from advice into a measurement with a date.

Yes, and application security has its own target. The most current released version of the OWASP Top Ten is the 2025 edition, and assessing against a superseded edition produces genuine findings against a revised set of priorities. Where applications are in scope, we assess against the current list and say which edition we used.

Those need scope definition before assessment, because what is in scope determines most of the work and scoping is frequently where the largest reduction in effort is available. PCI DSS version 4.0.1 is the current version in the standards council document library, and assessing against the right version matters as much as assessing against the right scope.

They answer different questions and complement each other. A risk assessment asks what could go wrong and how much it would matter. A gap assessment asks how far you are from a defined target. NIST publishes guidance for the former in Special Publication 800-30 revision 1, Guide for Conducting Risk Assessments, from September 2012. Most organisations benefit from both, in that order.

Annually is the usual rhythm, with the date agreed at the outset rather than decided afterwards. What matters more than the interval is that the second assessment uses the same format and the same evidence approach, because a comparable position is what demonstrates movement and a fresh assessment in a different format demonstrates nothing.

Yes, and consistency is the whole point. The same target, the same method and the same evidence standard applied to each entity produces positions a group function can compare and act on. Entities assessed against different targets by different methods produce documents that cannot support a group-level decision, however good each one is individually.

We scope by the target, the number of entities and environments, and how much evidence exists already. The target conversation comes first and is free, because it occasionally establishes that what the organisation needs is an audit, a risk assessment or a decision about direction rather than a gap assessment at all.
Before commissioning one

Fifteen questions worth answering before an assessment starts.

The first group is the target, the second is scope and evidence, and the third is what happens to the output, which determines whether the assessment was worth commissioning.

The target

  • What are you assessing against, exactly?
    Name it.
  • Who requires it?
    A regulator, a customer, a board, or nobody.
  • Is there a date attached?
    A deadline changes everything.
  • Do several obligations apply?
    Then reconcile before assessing.
  • Has the sponsor committed to the target?
    Before the findings, not after.

Scope and evidence

  • Which entities and environments?
    Groups often assess one.
  • Are third-party managed systems included?
    They usually should be.
  • Can you produce evidence, or only answers?
    The difference matters.
  • Who can grant read access?
    It shapes the method.
  • Is there a prior assessment to compare with?
    Comparison beats repetition.

The output

  • Who reads the report?
    It changes the form entirely.
  • What decision does it support?
    Funding, certification, or assurance.
  • Is there budget for remediation?
    Or is this an awareness exercise.
  • Who will own the gaps?
    Agree before, not after.
  • When is the re-assessment?
    Book it at the start.
Related reading

The pages around this one.

CIS Controls assessment

A gap assessment against a specific prescriptive framework.

Learn more

IT risk assessment

The complementary question of what could go wrong and how much it matters.

Learn more

IT audit services

The wider audit practice and the other assessments available.

Learn more
Next step

Write down what you are assessing against, and who requires it.

If the second half is difficult to answer, the assessment will produce findings with no sponsor. That is worth resolving before commissioning anything, and it is a conversation rather than a project.

Book a gap assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Audit Readiness Assessment

Run the audit before the auditor does

Learn more

CIS Controls Assessment

Eighteen controls, assessed and re-assessed

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy