A gap assessment is only as useful as the target state. Most are run against a framework nobody chose, which is why the findings never get funded.
The assessment compares your current position against a defined target and produces the work between them. The value depends entirely on whether the target is one your organisation actually has to meet, and on whether the output is a plan somebody owns rather than a list of differences.

- Target firstChosen deliberately, not inherited
- Evidence basedArtefacts rather than assurances
- Effort estimatedSo the plan is deliverable
- Owner per gapOtherwise nothing closes
Eight things that determine whether a gap assessment leads anywhere.
The target is chosen before anything is assessed
A regulatory obligation, a customer requirement, a certification you intend to pursue, a framework you have adopted, or an internal standard. Where an organisation has several, they are reconciled first. Running an assessment against a framework nobody has committed to produces findings with no sponsor, which is the most common reason gap reports are never actioned.
Frameworks are reconciled rather than stacked
Most organisations face several demands at once. The CIS Critical Security Controls at version 8.1 are described as prescriptive and prioritised, with version 8.1 adding updated alignment to evolving industry standards and frameworks. Using one as the working framework and mapping outwards is considerably cheaper than assessing separately against each.
The current position is established from evidence
An artefact, a configuration export, a report, a screenshot with a date. Not a workshop answer, because the person answering describes the intent and the evidence describes the reality, and the two differ without anybody being dishonest. Evidence-based assessment produces findings that survive an auditor rather than findings that surprise one.
A gap is described as work, not as a difference
The output of a comparison is a difference. The output of a useful gap assessment is a specific piece of work with a scope, an owner and an estimate. Improve access management is a difference. Implementing the account management and access control provisions for the named populations, with a completion test, is work somebody can plan.
Effort is estimated so the plan is deliverable
A list of forty gaps with no effort estimate cannot be sequenced, funded or committed to. Estimating each, even roughly, is what allows the organisation to distinguish the six that can be done this quarter from the four that are programmes, and it is what turns a report into something a budget cycle can absorb.
Every gap gets an owner, agreed rather than assigned
Gaps without owners do not close, and gaps owned by whoever commissioned the assessment do not close either. Agreeing ownership during the assessment, with the people concerned present, is uncomfortable and it is the single most reliable predictor of whether anything changes in the following year.
Accepted gaps are recorded as decisions
Some gaps will not be closed, for good reasons: cost, timing, business impact or a judgement that the risk is acceptable. That is a legitimate outcome provided it is recorded as a decision with a name and a review date, rather than left as an open item that quietly becomes permanent and is described afterwards as an oversight.
A re-assessment is scheduled at the outset
The second assessment is what makes the first one a programme rather than a document. Booking it before the first is delivered changes behaviour, because closing a gap stops being optional once there is a known date on which the same comparison will be run again in the same format.
Against what? If the answer is a framework nobody chose, the findings will not be funded.
A gap assessment inherits its authority from the target. Choose the target carelessly and the report has no sponsor, however good the analysis is.
- A regulatory obligation gives the findings a deadline and an external consequence. A customer requirement gives them a commercial one. A certification you intend to pursue gives them a date. All three produce funded work.
- A framework selected because it seemed comprehensive produces findings whose only advocate is the person who commissioned the assessment, and that advocacy runs out at the first budget conversation. The analysis is not wrong, it is unsponsored.
- Where an organisation faces several demands at once, which is normal, the answer is to reconcile rather than to stack. Assess once against a working framework and map outwards, which version 8.1 of the CIS Controls explicitly supports through its updated alignment to other standards and frameworks.
- That conversation takes an hour at the start and it determines everything afterwards. It is also the part most likely to be skipped, because agreeing the target requires the sponsor to commit to something before the findings are known.
Four things that make a gap assessment produce funded work.
We settle the target before we assess anything
Including whether the sponsor has committed to it. An assessment against a framework the organisation has not adopted produces findings whose only advocate is the commissioner, and that advocacy does not survive a budget conversation. An hour spent agreeing the target determines whether the rest of the work matters.
We ask for the artefact, not the assurance
Evidence-based assessment produces a position that survives an auditor. Interview-based assessment produces a position that surprises one. The difference is not honesty, it is that people describe what is intended and evidence describes what is operating, and the gap between those two is frequently the finding.
We write gaps as work with a completion test
A difference is not actionable. A scoped piece of work with an owner, an estimate and a test that determines whether it is finished can be planned, funded and closed. Writing the completion test at the same time as the gap is what prevents an item being marked complete when the intent has been addressed rather than the requirement.
We agree ownership in the room and book the re-assessment
Ownership assigned in a report is ownership nobody accepted. Ownership agreed with the person present is a commitment. Booking the re-assessment before delivering the first report converts the whole exercise from a description into a measurement with a known second data point, which is what makes remediation happen.
Four phases, and the first one is a conversation rather than an analysis.
- 01Week 1
Agree the target and the scope
What you are assessing against and why, which entities and environments are in scope, who the audience for the output is, and what decision the assessment is meant to support. Where several frameworks apply, they are reconciled into one working framework with mappings rather than assessed separately.
- A target state agreed and written down
- Scope defined by entity, environment and system
- The audience and the decision the output supports
- Framework mappings where several obligations apply
- 02Weeks 2 to 4
Establish the current position on evidence
Artefacts, configuration exports, reports and demonstrations rather than workshop answers. Where evidence cannot be produced, that is recorded as the finding rather than filled in with an assurance, because an assessment that accepts intent as evidence produces a position that will not survive an auditor.
- A position against every requirement, with evidence cited
- Requirements where evidence could not be produced, recorded as such
- Partial compliance distinguished from full and from absent
- Evidence retained in a form reusable for the next assessment
- 03Weeks 5 to 6
Turn differences into work
Each gap written as a specific piece of work with a scope and a completion test, an effort estimate sufficient to sequence and fund it, and an owner agreed with the person concerned present. Quick wins separated from programmes so the first quarter shows movement rather than mobilisation.
- Gaps expressed as scoped work with completion tests
- Effort estimated well enough to sequence and fund
- An owner agreed for each, in the room
- Accepted gaps recorded as decisions with review dates
- 04Ongoing
Track closure and re-assess
Progress reported in the same format as the assessment, so movement is directly visible. Then a re-assessment at the interval agreed at the outset, producing a comparable position. That comparison is the artefact that funds the following year, and it only exists if the first assessment was structured for it.
- Progress reported in the assessment format
- Re-assessment scheduled from the start
- A directly comparable second position
- Remaining gaps re-prioritised rather than re-discovered
Six UAE situations where a gap assessment is the right engagement.
A firm that has been given a regulatory expectation to meet
The clearest case, because the target is external, the sponsor is obvious and there is usually a date. The assessment maps each requirement to a control, establishes the position on evidence, and produces the work between. That work has a deadline attached, which materially improves the chance of it being resourced.
A business that has decided to pursue certification
The target is the standard and the date is the intended certification. What matters here is that documentation, process and evidence of operation are assessed alongside technical controls, because a management system standard is satisfied by demonstrable operation rather than by configuration alone.
An organisation answering an increasing number of customer questionnaires
Each questionnaire is a different target expressed differently. The efficient approach is one assessment against a working framework, mapped outwards, so the second and third questionnaires cost a fraction of the first. Version 8.1 of the CIS Controls explicitly supports this through its updated framework alignment.
An operator with an internal standard nobody has written down
A common and awkward case. The organisation has a view of how things should be, held collectively and inconsistently. The first phase here is writing the target down, and that exercise frequently produces more value than the assessment that follows, because it surfaces disagreements nobody knew existed.
A group standardising across several entities
The same assessment, run identically across each entity, produces a comparable position that a group function can act on. Assessing entities against different targets, or by different methods, produces documents that cannot be compared and therefore cannot support a group-level decision.
An organisation that has had a gap assessment and done nothing with it
Worth diagnosing before repeating. Usually the target was inherited rather than chosen, the gaps were written as differences rather than work, or nobody owned them. Re-running the same assessment fixes none of those, and the second report meets the same fate as the first.
How UAE organisations use gap assessments.
| Feature | Targeted, evidenced and owned | Assessed, reported, filed | No formal assessment |
|---|---|---|---|
Target chosen deliberately | Yes | Inherited | Not applicable |
Position established on evidence | Yes | On interviews | No |
Gaps expressed as scoped work | Yes | As differences | No |
Effort estimated | Yes | No | No |
Owner agreed per gap | Yes | No | No |
Accepted gaps recorded as decisions | Yes | Left open | Not applicable |
Progress reported in the same format | Yes | No | No |
Re-assessment scheduled | Yes | No | No |
Findings funded | Usually | Rarely | Not applicable |
Value a year later | A programme | A document | None |
Seven target states, and what each implies for the assessment.
| Target state | What it implies for the assessment | |
|---|---|---|
| A prescriptive control framework | Specific findings against named controls, with a prioritised order already built in | |
| A management system standard for certification | Documentation, process and evidence of operation as much as technical controls | |
| A payment card obligation | Scope definition first, since what is in scope determines most of the work. PCI DSS v4.0.1 is current | |
| A regulatory expectation | Mapping each requirement to a control, and evidence of operation rather than of intent | |
| A customer security requirement | Answering their questionnaire directly, with evidence behind each answer | |
| Application security expectations | Assessment against the current published list, which is the OWASP Top Ten 2025 | |
| An internal standard or an architecture target | The target has to be written down first, because most internal standards are implicit |
Five steps, and the first is a conversation about the target.
- 1
Agree the target, the scope and the audience
What you are assessing against, who requires it, whether there is a date, which entities and environments are in scope, who reads the output and what decision it supports. Where several obligations apply they are reconciled into one working framework with mappings, rather than assessed separately at several times the cost.
- 2
Collect evidence rather than answers
Artefacts, configuration exports, reports and demonstrations. Where evidence cannot be produced, that is recorded as the finding. Partial compliance is distinguished from full and from absent, because the three imply different amounts of work and collapsing them makes the plan unusable.
- 3
Establish the position against every requirement
With the evidence cited against each, so the assessment can be reviewed rather than trusted. Evidence is retained in a form that can be reused at the next assessment, which is what makes the second one substantially cheaper than the first.
- 4
Convert gaps into scoped, owned, estimated work
Each written as a specific piece of work with a completion test, an effort estimate sufficient to sequence and fund it, and an owner agreed with that person present. Quick wins separated from programmes, and gaps the organisation chooses not to close recorded as decisions with names and review dates.
- 5
Report progress in the same format, and re-assess
So movement is directly visible rather than described. The re-assessment is scheduled at the outset, and it produces a comparable position rather than a fresh discovery. That comparison is the artefact that supports the following year investment case, and it only exists if the first assessment was built for it.
What organisations ask about gap assessments.
Fifteen questions worth answering before an assessment starts.
The target
- What are you assessing against, exactly?Name it.
- Who requires it?A regulator, a customer, a board, or nobody.
- Is there a date attached?A deadline changes everything.
- Do several obligations apply?Then reconcile before assessing.
- Has the sponsor committed to the target?Before the findings, not after.
Scope and evidence
- Which entities and environments?Groups often assess one.
- Are third-party managed systems included?They usually should be.
- Can you produce evidence, or only answers?The difference matters.
- Who can grant read access?It shapes the method.
- Is there a prior assessment to compare with?Comparison beats repetition.
The output
- Who reads the report?It changes the form entirely.
- What decision does it support?Funding, certification, or assurance.
- Is there budget for remediation?Or is this an awareness exercise.
- Who will own the gaps?Agree before, not after.
- When is the re-assessment?Book it at the start.
Write down what you are assessing against, and who requires it.
If the second half is difficult to answer, the assessment will produce findings with no sponsor. That is worth resolving before commissioning anything, and it is a conversation rather than a project.
Related Services
Explore more solutions that work great with this service
Audit Readiness Assessment
Run the audit before the auditor does
CIS Controls Assessment
Eighteen controls, assessed and re-assessed
IT Risk Assessment
A short register with an owner against every risk
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
Cybersecurity Audit
Security assessment and compliance audit
Compliance as a Service
Keeping the position true between assessments