The exercise walks the framework requirement by requirement and grades your reality against each: in place, partial, or absent. Against SOC 2 that means mapping practices to the Trust Services Criteria; against ISO 27001, to the clauses and Annex A. Done honestly, it surprises in both directions — most engineering-led startups discover they already satisfy more than they expected through cloud defaults and good hygiene, while the gaps cluster in the unglamorous governance layer: risk assessments, vendor management, formal policies, documented reviews.
The deliverable is a gap register: each shortfall tied to the requirement it fails, sized by effort, and sequenced — which becomes the program plan and, once owners and dates attach, a remediation plan. Timing matters more than teams expect: gaps found now are engineering tickets, while the same gaps found during fieldwork are findings.
One distinction worth pinning down: a gap assessment measures you against the framework at the start of the journey; a readiness assessment measures you against the audit at the end of it. Teams that skip the first tend to discover their scope mid-program, which is the expensive place to learn it.
GRC platforms give you a rough automated cut the day you connect integrations — useful, but limited to what the software can see. A human-led assessment adds the parts machines miss: whether policies describe your actual practices, whether ownership exists, whether the scope you have in mind matches what customers will demand. Either way, the exercise only works if it is honest; a gap assessment graded generously just relocates the bad news to fieldwork.