Glossary

Gap assessment

A gap assessment compares your current security practices against a framework’s requirements — SOC 2’s criteria, ISO 27001’s clauses, HIPAA’s safeguards — and produces the list of what is missing or partial. It is the standard first step of a compliance program: you cannot scope the work until the gap is measured.
Assemble Your GRC Team
Last updated July 26, 2026