Service
Before you commit to a certification budget, find out where you actually stand and what the distance really costs.
Before committing a budget to certification or a compliance route, you want three answers: where you stand today, what it takes to close the distance, and how long that will take. A gap analysis exists to produce those three. Everything else it produces is decoration.
Most organisations misjudge the distance in a predictable way. They overestimate what is missing in technology and underestimate what is missing in governance. The controls that turn out to be absent are rarely the technical ones. What is absent is that nobody owns the process, nobody reviews it, and nothing it does leaves a trace.
That distinction matters commercially, because the two kinds of gap have very different price tags.
Against ISO/IEC 27001:2022, covering both the management system requirements and the Annex A controls. Against the CyberFundamentals framework at the assurance level that applies to you. Or against both, which is the sensible option when NIS2 is the driver and you have not yet settled on a conformity route.
The frame should match the decision you are about to make. Measuring against a standard you have no intention of adopting produces an interesting document and no decision.
Organisations deciding whether to commit to ISO 27001 or a CyFun route, organisations that need a defensible number to put in a budget, and organisations that inherited a security programme and want to know what they actually own. It suits management teams who would rather have an uncomfortable baseline than a comfortable assumption.
A gap analysis is not always worth buying. If you already know you are a long way from the standard and you are committed to getting there anyway, the analysis mostly confirms what you know and delays the work. When that is your situation, I will say so and we can start on the implementation instead.
For a typical SME, one to two weeks, of which your team spends perhaps an hour each in interviews. You get the report within a week of the last conversation, because a gap analysis delivered late is a gap analysis delivered after the decision.
Very little. This is an assessment of governance and evidence, built on documents and conversations. It is not a penetration test or a technical audit, and where a technical examination is the right next step I will say so rather than improvise one.
No, and the difference matters. A gap analysis measures you against a standard. A risk assessment measures you against your own risks. A gap analysis will not tell you what matters most to your business, and a risk assessment will not tell you whether you would pass an audit. Certification requires the risk assessment; the gap analysis is what makes the road towards it predictable.
Then it is the cheapest bad news in the project. Every gap found now is a gap you plan for, rather than one a certification body finds under time pressure at your expense.
You can, and it is worth doing as a first pass. Be aware that internal self-assessments run optimistic in a consistent direction: people score the intention rather than the evidence, and nobody enjoys scoring their own area poorly. The value I add is mostly that I have no reason to be kind about it.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call