Gap Assessment
A gap assessment is the structured comparison of your current environment against a target framework — SOC 2, ISO 27001, HIPAA, PCI DSS — producing a findings list and a prioritized remediation plan. It converts “we should get SOC 2” from an anxiety into a project with scope, sequence, and dates.
What separates a real one from a checklist
Template gap assessments mark controls present or absent. Useful ones judge sufficiency: whether your access review process would survive sampling, whether policies describe actual practice, and which gaps threaten the audit versus merely lengthen the punch list. That judgment is why assessments run by experienced practitioners change timelines and template-driven ones just change spreadsheets.
Observation Window — The observation window is the period a SOC 2 Type II report covers — typically 3 to 12 months — during which controls must demonstrably operate.
Penetration Test vs Vulnerability Scan — A vulnerability scan is automated and finds known issues; a penetration test is a human actively exploiting your defenses. Auditors and customers ask for both.
Statement of Applicability — The SoA lists every ISO 27001 Annex A control with your inclusion or exclusion decision and justification — the document certification auditors read first.