Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Gap assessment scoring matrix ranking findings by risk and effort

Gap Assessment Scoring and Prioritisation 2026

Gap assessment scoring is what turns a long list of findings into a plan. A gap assessment compares what you do today against a standard, law or framework, and it usually finds dozens or hundreds of differences. Without a way to score them, teams either try to fix everything at once or start with the easiest items, leaving serious gaps open. A simple, consistent scoring method shows what to fix first and why.

This guide explains how to design gap assessment scoring: how to rate the current state, how to weight gaps by risk and effort, how to handle evidence and how to report the results.

What a gap assessment compares

A gap assessment sets a target, such as the requirements of ISO 27001, GDPR or an internal policy, and then checks the current state against each requirement. The NIST Cybersecurity Framework describes a similar idea with Current and Target Profiles, where the differences between them identify the gaps to address; see the NIST Cybersecurity Framework page. Whatever framework you use, the output is a requirement-by-requirement view of where you stand. For examples in specific standards, see our guides to an ISO 27001 gap analysis and a GDPR gap analysis.

Step 1: Rate the current state for gap assessment scoring

Start with a scale for how well each requirement is met. Four or five levels are enough, and each needs a written definition and an evidence rule.

RatingMeaningEvidence expected
Not metNo process or control existsNone
Partly metSomething exists but is incomplete or inconsistentSome documents or practices
Largely metWorks in most cases; minor gapsDocuments and records for most areas
Fully metWorks consistently and can be shownComplete documents, records and testing

Insist on evidence. A statement that “we do this” is a claim, not a rating. Score what you can demonstrate. If you use a maturity scale instead, see how frameworks such as the NIST CSF maturity levels define steps between levels.

Step 2: Weight the gaps

A count of unmet requirements treats a missing policy footer the same as a missing incident response process. Weighting fixes this. The simplest approach gives each requirement a weight based on the risk it addresses: high, medium or low. A high-weight requirement is one whose failure would cause serious harm, breach a legal duty or block certification.

Base weights on facts. Ask what happens if this requirement is not met: does it invite a fine, make a breach more likely, stop you passing an audit, or harm people? Record the reasoning for high weights, since they will drive priorities and may be challenged.

Add an effort estimate

Effort is a separate dimension. Rate each gap by the work needed to close it: quick win, moderate or major project. The combination of weight and effort gives a practical ranking. High-risk, low-effort gaps go first. High-risk, high-effort gaps need a funded project. Low-risk, low-effort gaps are batched. Low-risk, high-effort gaps may be deferred or accepted.

Step 3: Calculate the score

A workable gap assessment scoring formula multiplies the shortfall by the weight. For example, convert the rating into a shortfall (not met is 3, partly met 2, largely met 1, fully met 0) and multiply by the weight (high 3, medium 2, low 1). The result gives a priority score from 0 to 9. Sort by score, then use effort to break ties and plan work. Keep the arithmetic visible, so anyone can see how a score arises.

Avoid over-engineering. The aim is a defensible ordering, not an exact number. If two gaps have scores of 6 and 7 and you would treat them alike, the model is precise enough.

Step 4: Roll up the results

Leaders need a summary. Group requirements by domain, such as governance, access control and supplier management, and show the average or the number of high-priority gaps in each. A chart of domains by number of high-priority gaps quickly shows where the problems are. Overall percentages of compliance can mislead, because a high overall figure can hide a critical gap. Always show the highest-priority items next to any average.

Step 5: Turn scores into a remediation plan

Every high-priority gap needs an action, an owner, a target date and a way to verify closure. Our guide to a gap analysis remediation plan explains how to structure that step. Keep the scoring sheet and the plan linked, so that when an action closes, the requirement’s rating is updated with the new evidence.

Evidence rules for gap assessment scoring

Consistency comes from clear rules on what counts as evidence. Decide in advance whether interviews alone are enough (usually not), how recent records must be, whether a sample must be tested and who may rate a requirement. Ideally, someone other than the control owner rates each item, or at least reviews it. Owners tend to rate their own areas generously, and independent review improves accuracy and makes the result more credible to auditors and customers.

Handling requirements that do not apply

Some requirements will not apply to your organisation, such as controls for a service you do not offer. Mark them not applicable, with a written reason and an approver, instead of leaving them blank or rating them fully met. Auditors sample these exclusions, and an unexplained one is a weak point. Exclude them from the totals so that they do not distort the averages, but keep them in the record.

Communicating gap assessment scoring to non-specialists

Executives rarely want the full sheet. Give them one page: the overall position by domain, the five to ten highest-priority gaps in plain language, the effort and cost estimate for each, and the decisions you need. Translate technical requirements into business consequences, such as “we cannot show that we test our backups, which could delay recovery after an incident and would fail a certification audit”. Consequences prompt decisions; requirement numbers do not.

Linking scores to existing frameworks

If you assess against several standards, map the requirements once and reuse the ratings. Many controls satisfy more than one framework, so a single piece of evidence can support several rows. Comparing scores across standards will show where a single project closes gaps in several places at once, which is often the best return on effort. The related guide to an ISO 9001 gap analysis shows the same approach in a quality context.

A hypothetical example of gap assessment scoring

The following is a hypothetical example invented for illustration. A software company assesses its readiness for an information security certification and reviews 90 requirements. It finds 12 rated not met, 25 partly met, 30 largely met and 23 fully met. A simple count suggests a moderate position. After weighting, however, the top five priorities are a missing supplier assessment process, no tested incident response, weak access reviews, an incomplete asset inventory and no documented risk acceptance criteria.

Two of those are quick wins: an access review can be run in a fortnight, and risk acceptance criteria can be drafted in days. The incident response gap needs a plan and a test, and the supplier process needs a new workflow and some training. The company schedules the quick wins in the first month, funds the larger items over a quarter and defers a group of low-risk documentation gaps. The scores gave the team a clear order and a defensible reason for it.

Common mistakes in gap assessment scoring

Frequent errors include rating without evidence, counting all gaps equally, letting owners rate their own controls, mixing up effort and risk, using scales without definitions, presenting only an overall percentage, producing a list with no owners or dates, and never re-scoring after remediation. Another is treating the first assessment as final. Gaps close, new requirements appear and the score should move with them.

Re-scoring and tracking progress

Re-run the assessment at set intervals, such as quarterly during a certification project, and update ratings as evidence arrives. Track the number of high-priority gaps open, the number closed in the period and the number overdue. A trend line of high-priority gaps is the simplest measure of progress. If you are working towards certification, our ISO 27001 readiness assessment shows how a final check before the audit fits in.

A structured report for gap assessment scoring

A consistent report helps you record ratings, evidence, weights and actions in the same format. The Gap Assessment Report and Workbook provides a report and workbook for documenting requirement ratings, evidence and remediation. Whichever tool you use, keep the same scale and fields across assessments so results can be compared over time.

Gap assessment scoring FAQ

How many rating levels should we use?

Four or five. Fewer lose useful detail; more create arguments about small differences. Define each level in writing.

Should every requirement have the same weight?

No. Weight requirements by the risk they address, so that a missing critical control counts for more than a small documentation gap.

Who should score the gaps?

An assessor independent of the control owner, or at least a reviewer who checks evidence. Owners tend to rate themselves too generously.

How is effort used in the score?

Effort is kept separate from risk and used to sequence work. High-risk, low-effort gaps go first; high-risk, high-effort gaps need a funded plan.

How often should we re-score?

At intervals such as quarterly during a project, and whenever evidence changes or new requirements apply.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.