Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Gap assessment reassessment progress comparison diagram

Gap Assessment Reassessment: The Essential 2026 Guide to Measuring Progress

A gap assessment reassessment is a repeat of your original gap assessment, using the same method, to show which gaps have closed, which remain and whether new ones have appeared. It is how a one-off exercise becomes evidence of real improvement.

This guide explains when to reassess, how to keep results comparable, how to verify that gaps are truly closed and how to report progress. It builds on the scoping, scoring and remediation plan stages of the first assessment.

Why a gap assessment reassessment matters

A first assessment tells you where you stand. A reassessment tells you whether the effort since then worked. Leaders fund remediation more readily when they can see measured movement, and auditors trust progress that has been independently checked.

It also catches drift: controls that passed last year may have weakened after system changes, staff turnover or new suppliers.

When to schedule a gap assessment reassessment

Common triggers include the completion of a remediation phase, a fixed cycle such as every twelve months, a major change in the business, a new regulation or framework version and an incident that exposed unexpected weaknesses.

Do not wait until every gap is closed. A mid-programme check often shows which actions are working and which need a new approach.

Handling scope changes between rounds

Scope rarely stays fixed. A new business unit, a divested site or a switch to a new framework version can make raw comparisons misleading. Where scope grows, report the original scope and the expanded scope separately, so leaders can see progress on the baseline and the size of the new areas. Where scope shrinks, remove the affected items from both rounds before comparing. Write the scope decisions into the report, because unexplained changes make readers doubt the trend.

Keeping the method comparable

Use the same scope, framework version, questions, scoring scale and evidence rules as the baseline. If you change any of them, note the change and, where possible, rescore the baseline on the new basis so the comparison stays fair.

The guide to the maturity levels shows how to define the scale so results are stable from one round to the next.

Reviewing changes since the baseline

Before you begin, list what changed: new systems, sites, suppliers, policies, regulations and organizational structure. These changes may add requirements or invalidate earlier answers, and the list helps decide whether the scope needs to expand.

Reuse the earlier document set where possible, but check that each item is still current, and confirm whether your reference framework, for example the one described on the NIST Cybersecurity Framework page, has been updated.

ItemBaselineReassessmentChange
Access control maturity23Improved
Incident response maturity13Improved
Supplier oversight maturity22No change
Logging and monitoring21Declined, new system gap
Open high gaps146Down by 8

Timing and effort for the gap assessment reassessment

A repeat usually takes less time than the baseline because scope, questions and contacts are already defined. Plan a few weeks for a mid-sized organization: a week to review changes, two weeks for evidence and interviews and a week for scoring and reporting. Book interviews early, since availability is the most common cause of delay. Share the calendar with control owners so evidence requests do not arrive as surprises.

Verifying closed gaps in a gap assessment reassessment

A gap is closed only when evidence shows the control now operates. A published policy is not proof; a record showing the policy followed is. For each closed gap, gather fresh evidence and score it using the same rules as the baseline. The guide to evidence for gap assessments explains what to collect.

Where evidence is thin, downgrade the status to partly closed and set a follow-up date.

Interviews and sampling in the repeat exercise

Repeat the interview approach with the same roles where practical, and add anyone whose responsibilities changed. Use samples from the current period rather than reusing old ones, since the aim is to test present operation. See the note on gap assessment interviews for questions that work well.

Using automation to support reassessment

Some evidence can be collected automatically: configuration reports, access lists, patch status and training completion. Automated feeds shorten the exercise and improve accuracy, but they must be validated. Test that the reports cover the full scope and interpret exceptions with the control owner. Keep the exported evidence with the assessment so it can be reviewed later.

Finding new gaps in a gap assessment reassessment

Compare results item by item. New gaps often follow change, such as a cloud migration. Recurring gaps suggest that earlier remediation was superficial or that the root cause was never addressed.

Treat recurring gaps seriously and revisit their root cause instead of repeating the same action.

Comparing results in a gap assessment reassessment

Present the comparison in a table or chart: baseline against current by domain, the number of open gaps by severity and the trend in average maturity. The table in this article shows a simple format.

Explain declines as well as gains. Leaders trust a report that admits setbacks more than one that shows only good news.

Reprioritizing after the gap assessment reassessment

Use the new results to update the plan. Close completed items, raise the priority of gaps that worsened and add actions for new findings. Our guide to prioritization explains how to rank actions by risk, effort and dependencies.

Turning results into decisions

End the report with clear asks: which actions need budget, which risks need acceptance and which dates need to move. Give each ask an owner and a decision date. If nothing is decided, record why, so the next round starts from a known position rather than a repeat of the same discussion.

Sustaining momentum between reassessments

Progress fades when attention moves elsewhere. Hold a short monthly check on the remediation plan, publish a simple status view and celebrate closed gaps so teams see their effort recognised. Link objectives to remediation milestones for control owners, and share the next reassessment date early so preparation becomes routine rather than a scramble.

Reporting the gap assessment reassessment

Keep the report short: scope, method, headline results, comparison with baseline, main risks and decisions needed. Follow the same structure as the original, as covered in the guide to the gap assessment report structure, so readers can compare the two easily.

A worked example of a reassessment cycle

A mid-sized company completed its first assessment in January and found fourteen high gaps. Over nine months it fixed access reviews, wrote an incident response procedure and trained staff. In October the team repeated the assessment with the same questions and scoring rules. Access control maturity rose from two to three, incident response from one to three, and open high gaps fell from fourteen to six. Logging declined because a new application was never connected to monitoring, so a new gap appeared. The report showed all of this in one table and asked leaders to fund the logging fix and a supplier oversight programme that had not moved.

Common mistakes to avoid

Watch for these problems.

  • Changing the method so results cannot be compared.
  • Accepting policies as proof that gaps are closed.
  • Reassessing only the areas that improved.
  • Ignoring new requirements introduced since the baseline.
  • Skipping the update to the remediation plan.

Roles and responsibilities in the repeat exercise

Assign a lead who owned the baseline, so knowledge carries over, and add an independent reviewer for a share of the items to reduce bias. Control owners should present their own evidence, and the lead challenges it using the agreed rules. Keep sponsors informed: an executive who understands the method will defend the results when they show gaps that remain.

Record who assessed each area so future rounds can compare assessor effects and calibrate scores.

Reassessment versus audit

A reassessment is a management tool that measures progress against your target, while an audit checks conformity independently against a standard. The two support each other, and our comparison of gap assessment vs audit clarifies where each fits. Findings from audits should feed the next reassessment.

Using a structured workbook

A consistent workbook makes each round faster. The Gap Assessment Report and Workbook provides scoring, evidence and comparison fields that carry across cycles, so you can show trends without rebuilding the analysis each time. Whatever tool you use, protect the baseline and keep every round in a dated, controlled record.

Gap assessment reassessment FAQ

What is a gap assessment reassessment?

It is a repeat of a previous gap assessment using the same method to measure progress, verify closed gaps and find new ones.

How often should we reassess?

Typically every twelve months, and sooner after major change, remediation milestones or incidents.

Do we need to reassess everything?

Not always. Focus on areas that changed or were remediated, but include a sample of stable areas to catch drift.

How do we prove a gap is closed?

With current evidence that the control operates, such as records, logs, test results or interview confirmation.

Can we change the scoring scale between rounds?

Only with care. If you must, rescore the baseline on the new scale so comparisons remain fair.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.