What happens in a cyber security gap assessment? A step-by-step walkthrough

A step-by-step cyber security gap assessment walkthrough: the five stages, the questions you'll be asked, framework scoring against Essential 8, NIST and ISO 27001, and what to do with the report.

A cyber security gap assessment is a structured check of where your security practices stand today against a recognised framework — Australia's Essential 8, NIST CSF or ISO 27001 — compiled into a report of findings and priorities that a non-technical owner can actually read. It is not a pass/fail exam and not a penetration test: nobody attacks your systems during one. This walkthrough covers exactly what happens, stage by stage, so you know what you are signing up for before you start.

Key takeaways

What a gap assessment is — and is not

A gap assessment answers one question: "where do we stand against the practices a framework expects, and what are the biggest gaps?" It is a guided questionnaire plus evidence review, scored and mapped to a framework, and delivered as a branded report of findings and priorities.

What it is not:

Stage 1: Scoping (30 minutes)

The assessor — or a self-guided platform — establishes the shape of the review: how many staff, what systems you run (email, accounting, file storage, devices), what data you hold, and any client or regulatory obligations. This decides which framework mapping makes sense. Australian small businesses most often map to the Essential 8 because the Australian Signals Directorate designed it as a practical baseline, while businesses with European or enterprise clients may be asked for ISO 27001 or NIST CSF coverage.

Stage 2: The guided questionnaire (1–2 hours)

The core of the assessment is a maturity-style question set. Questions are graded, not yes/no — each asks how regularly something happens, on a scale from "not consistently applied" to "automated and verified." For example:

You can complete it yourself or walk through it with the assessor in a session — the findings compile either way.

Stage 3: Evidence and verification

For each answer, light evidence confirms the practice is real: a screenshot of the MFA policy, a backup restore log, a recent phishing simulation result. This stage is what separates a gap assessment from a self-assessment survey — claims are checked, and maturity levels are scored on what can be shown, not what was remembered.

Stage 4: Framework mapping and scoring

Your answers are mapped to the chosen framework's controls — the Essential 8's eight mitigation strategies, NIST CSF's functions, or ISO 27001's Annex A — and each area is scored from Level 0 (not applied) to Level 3 (automated, verified, reviewed). The output is a maturity score per control area plus an overall score, so you can see at a glance that patching sits at Level 2 while backups sit at Level 0.

Stage 5: The report and priorities

The assessment compiles into a branded report a non-technical stakeholder can read: overall score, per-area maturity, the gaps ranked by risk, and recommended next actions. A useful report names the two or three fixes that reduce the most risk for the least effort — typically enforcing MFA everywhere, verifying backups restore, and standing up recurring phishing simulations with auto-enrolled remediation training.

What happens after the assessment

The report is only useful if it triggers work. The highest-leverage sequence for most small businesses:

  1. Close the technical quick wins first — MFA coverage, patching cadence, backup restore tests. These are configuration changes, not projects.
  2. Measure the human layer. The assessment flags training gaps; a monthly phishing simulation programme quantifies them. The benchmark that matters: an average 80% reduction in clicked links within eight months on monthly cadence — see how often you should run phishing simulations.
  3. Track movement monthly. Rolling assessment findings, training completion and phishing behaviour into one view — what human risk reporting is built for — turns a one-off snapshot into a trend your leadership or clients can see improving.
  4. Re-assess in 6–12 months to prove the gaps closed.

How long the whole thing takes

StageTypical time
Scoping30 minutes
Questionnaire1–2 hours (self-guided or facilitated)
Evidence review1–3 days
Scoring and report2–5 days
TotalUnder two weeks end to end

FAQ

What is a cyber security gap assessment? A structured assessment of where an organisation's security practices stand, scored against a framework such as the Essential 8, NIST CSF or ISO 27001 and compiled into a report of findings and priorities.

Is a gap assessment the same as a penetration test? No. A penetration test simulates attacks against your systems. A gap assessment reviews practices through a questionnaire and evidence — nothing is attacked or exploited.

Which framework should a small Australian business use? The Essential 8 is the usual starting point because the Australian Signals Directorate designed it as a practical prioritised baseline; ISO 27001 or NIST CSF mappings matter when clients or contracts require them.

Who fills in the assessment? The business owner or IT lead — it is a guided questionnaire you can complete yourself or walk through with the assessor in a single session.

How often should we repeat it? Every 6–12 months, or after a major change such as new systems, rapid headcount growth or an incident. Repeat assessments are also how you evidence improvement to clients and insurers.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.