Gap assessment vs penetration test: which should you run first?

A gap assessment checks your controls against a framework; a penetration test attacks your systems. See what each covers and which one to run first in 2026.

A gap assessment checks whether your security controls exist and line up with a framework like the Essential Eight, ISO 27001 or NIST CSF 2.0; a penetration test attacks your live systems to find what an attacker could actually break into. They answer different questions, and for most small and mid-sized businesses in 2026 the gap assessment is the one to schedule first.

Gap assessment vs penetration test at a glance

AspectGap assessmentPenetration test
Question it answersAre our controls in place?Can someone actually break in?
MethodStructured review against a frameworkEthical hackers probe systems and people
OutputScored gap list plus a prioritised roadmapTechnical findings ranked by severity
Who runs itInternal team or an assessment platformExternal security specialists
Typical durationDaysOne to three weeks
Sensible cadenceAnnually, or quarterly while remediatingAnnually, or after major system changes

What a gap assessment actually checks

A gap assessment is a structured review. It walks a defined control framework and asks, for each control, whether you have it, whether there is evidence, and where it sits on a maturity scale. The output is not a horror story — it is a scored list of gaps and a prioritised roadmap for closing them.

A typical assessment touches:

The framework you pick decides the shape. The Essential Eight, published by the Australian Signals Directorate, defines eight mitigation strategies across four maturity levels from Level Zero to Level Three, so you choose a target level and measure against it. ISO 27001 matters when a customer contract or certification requires it. NIST CSF 2.0 organises everything into six functions — Govern, Identify, Protect, Detect, Respond, Recover — and NIST publishes a dedicated Small Business Quick-Start Guide for organisations with modest or no existing plans.

What a penetration test actually finds

A penetration test is a simulated attack. Skilled testers probe your networks, applications and sometimes your staff, using the same techniques a real attacker would, and report back the paths they exploited.

Its strengths are real. It proves exploitability rather than intention — the difference between saying you have a firewall and showing how far someone got through it. It finds the misconfigurations and forgotten systems that a checklist review misses. And it produces findings ranked by severity, which is exactly the language an insurer, an enterprise buyer or a board wants to see.

Its limits matter just as much. A pen test examines a snapshot in time. It does not produce a remediation roadmap — you get a findings list, and the work of translating that into a plan is yours. And it is priced like a multi-week expert engagement, because that is what it is.

Why the framework behind the assessment matters

Two assessments can both be called gap assessments and produce completely different documents. The useful question is: assessed against what, and scored how?

A framework-anchored assessment gives you three things a generic checklist cannot. First, comparability — you can re-run the same assessment in six months and see movement. Second, recognisability — an assessor, insurer or enterprise customer who sees Essential Eight or ISO 27001 mapping understands your document without a briefing. Third, a defensible maturity target — saying you sit at Level 2 and are targeting Level 3 is a sentence a board can act on.

For Australian small businesses, the Essential Eight is the natural anchor because ASD guidance is free and the maturity levels are published. For businesses selling into the US or globally, NIST CSF 2.0 with its small-business quick-start guide works well precisely because it was designed for organisations of any size.

Which one should you run first

Run the gap assessment first. For most businesses under a few hundred staff, that is the honest verdict, and here is the logic:

The pen test earns its place after the basics are fixed: annually, after a major system change, or the moment a contract or insurer requires one. Until then, it is buying findings you could have found yourself for less.

Where a gap assessment stops

A gap assessment tells you a control exists on paper. It does not prove the control holds under attack, and it does not test your people in the moment — which is exactly what a phishing simulation measures. The two activities are complementary by design: the assessment finds the missing pieces, and the simulation tests whether the people-facing pieces you claim actually behave the way you say.

Where Cyber Aware fits — and where it does not

Cyber Aware's gap assessment scores your posture against the Essential Eight, ISO 27001, CSF and NIST CSF across maturity levels, and its human risk reporting produces the people-control evidence — training completion, simulation outcomes, per-learner risk — that a framework assessment will ask about.

The honest limit: Cyber Aware does not perform penetration testing or incident response. When a pen test is due, pair the platform with a specialist provider. If you are weighing platforms side by side, the compare page lays out the differences directly.

FAQ

How much does a gap assessment cost compared to a penetration test?

A gap assessment is typically a fraction of the cost of a penetration test, because it is a structured review rather than a multi-week expert engagement. Exact pricing depends on scope and platform — check current pricing before booking either.

How long does each one take?

A framework gap assessment usually completes in days once your evidence is assembled. A penetration test typically runs one to three weeks including scoping, testing and reporting.

Do I need both every year?

Gap assessment annually — or quarterly while you are actively remediating. Penetration test annually or after major system changes. Running both in the same year is common once the basics are in place.

Which framework should a small business use?

In Australia, the Essential Eight, because ASD publishes the controls and maturity levels free. Businesses selling internationally often use NIST CSF 2.0, which has an official small-business quick-start guide.

Does a gap assessment test our employees?

No. It checks whether people-controls exist and are evidenced. Testing behaviour in the moment requires phishing simulations and recurring training, which produce the completion and click evidence an assessor will ask to see.

One last thing

The two outputs feed each other. Fix the gap list, then let the pen test validate the fixes — and re-run the assessment six months later so the improvement is documented rather than remembered. Businesses that operate this cycle walk into insurer renewals and enterprise security reviews with evidence instead of anecdotes.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.