What is a security gap assessment?

A security gap assessment compares your controls against a benchmark like Essential Eight or SMB1001 and lists every gap. What it covers, the steps, and how often to run one.

A security gap assessment compares what your business actually does about cyber security against a benchmark you are expected to meet — Essential Eight, SMB1001, ISO 27001 or a client's own security questionnaire — and produces a ranked list of everything missing in between. It is the starting point for nearly every certification project, insurance renewal and serious client contract, because "we're probably fine" is not an answer any of them accept.

Key takeaways

What is a security gap assessment?

A gap assessment answers one question: where does what we do fall short of what we are supposed to do?

It produces three outputs. First, a picture of your current state — which controls exist, which are partial, which do not exist at all. Second, a ranked gap list, ordered by how much risk each gap leaves on the table. Third, a remediation plan with owners and dates, so the findings become work instead of a PDF nobody opens again.

The benchmark is what makes it an assessment rather than an opinion. Without a framework to measure against, every finding is arguable. With one, every finding maps to a control an auditor, a client or an insurer will eventually ask about — and you can put a number on how far away you are.

Gap assessment vs security audit vs penetration test

Gap assessmentAuditPenetration test
Question answeredWhat are we missing?Did we follow the rules?Can we be broken into?
OutputA ranked list of gapsA compliance verdictExploit findings
Best usedBefore an uplift or certificationPeriodic compliance checksOnce the basics are in place

The three overlap, but they answer different questions and run in that order in practice: gap assessment first, audit to confirm, penetration test to stress-test the result.

What a gap assessment covers

A useful assessment walks the same ground the frameworks do:

How a gap assessment works, step by step

  1. Pick the benchmark. Essential Eight if you serve government or want the Australian default; SMB1001 for small-business certification; a client's own questionnaire if a contract drives the deadline.
  2. Score the current state against each control — with evidence, not memory.
  3. Rank the gaps by risk and effort. A backup that has never been restore-tested outranks a policy rewrite.
  4. Build the remediation plan with a named owner and a date for each item.
  5. Re-check the open items on a fixed date, and repeat annually.

Why small businesses run one

The price of not knowing is on the record. ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — one every 6 minutes — and the average self-reported cost of cybercrime to small business rose 14% to $56,600. Business email compromise fraud, an attack that needs no technical gap at all, just an untrained payment process, accounted for 15% of business cybercrime reports that year.

At the global end of the scale, IBM's 2026 Cost of a Data Breach Report puts the average breach at USD 4.99 million, up 12% year over year. A small business will never see that figure, but the proportion is the point: the cheapest time to find a gap is before someone else finds it for you.

How often should you run a security gap assessment?

Annually as a baseline, plus after any material change: a new line-of-business system, a new certification target, a new major client whose contract carries security clauses. Frameworks move — Essential Eight maturity levels get revised, SMB1001 is updated edition by edition — so a two-year-old assessment is a historical document, not a current one.

From findings to fixes

Most gaps in a small business are process gaps, and two of them — training records and phishing-simulation evidence — are among the fastest to close and the easiest to evidence later. Cyber Aware's gap assessment turns your training and phishing data into the evidence pack those frameworks ask for, and human risk reporting keeps it current month after month.

FAQ

What is a security gap assessment? A structured comparison of your current cyber security controls against a benchmark such as Essential Eight or SMB1001, ending in a ranked list of gaps and a remediation plan.

How long does a gap assessment take? Long enough to gather real evidence for each control and short enough to act on. The pace is set by how quickly you can produce evidence, not by the framework itself.

What is the difference between a gap assessment and a risk assessment? A gap assessment measures you against a defined target. A risk assessment identifies and rates risks generally, with no fixed benchmark to measure against.

Is a gap assessment required for Essential Eight or SMB1001? Certification against either framework starts by knowing where you stand, so an assessment is the standard first step — though neither mandates one specific document.

How much does a gap assessment cost? It varies with scope. A self-service assessment costs staff time; a consultant-led one is priced per framework and per site. Check current pricing before you commit.

What happens after a gap assessment? A ranked remediation plan. Fix the high-risk gaps first, re-check on a date, and keep the evidence — it doubles as your audit pack.

One last thing

The most common finding in a small business gap assessment is not a missing firewall. It is missing evidence: the control exists, but nothing was ever written down. Documentation is the cheapest gap you will ever close, and the first thing an auditor asks for.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.