Gap analysis against ISO 27001, NIS2 or DORA
Where do you stand today against the requirements of ISO 27001, the Swedish Cybersecurity Act (NIS2) or DORA? A gap analysis gives a documented current state, gaps per requirement and a prioritised action plan that management can decide on.
Who it is for and when
The gap analysis suits organisations that need to meet a regulation or a standard and want to know exactly what is missing before they start building.
- You are affected by the Cybersecurity Act or DORA and need to know where the gaps are.
- A customer, owner or procurement requires ISO 27001 or an equivalent management system.
- You have security work in place but lack a consolidated picture of what exists and what is missing.
- Management wants decision material with priorities, not a list of seventy deficiencies.
What we do
- Requirements and scope. We establish which regulation or standard applies, which parts of the business are affected and which requirements are relevant for you.
- Interviews and document review. We go through policies, procedures, risk work, incident handling, continuity and supplier governance with the people who own the questions.
- Gap per requirement. Every requirement is assessed: in place, partly in place or missing, with a short justification and evidence.
- Prioritised action plan. Actions are prioritised by risk and benefit, with proposed ownership and order.
- Review with management. We present the current state, gaps and plan so that decisions can be made directly.
You get
- Documented current state against the chosen regulation or standard
- Gaps per requirement with assessment and evidence
- Prioritised action plan with proposed ownership and order
- Presentation and review with management
- Material that can be used directly in the continued work
Scope and price
A defined engagement that takes from a few days to about a week depending on the size of the organisation, how many requirements are assessed and how much documentation exists.
The price varies from engagement to engagement and depends on the scope above. You get a fixed price in the proposal, so you know what the analysis costs before we start.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
How long does a gap analysis take?
From a few days for a smaller organisation in good order to about a week for a larger organisation or several regulations at once. The time is driven by how many people need to be interviewed and how much documentation exists.
Can you do the gap analysis against several regulations at the same time?
Yes. ISO 27001, NIS2 and DORA overlap to a large extent. We assess common requirements once and report what is specific to each regulation, so that you avoid parallel analyses.
What happens after the analysis?
You own the result and can deliver the plan yourselves. If you want support in delivery we continue with the parts you choose, for example the management system, risk work or incident preparedness.
Want to know where you stand against the requirements?
Contact us