A gap analysis is just a structured comparison: what the standard requires, versus what you actually have in place today. Consultants charge real money for this specifically because most people don't know how to structure the comparison — not because the comparison itself is hard.
The structure
- Step 1 — list what you have, not what you think you should have. Go control by control through all 93 Annex A controls and write down, honestly, what currently exists — not what you plan to build.
- Step 2 — mark applicability first, implementation second. Some controls genuinely don't apply to you (physical security controls for a fully remote company, for instance). Deciding "not applicable" with a real reason is progress, not avoidance.
- Step 3 — score what remains as Not Started / In Progress / Implemented. Resist the urge to mark something "in progress" because you intend to get to it — that's the single most common way self-led gap analyses become inaccurate.
- Step 4 — sort by effort, not by control number. Some gaps (enabling MFA, documenting an existing process) take an afternoon. Others (a full risk assessment, a formal supplier review process) take weeks. Do the cheap, high-impact ones first.
The trap to avoid
The most common failure mode isn't missing controls — it's a gap analysis that's technically complete but was never grounded in real risk. Controls chosen because a risk assessment actually surfaced them hold up far better under audit than controls chosen because they were next on the list.
What "done" looks like
A finished gap analysis is really just the first draft of your Statement of Applicability — the same 93 rows, now with real, specific justification instead of blanks. If you can defend every applicability decision in one sentence, you've done the work a consultant would have billed for.