All articles
ComplianceGovernance

A Practical Guide to Finding (and Closing) Your Compliance Gaps

Every compliance program eventually faces the same question, usually a few weeks before an audit: where are we actually exposed? This is the method to answer it calmly and repeatably, before the audit does it for you.

Ilke Tosunoğlu
Ilke TosunoğluJuly 2, 20265 min readUpdated July 20, 2026
A repeatable, seven-step compliance gap-analysis loop laid out as a cycle.

Part of the pillar series Sovereignty You Can Actually Operate.

This is practical guidance for compliance teams, not legal advice. Current as of July 2026.

Gap analysis has a bad reputation because most organizations do it as an annual scramble: a consultant, a spreadsheet, a panic, a binder, and then eleven months of drift. It doesn't have to be that way. Done as a repeatable loop, gap analysis is the steady heartbeat of a compliance program. Here's the loop.

The seven-step gap-analysis loop

1 · Scope
2 · Inventory
3 · Map
4 · Find gaps
5 · Prioritize
6 · Remediate
7 · Evidence
↻ A continuous loop — step 7 feeds back into step 1.

1. Scope: which laws and frameworks apply? Start here, always. You fall under GDPR if you process personal data; NIS2 by sector and size; DORA if you're a financial entity; the CRA if you place a digital product on the EU market; the AI Act if you provide or deploy AI. Getting scope wrong produces false assurance, the most dangerous outcome, because you feel covered and aren't.

2. Inventory: what do you actually have? Your controls, their owners, and the evidence behind them, plus the assets, systems, data, AI use-cases, and suppliers they protect. You can't find a gap in something you can't see.

3. Map: connect controls to requirements. Map each control to the framework requirements it satisfies. Use the seven shared control domains and existing crosswalks (ENISA's NIS2→ISO 27001 mapping, NIST informative references). Don't invent a taxonomy.

4. Find the gaps. Two kinds: requirements with no control (a genuine hole), and controls with no or expired evidence: "orphaned controls" and "evidence rot." The second is the one audits actually fail on.

5. Prioritize: by risk × exposure × deadline. (The regulatory clock, and what's actually landing when, is laid out in the timeline.) Not every gap is equal. Weight by the harm if exploited, the likelihood an auditor or incident surfaces it, and the regulatory clock (DORA already applies; CRA reporting starts September 2026; the AI Act's high-risk obligations now land in December 2027 per the Council's final adoption of the Digital Omnibus).

6. Remediate: with owners and evidence targets. Every gap gets an owner, a due date, and a definition of the evidence the fix must produce. A remediation that doesn't produce evidence hasn't closed the gap in any way an auditor will accept.

7. Evidence: continuously. Keep evidence dated, inspectable, and current. Then loop back to scope, because the laws move.

The antipatterns that sink gap analyses

Three failure modes appear again and again. Name them so your team can catch them:

  • Evidence theater. Policies and questionnaires produced faster than the working controls behind them. The bottleneck is never documents; it's turning governance language into measurable, inspectable, system-linked evidence.
  • Policy without practice. A signed policy with nothing operational behind it. It passes a document review and fails a technical one.
  • False assurance from bad scoping. "We're aligned to ISO" is not "we meet NIS2." Alignment to a framework is not compliance with a law.

This is now a legal expectation, not a nice-to-have

Gap analysis used to be optional hygiene. Two laws made it an expectation. DORA requires documented, tested resilience: you must be able to show the gaps you found and closed. NIS2 requires evidence of implementation, not just policy, and its Article 20 makes management accountable for it. Regulators increasingly want to see the loop, not just the certificate.

Where Soveryne fits

The seven-step loop is a lot of connective work by hand, and it's exactly what Command automates. It runs gap analysis per framework: enroll the frameworks in scope, and Command shows you, requirement by requirement, where you have a mapped control with current evidence and where you have a hole: coverage, audit-readiness, and open gaps at a glance. Because controls are mapped across frameworks, closing one gap can close it in several places at once, and its continuous validation turns step 7 from an annual scramble into a live signal, so evidence rot surfaces the day it happens rather than the week before an audit. That's steps 2 through 7, operated.

And step 1 (scope) is a Counsel question: "does the CRA apply to our product?" or "are we an essential entity under NIS2?" answered from the regulations with citations. Coverage intelligence sets the scope; Command finds the gaps and proves they're closed.

FAQ

How do I do a compliance gap analysis? Scope the applicable laws, inventory your controls and evidence, map controls to requirements, identify gaps (missing controls and missing/expired evidence), prioritize by risk and deadline, remediate with owners, and keep evidence continuous, then repeat.

What's the most common reason gap analyses fail? Evidence theater (producing policies faster than the working, inspectable controls behind them) and bad scoping that creates false assurance.

How often should I run a gap analysis? Continuously, not annually. Regulations and environments change (the AI Act's deadlines moved in 2026), and evidence expires, so a point-in-time analysis is stale quickly.

Is gap analysis legally required? Not by name, but DORA requires documented, tested resilience and NIS2 requires evidence of implementation. Both effectively require you to find and close gaps and prove it.


Turn the annual scramble into a live signal. Run gap analysis per framework and keep evidence current with Command; settle what's in scope with cited answers from Counsel.

Sources