NIS2 · GDPR · ISO 27001 · DORA

Compliance gap analysis

We assess your organisation against NIS2, GDPR, ISO 27001 and DORA and deliver a prioritised action plan within 3 to 5 business days.

Book a call Analysis in 3 to 5 business days Report with risk levels

We don't start blind

Scope and costs depend on your organisation and the relevant frameworks. We fix both only after a personal conversation.

Request an analysis

Our compliance analyses

Individually or combined where frameworks overlap.

NIS2 gap analysis

Assessment against all NIS2 requirements: risk management, incident response, supply chain security and reporting obligations.

GDPR analysis

Data protection compliance under GDPR: processing records, data subject rights, technical and organisational measures (TOMs) and data protection impact assessment.

ISO 27001 & DORA

ISMS per ISO 27001 or digital operational resilience for the financial sector per DORA: ISMS setup, controls assessment, documentation and certification preparation.

What you receive

The outcome of the analysis, documented and prioritised.

Detailed gap report

Complete documentation of all identified gaps with risk assessment (critical/high/medium/low) and compliance impact. Clearly prepared for management and technical teams.

Prioritised action plan

Structured implementation plan with short-term, medium-term and long-term measures. Realistic timeline and resource estimates for implementation.

Concrete recommendations

Technical and organisational measures for each gap, plus concrete recommendations on tools and processes.

How the gap analysis works

Three steps, from the first call to the report.

  1. First call

    We clarify your organisation, the relevant frameworks and the scope and costs of the analysis.

  2. Analysis

    Document review, technical assessments and interviews with the people responsible, within 3 to 5 business days.

  3. Report and implementation

    You receive the report with all gaps, risk assessments and a prioritised action plan. On request we support the implementation or work together with your internal team.

Common questions

What does a compliance gap analysis include?
A compliance gap analysis evaluates your current security posture against regulatory requirements (NIS2, GDPR, ISO 27001, DORA). You receive a detailed list of all gaps, a prioritised action plan for remediation and concrete recommendations. The analysis covers technical controls, processes, documentation and organisational measures.
For which compliance frameworks do you offer gap analyses?
We analyse against NIS2 (Network and Information Security Directive), GDPR, ISO 27001, DORA (Digital Operational Resilience Act) and industry-specific standards. Where the frameworks overlap, we can combine analyses so you save time.
How long does a gap analysis take?
A standard gap analysis takes 3 to 5 business days. This includes document review, technical assessments, interviews with the people responsible and creation of the final report with a prioritised action plan.
What happens after the gap analysis?
You receive a detailed report with all identified gaps, risk assessments and a prioritised action plan. We are happy to support you with implementing the measures or work together with your internal team.

Ready?

Request the gap analysis

Start with a first call. It clarifies frameworks, scope and the costs of the analysis.

Book a first call

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.