Anders m. Damgren
Head of Safety & Documentation
You know NIS2 has to be dealt with. The harder question is which requirements you already meet, which you don’t, and what to fix first. A NIS2 gap analysis answers that: It compares your current security practices with the requirements and shows the distance, area by area, so the work is mapped and prioritised before you commit budget to any of it.
Table of contents
What a gap analysis is, and why it comes first
A gap analysis is a systematic comparison of your current level with the required level. For NIS2 it means holding every requirement area in the directive and its national implementation up against your actual practices and documentation, so the result is a list of concrete gaps rather than a general sense of being behind.
The analysis comes first for a practical reason: prioritisation. NIS2 work competes with operations for the same people, and without a mapped starting point the effort spreads to wherever feels most urgent. With a mapped starting point you can put the effort where the gap is largest and where the consequence is most serious. It also gives management an honest basis to decide on, and under NIS2’s management accountability management must itself approve the risk management.
A gap analysis is not a legal requirement in itself. But the requirements to assess risks and to evaluate whether your measures are effective are difficult to meet without the overview the analysis provides.
What the analysis covers: the control areas
A covering NIS2 gap analysis reviews all of the requirement areas. In our model we work with 21 control areas that together cover the requirements, including:
- Roles and responsibilities, and the risk management policy
- Incident handling, reporting and post-incident review
- Monitoring and logging
- Business continuity, crisis management, backup and redundancy
- Supply chain security
- Security in the acquisition, development and maintenance of systems
- Access control, identification and asset management
- Cryptography
- Basic cyber hygiene and security training
- Human resources security, and physical and environmental security
The list also shows why NIS2 is not purely an IT project. Several of the areas concern organisation, people and physical premises, and the analysis therefore only gives a true picture if the right people take part: IT, operations and a management representative.
Three questions per area: status, gap and owner
For each control area the analysis has to answer three questions.
What do you have today? The actual practice and the actual documentation. Not what a policy from 2019 says, but what happens in the daily operation. The two are rarely identical, and the difference is a finding in itself.
How large is the gap? The distance between your current level and what the requirement assumes. Some gaps are documentation work, where practice is fine but not described. Others are real holes in the security, and the two types should not be prioritised the same way.
Who owns it? Every gap needs a named owner, otherwise the list becomes another document in the archive. The owner is not necessarily the person doing the work, but the person responsible for it getting closed.
- Status What you have
- Gap The distance
- Owner Who closes it
How to run one in practice
A gap analysis can be run as a document review, as interviews or as a single workshop. The workshop format is the fastest route to a shared picture: All areas are reviewed in the same room, with the people who own them, and disagreements about what is actually practice get settled on the spot instead of hiding in each department’s answers.
We offer the format as a free NIS2 gap workshop: three hours in which a NIS2 specialist reviews the 21 control areas with your team, on site or online. You leave with a shared picture of what is in place, where the gaps are, and what to prioritise first. If you later want the assessment captured in a formal, documented gap report, that can be produced as a separate service.
Whoever runs the analysis, one principle is worth holding on to: The person driving the method has to be able to read the technical content. A gap analysis that consists solely of questionnaires sent to departments measures how good the departments are at answering questionnaires.
Get a free GAP analysis
Three hour workshop with
Head of Safety, Anders M. Damgren.
From overview to action
The result of the analysis is a prioritised work list, and from there two routes exist. You can close the gaps with your own team, using the list as the steering document. Or you can bring in capacity for the bounded task, for example an interim NIS2 specialist who drives documentation, risk assessments and incident procedures together with your staff until the work is in place.
If you are unsure whether NIS2 applies to you at all, that is no reason to postpone the analysis. We have covered the criteria in our article on who is covered by NIS2, and if you supply covered companies, the documentation requirements come to you through the contracts in any case.
Contact us
Want to map how far you are with NIS2? Book a free NIS2 gap workshop, and we will review the 21 control areas with your team and leave you with a prioritised picture of what needs to happen.
FAQ
A systematic comparison of your current security practices and documentation with the NIS2 requirements. The result is a prioritised list of gaps with an owner on every item.
No. But the requirements to assess risks and to evaluate whether your measures work are hard to meet without the overview a gap analysis provides.
It depends on the format. A workshop-based review of all control areas can be done in three hours with the right participants. A full analysis with document review and a formal report takes longer.
Typically someone from IT, someone from operations and a management representative. The analysis only gives a true picture if the people who own the areas day to day are in the room.
Our workshop-based review of the 21 control areas is free and comes with no obligations. A formal written gap report and the subsequent implementation work are separate services.
You prioritise and close the gaps, either with your own team or with interim capacity for the bounded task. The most important thing is that every gap has an owner and a deadline, so the list does not end up as another document in the archive.
Yes, and it is often a good idea. The analysis shows where you stand whether the requirements come from legislation or from your customers’ contracts, and if you supply covered companies, they arrive either way.