Skip to content
    August 25, 2026| Top Floor Team| 12 min read

    How Long Does a Gap Assessment Take?

    A gap assessment against one framework, at a company with a defined scope, takes weeks rather than months, and the bands this site already publishes agree with each other: 2 to 4 weeks for the readiness phase in our SOC 2 end-to-end timeline, and 3 to 6 weeks for a gap assessment measured against the assessment objectives in our CMMC timeline. We sell this work, so read those as an interested party's figures. Here is the part the timeline graphics leave out: the number of requirements in the framework is not what sets the clock. The depth of evidence the assessor examines is, and that depth is decided at scoping, usually by whoever wrote the statement of work, usually without anyone noticing a decision was made.

    Below: what the exercise measures and the five steps NIST puts around it, where the weeks actually go, the three depths an assessment can be run at, what this site already publishes per framework, what compresses the calendar, what reliably blows it, and the case for a fast shallow one.

    Key takeaways

    • Weeks, not months: 2 to 4 weeks for the SOC 2 readiness phase and 3 to 6 weeks for a CMMC gap assessment, as this site already publishes. Neither is a floor and neither is a promise.
    • The depth of evidence is the calendar driver. An assessment can take people at their word, examine artifacts, or sample real populations, and each step deeper multiplies both the elapsed time and the value.
    • Your own response latency is the largest variable the assessor does not control. A document request unanswered for a week is a week of clock.
    • NIST CSF 2.0 describes the exercise as five steps. The gap analysis is step four. Step five, implementing the action plan, is where the months go, and it is a different purchase.
    • Assessing two frameworks in one pass takes less elapsed time than two separate assessments, because the interviews and the artifact requests are largely the same.

    What a gap assessment measures, and the five steps NIST puts around it

    A gap assessment measures the distance between the controls you operate today and what a named framework requires, and its deliverable is the shortfall list that becomes the remediation plan. The most careful public description of the exercise is not in any framework's own text; it is in NIST CSF 2.0, published February 26, 2024, which frames it as creating and using an Organizational Profile. NIST's section 3.1 lists five steps:

    • Scope the Organizational Profile. NIST notes that "an organization can have as many Organizational Profiles as desired, each with a different scope," and gives the example of a Profile scoped to an organisation's financial systems rather than the whole company.
    • Gather the information needed. NIST's examples are "organizational policies, risk management priorities and resources, enterprise risk profiles, business impact analysis (BIA) registers, cybersecurity requirements and standards followed by the organization, practices and tools (e.g., procedures and safeguards), and work roles."
    • Create the Organizational Profile. The Current Profile records the outcomes being achieved and "how or to what extent each outcome is being achieved"; the Target Profile records the outcomes selected and prioritised.
    • Analyze the gaps and create an action plan. In NIST's words: "Conduct a gap analysis to identify and analyze the differences between the Current and Target Profiles, and develop a prioritized action plan (e.g., risk register, risk detail report, Plan of Action and Milestones [POA&M]) to address those gaps."
    • Implement the action plan, and update the Organizational Profile. NIST adds that "an action plan may have an overall deadline or be ongoing."

    Steps one to four are the gap assessment. Step five is remediation, and it is the subject of how long remediation takes after a gap assessment. Keeping the two apart is the first thing that makes a timeline honest, because a proposal that quietly includes some of step five in an "assessment" price is describing a different engagement.

    NIST sells nothing, which is why it is the source here rather than a platform's readiness content, and the framing travels: the same five steps describe a SOC 2 readiness pass against the Trust Services Criteria, a CMMC gap assessment against NIST SP 800-171 (under 32 CFR 170.14 the Level 2 requirements are "identical to the requirements in NIST SP 800-171 R2"), or an ISO 27001 pass against Annex A. Only the Target Profile changes.

    Where the weeks actually go

    Four stretches of elapsed time, and only one of them is the assessor working alone.

    Scoping and kickoff, days. Which systems, which entities, which framework and which optional categories. This is short and disproportionate: everything downstream is a function of it, and it is the one deliverable a good readiness engagement is most valuable for, as our readiness assessment piece sets out. If the scope is still moving at kickoff, nothing below has a date.

    Information gathering, the longest stretch. Interviews with control owners, document requests, and reading. NIST's step two list above is a fair description of what gets asked for, and note what it implies: policies, a risk register, a business impact analysis, an inventory of practices and tools, and named work roles. A company that has none of those written down is not being assessed during this stretch; it is being inventoried, and inventorying takes longer than comparing. The assessor is mostly waiting on you here, which is why your response latency is the biggest variable in the whole calendar.

    Analysis and classification, days. The comparison itself, control by control, with each shortfall classified. The three states that matter are the ones the readiness piece names: missing, designed but not operating, and operating but not evidenced. That classification is what the remediation timeline is built from, and an assessment that hands you an undifferentiated list has skipped the step that made it worth buying.

    Reporting and readout, days. The written gap list, the sequencing, and a conversation about what to fix first. The sequencing is the product. A gap list is a to-do list; a sequenced gap list is a plan, and the difference is whether someone with judgement looked at which gaps block others and which take a quarter of evidence to close.

    The three depths, and why the deepest one is a different purchase

    The same framework, the same scope and the same company can be assessed at three depths, and the depth is what the statement of work is really pricing.

    DepthWhat the assessor examinesWhat it can tell youWhat it cannot tell you
    Interview-basedPeople describing the controls they operateWhich controls are claimed, and where nobody claims one at allWhether any of it is true
    Artifact-basedPolicies, configurations, tickets, screenshots, exportsWhether the control exists and is documentedWhether it operated consistently across a period
    Population-sampledReal populations (the full leaver list, the full change log), sampled the way an examiner willWhether the evidence would survive fieldworkNothing an examiner would not also find, which is the point

    The first depth takes days and is honest about what it is. The second is the normal gap assessment and takes the weeks above. The third is the rehearsal that turns a gap assessment into a readiness assessment, and it belongs to the readiness piece, which covers what that rehearsal buys and the three cases for skipping it. What matters for the calendar is that each step down adds elapsed time in your team, not in the assessor's: pulling a full population and answering sampling requests is your work, and it is the same work fieldwork will ask for later.

    Ask which depth is in the proposal, in these words. A firm that cannot say is going to run the first depth and invoice for the second.

    What this site already publishes, per framework

    Cited, not restated. Each row belongs to the article linked in it, and the phases are not all the same exercise.

    FrameworkThe phase our timeline namesPublished bandWhere it lives
    SOC 2Readiness: mapping what you do against the selected Trust Services Criteria and producing a gap list2 to 4 weeksHow long does SOC 2 take
    CMMC Level 2Gap assessment against the assessment objectives, not against the requirement sentences3 to 6 weeksHow long does CMMC take
    ISO 27001Phase one is scope and risk assessment under clauses 4.3 and 6.1.2, which is a different exercise from a gap assessment and precedes one4 to 8 weeksHow long does ISO 27001 take
    PCI DSSThe timeline separates the self-assessment path, which has no fieldwork clock at all, from the Report on Compliance path; the gap work sits inside the remediation clock on bothSee the articleHow long does PCI compliance take

    Two things to read off that table. The SOC 2 and CMMC bands overlap almost entirely despite the frameworks having nothing in common structurally, which is the evidence for the claim at the top of this article: the framework is not the driver. And the CMMC row carries a warning that generalises. The CMMC piece is explicit that a gap assessment run at requirement level "looks reassuring and misses most of the work," because the assessor tests objectives, not sentences. Every framework has an equivalent unit that the examiner actually works to, and an assessment measured against the wrong unit is fast because it is wrong.

    What compresses the calendar

    A scope decided before kickoff. NIST's first step exists for a reason. A Profile scoped to one product and the team that runs it is assessed in a fraction of the time of one scoped to "the company," and the honest scope is usually the narrow one.

    One named responder per control area. Not a team, a person, with the authority to pull the artifact and the calendar space to do it inside a day or two. Most of the elapsed time in a gap assessment is the interval between a request and its answer.

    An inventory that already exists. Systems, owners, vendors, data flows. If step two of NIST's list has to be built from scratch, the assessment is really two engagements.

    Two frameworks in one pass. The interviews are the same interviews and the artifacts are largely the same artifacts, so a combined assessment takes less elapsed time than two sequential ones. How much less depends on how much the two control sets actually overlap, and that number is directional, which our piece on framework overlap measures from this site's own mapping dataset rather than asserting.

    What reliably blows it

    Scope reopened mid-assessment. Every system added restarts information gathering for that system. Decide, then hold.

    Response latency. Said twice because it is the whole story. A team that answers requests in two days and a team that answers in two weeks buy the same assessment and experience very different calendars.

    Remediating during the assessment. It feels productive. It means the assessor is comparing against a moving baseline, and the report describes a state that no longer exists in either direction.

    The wrong unit of measurement. Requirement sentences instead of assessment objectives, Annex A control titles instead of what the control actually requires, Trust Services Criteria headings instead of the points of focus. Fast, reassuring, and wrong.

    The honest caveat: a fast gap assessment is a shallow one, and sometimes that is fine

    Against our own interest, since this is work we sell.

    If you already know your gaps specifically enough to assign them to people, an interview-based assessment lasting days is a legitimate purchase and a two-week artifact-based one is money that belongs in remediation. The readiness piece makes the same argument at length and names the three cases for skipping the engagement entirely. And there is a free version of the shallowest depth: the compliance debt self-assessment is ten questions you can score in an afternoon, and if the score is low and someone on staff clearly owns the programme, a paid gap assessment will mostly confirm what you know.

    The case where the deeper assessment earns its weeks is the mirror image: a first examination against this framework, evidence spread across tools nobody has inventoried, and a scope decision nobody internal can make with confidence. In that situation the two extra weeks are the cheapest weeks in the whole programme, because everything after them is scheduled off the output.

    Where Top Floor fits

    We run gap assessments and readiness engagements, and we never issue the report at the end, which is the independence structure the readiness piece explains and the reason we can tell you to buy the shallow version. Where we add the most is the front of the exercise: the scope decision, the choice of measurement unit, and the sequencing that turns a gap list into a plan. That is audit and readiness work when a specific examination is ahead, SOC 2 readiness when that examination is SOC 2, and it sits inside compliance as a service when nobody internal owns the calendar that follows. For what the engagement costs, our SOC 2 cost breakdown owns the published figures and the budget planner models them for your size.

    How to decide this week

    Answer three questions before you ask anyone for a proposal. First, what is in scope, written down as a list of systems and teams, and who has the authority to hold that list still for a month. Second, does anything in NIST's step two list already exist in writing, and if the answer is mostly no, budget for inventorying rather than assessing. Third, which depth do you actually need: if a customer contract names a date and this is your first examination, the population-sampled rehearsal; if your gaps are already obvious, the interview.

    Then, when the proposals arrive, compare them on the unit of measurement and the depth, not on the week count. A shorter number attached to a shallower depth is not a faster assessment. It is a different one.

    Frequently asked questions

    How long does a SOC 2 gap assessment take?

    Our SOC 2 end-to-end timeline puts the readiness phase, which is where the gap list against the selected Trust Services Criteria gets produced, at 2 to 4 weeks, and our SOC 2 startup guide publishes the same band. Treat it as an interested party's figure. What moves a specific engagement inside or outside it is the depth of evidence examined and how quickly your control owners answer requests, not the number of criteria in scope.

    Can we run a gap assessment ourselves?

    Yes, and NIST CSF 2.0 is written on the assumption that you can: its five Organizational Profile steps are addressed to the organisation, not to a consultant. The limit is not competence, it is charity. A team assessing its own documentation reads it the way it was meant rather than the way an examiner will, and the third depth in the table above, sampling real populations, is hard to do honestly against your own work. A self-run assessment is a sound first pass and a poor rehearsal.

    Does a gap assessment against two frameworks take twice as long?

    No. The interviews are largely the same interviews and the artifact requests largely the same requests, so the second framework adds analysis time rather than a second round of information gathering. How much it adds depends on how far the two control sets overlap, and that figure is directional rather than a single number; our framework overlap piece measures it from this site's own mapping dataset. Ask for both in one statement of work rather than buying them in sequence.

    What happens after the gap assessment?

    Remediation, which NIST calls implementing the action plan, and which is the widest band on every compliance timeline this site publishes. The output you should be holding is a sequenced gap list with each item classified as missing, designed but not operating, or operating but not evidenced, because those three classes close on three different clocks. Our piece on how long remediation takes works through what each class needs and which items belong at the front of the queue.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.