Skip to content
    August 25, 2026| Top Floor Team| 14 min read

    How Long Does Remediation Take After a Gap Assessment?

    Remediation after a gap assessment is the phase nobody can quote in advance, and the bands this site already publishes show why it is the widest one on every timeline: 8 to 12 weeks in our SOC 2 end-to-end timeline, two to nine months in our CMMC timeline, and roughly two to four months for the build-and-document phase in our ISO 27001 timeline. Same phase, a spread measured in quarters. We sell this work, so treat those as an interested party's figures. The contrarian point is that the length of the gap list predicts almost nothing. What predicts the calendar is the class of each gap: a missing document closes in days of work, a missing configuration closes in weeks, and a control that exists but has never operated cannot be closed by work at all. It closes by time.

    Below: the three classes and their three clocks, why process gaps close by time rather than by effort, the long-lead items that set the critical path, the clocks other people impose, what the published bands are made of, what compresses remediation, what blows it, and the case for a remediation length of zero.

    Key takeaways

    • Three classes of gap, three clocks. Missing controls close by building; designed-but-not-operating controls close by operating history; operating-but-not-evidenced controls close by capturing records that then have to accumulate.
    • The longest gaps are the process ones, because no amount of engineering effort creates a second occurrence of a monthly control this week.
    • Long-lead items set the critical path: a penetration test slot, a policy set that needs board approval, a vendor or identity migration, and any log or record that has to be genuinely old by the time it is examined.
    • Where a regulator sets a clock, it is explicit. Under 32 CFR 170.21 a CMMC plan of action must be closed out within 180 days of the Conditional CMMC Status Date. HIPAA sets no number and asks for a "reasonable and appropriate" level. SOC 2 has no regulator; its clock is the observation window you cannot open until remediation is done.
    • The published bands differ by framework mostly because the class mix and the staffing differ, not because one framework is intrinsically slower.

    Three classes of gap, three different clocks

    Our readiness assessment piece introduced the classification a gap list needs to be useful: each item is missing, designed but not operating, or operating but not evidenced. That trichotomy was written for the assessment. It is even more important for the remediation, because the three classes do not just cost different amounts. They close on different clocks.

    Class of gapExampleWhat closes itWhat sets the clock
    MissingNo vendor management policy; no multifactor authentication on administrative access; no asset inventoryBuilding it: writing, configuring, deployingEngineering and writing effort, plus any long-lead dependency
    Designed but not operatingAn access review procedure that exists and has never been run; a change approval step in the policy that nobody performsRunning it, then keeping it runningOperating history: the control has to produce enough occurrences to be examined
    Operating but not evidencedOffboarding that happens in a chat thread with no dated record; supplier reviews that live in an inboxCapturing the record at the point the control runsShort work, then the record has to accumulate; nothing backfills honestly

    Most gap lists are sorted by severity or by framework reference. Re-sort yours by class and the calendar changes shape, because the first class is the only one where adding people shortens the clock. The second and third are gated by elapsed time, and elapsed time is the input nobody can buy.

    Why process gaps close by time and not by work

    The mechanism is sampling, and it is owned elsewhere on this site rather than restated here: our piece on remediation plans auditors accept walks through why a fixed control can only be re-tested once it has produced occurrences to sample, and our SOC 2 timeline shows how the least frequent control in scope puts a floor under the whole calendar. The consequence for remediation planning is direct and is the single most useful thing in this article: list the second-class gaps by control frequency, ascending, and start the slowest ones on the first day of remediation, not the last.

    The CMMC piece states the practical rule the way we apply it: whatever the last remediation item is, "the calendar wants a further quarter of the control simply operating before anyone assesses it." That quarter is not padding. It is where an access review gets performed twice, where a retention setting is proven by records that are actually that old, and where the gap between the written procedure and the practice gets found by you rather than by an assessor. CMMC has no defined observation window; the rule still holds, because an assessor examines artifacts, interviews the operators and tests the control, and a control switched on last week produces one artifact and an operator who has done it once.

    This is also why "how long is remediation" and "when can the window open" are the same question for a SOC 2 Type II. Remediation is finished when the last control in scope is operating and producing records, and not before, whatever the engineering tickets say.

    The long-lead items that set the critical path

    A remediation plan sorted by severity fixes the scariest thing first. A remediation plan sorted by lead time finishes sooner. The items with the longest lead times, in rough order of how often they turn out to be the critical path:

    • A penetration test. Testers book out, a finding round adds a retest, and a control that says "annual penetration test" has not operated until the report exists. Our piece on how long a penetration test takes covers the scheduling reality. Book it in week one of remediation, not month three.
    • Policies that need governance approval. A policy set that goes to a board or an executive committee moves at that body's meeting cadence, and a control that requires annual management approval of policies has one occurrence per cycle.
    • Vendor and contract changes. Swapping a supplier, renegotiating a data processing agreement, or getting a sub-processor list published all involve a counterparty's calendar. Our DPA piece covers what those agreements have to contain.
    • Identity and offboarding coverage. The example in our remediation plan piece is the one we see most: offboarding covers everything behind single sign-on and misses the database that predates the identity provider. Bringing that system into the control is a migration, and migrations have their own calendar.
    • Records that have to be old. Log retention, backup restoration history, access review history. None of these can be created retroactively without it being visible that they were.

    The rule that follows: on the day the gap list arrives, pull out every item with an external dependency or an accumulation requirement and start those. The documentation gaps can wait a month without moving the date. These cannot.

    The clocks other people impose

    Some remediation windows are set by a regulator or a scheme, and where they are, they are explicit and worth knowing before you plan.

    CMMC. 32 CFR 170.21 states that "the closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date," and that a closeout assessment "assesses only the NOT MET requirements that were identified with POA&M in the initial assessment." The same section lists Level 2 requirements that may not be placed on a plan of action at all, among them the system security plan (CA.L2-3.12.4) and the physical access requirements, so those have to be closed before the assessment rather than after it. Our piece on CMMC POA&M rules covers what can and cannot be deferred in full. The 180 days is the one hard remediation clock in this article, and it starts after the assessment, which means a remediation plan that relies on it has already accepted a conditional status.

    HIPAA. The Security Rule sets no number. 45 CFR 164.308 requires a risk analysis that is "accurate and thorough," and risk management that will "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level," with a periodic evaluation "in response to environmental or operational changes." The clock is yours, and the defensibility of the pace is what an investigator later reads.

    ISO 27001. Our ISO timeline puts the gap between Stage 1 and Stage 2 at 4 to 8 weeks, set by how much remediation Stage 1 surfaces and by the certification body's calendar, and notes that bodies place a limit on how stale a Stage 1 can be before it must be repeated. The remediation window has a ceiling, and the ceiling is the body's, not yours.

    SOC 2. No regulator and no fixed window. The clock is the observation period, which cannot honestly open until the controls in scope are operating, and our SOC 2 timeline records that the commonest slip is not remediation running long but the interval between finishing it and formally opening the window.

    A customer contract. For most companies this is the real deadline, and it is negotiated rather than published. The seller-side view of that negotiation is how long a customer security review takes.

    What the published bands are made of

    The 8 to 12 week SOC 2 band in our startup guide and end-to-end timeline is stated for a startup with 20 to 100 employees, and the timeline piece is explicit that remediation is "the entire difference between the 6-to-12-month band and the 6-to-15-month one." Read that as a class-mix statement: a company arriving with offboarding, access reviews and change approvals already operating is remediating first-class gaps, and one arriving without them is remediating second-class gaps with a quarter of operating history attached to each.

    The two to nine month CMMC band is wider for two reasons the CMMC piece names. The content is heavier, with multifactor authentication, encryption of controlled unclassified information in transit and at rest, boundary protection and logging where most of it lands. And the staffing is often thinner: "one capable person doing scoping, remediation, documentation, and evidence collection in sequence takes roughly the sum of those durations, while a program with a technical owner and a documentation owner takes roughly the maximum." That serialisation problem is not specific to the defence supply chain. It is the reason two companies with identical gap lists finish a quarter apart, and our piece on staffing versus outsourcing compliance covers the arithmetic.

    One more band belongs here because it is the same work under a different name. Our compliance debt piece puts the repayment project for a company scoring 6 to 10 on its self-assessment at three to six months. Compliance debt is the drift between what the documentation claims and how the controls run, which is exactly the second and third classes of gap above, and the repayment plan it prescribes, ownership, cadence and an exception register, is remediation for a programme that used to work.

    What compresses remediation

    Classify before you schedule. The class tells you whether people help. Add engineers to first-class gaps; add calendar to the others.

    Start the slow controls first. Frequency ascending, day one. This is the whole content of the sampling argument applied to planning, and it is the difference between a window that opens on schedule and one that waits a quarter for an annual control to have run once.

    Two owners, not one. A technical owner and a documentation owner working in parallel, per the CMMC serialisation rule above. If one person is carrying both, the plan's dates are the sum of its parts.

    Evidence capture as part of the fix. When a control is stood up, decide in the same ticket which system is authoritative for its records and how they will be exported. A control that operates and leaves no record is a third-class gap you created during remediation.

    A compliance automation platform, for the right reason. It compresses evidence collection and it does not shorten a period; our SOC 2 timeline owns that argument. Buy one to make the third class of gap cheaper, not to make the second class faster.

    What reliably blows it

    Treating every gap as a document gap. A policy written for a control nobody runs converts a first-class gap into a second-class one and adds a quarter to the calendar while feeling like progress.

    Discovering the slow control late. The annual risk assessment, the annual disaster recovery exercise, the annual policy review. Found in month five of remediation, any of them moves the window by the time it takes to perform them once.

    Remediating to the report, not to the population. Fixing the two accounts an assessor found and not the class of account they belong to is the most common incomplete remediation our remediation plan piece records, and it comes back as the same finding next cycle.

    The interval after. Remediation finishes, everyone is tired, and the window does not open for a quarter because nothing forced it. Our SOC 2 timeline calls this the drift that quietly costs a quarter, and the fix is a window start date written into the engagement letter before remediation ends.

    Scope creep from the fix itself. Standing up single sign-on to cover offboarding brings every application behind it into scope. That is usually right and it is never free.

    The honest caveat: sometimes the right remediation length is zero

    Against our own interest, since the longer the remediation, the larger the engagement.

    Not every gap should be closed. Some should be accepted as risk, with a named owner and a written rationale, which is what a risk register is for and what an examiner will respect if it is recorded rather than reconstructed. Some should be descoped: a system that is in scope only because nobody drew the boundary carefully is a remediation project you can delete by redrawing the boundary honestly, and the scope decision is cheaper than any fix. And some gaps are examiner-relevant but not risk-relevant, in which case the question is whether the report is worth the work, and our SOC 2 timeline makes the case for reading your customers' actual security requirements before starting at all.

    What we cannot do, and neither can anyone else, is shorten the second class of gap with money. If your remediation is mostly controls that have never operated, the calendar is what it is, and a firm promising to compress it is promising to compress time.

    Where Top Floor fits

    The useful outside contribution is the classification, the lead-time sort, and a realistic date, followed by someone actually running the cadence so second-class gaps convert into operating history without a heroic month at the end. The first part is audit readiness work. The second is compliance as a service, which is, bluntly, the operating rhythm that turns a remediation plan into records. For what remediation costs rather than how long it takes, our SOC 2 cost breakdown owns the published figures and the budget planner carries a remediation line for each framework it models; note that those are cost bands, and this article deliberately does not turn them into durations.

    If your gaps are few, your owners are clear and most items are first-class, you do not need help. A shared document with four columns and a weekly review will do.

    How to decide this week

    Take the gap list and add two columns: class, and lead time. Sort by lead time descending and start the top five today, whatever their severity. Then sort the second-class items by control frequency ascending and ask, for each, when its first occurrence will happen if you start now. The latest of those dates plus the operating history an examiner will want is your earliest honest window start. If that date is later than the date a customer contract names, the conversation to have is with the customer about a Type I plus a committed Type II date, not with the team about working faster. Our Type I versus Type II guide covers that sequencing.

    Frequently asked questions

    Why is remediation the widest band on every compliance timeline?

    Because it is the only phase whose length depends on the starting state rather than on the framework. A gap assessment takes weeks whatever it finds; an examination takes weeks whatever it examines. Remediation takes the time needed to build what is missing, plus the operating history needed for controls that have never run, plus whatever long-lead dependencies sit on the critical path. Two companies pursuing the same report with the same scope can differ by a quarter or more, and the difference is almost entirely how many of their gaps are controls that exist only on paper.

    Which gaps should we fix first?

    The ones with the longest lead time, not the ones with the highest severity. Start anything with an external dependency, a penetration test booking, a vendor contract change, a governance approval cycle, and anything that closes by accumulation, such as a monthly access review that has never run or a retention setting that has to be proven by old records. Documentation gaps close in days whenever you get to them. A control that needs a quarter of operating history needs that quarter to start now.

    Is there a deadline for closing a CMMC plan of action?

    Yes. 32 CFR 170.21 requires the closing of a POA&M to be confirmed by a closeout assessment within 180 days of the Conditional CMMC Status Date, and the closeout assessment covers only the requirements that were assessed NOT MET and placed on the plan. Certain Level 2 requirements, including the system security plan, may not be placed on a plan of action at all and must be met before the initial assessment. Our piece on CMMC POA&M rules covers the eligibility rules in full.

    How do we estimate remediation before the gap assessment is finished?

    You cannot estimate it precisely, and anyone who quotes a number before seeing the gap list is quoting a habit. What you can do this week is estimate the class mix. Run the compliance debt self-assessment, which takes an afternoon: a low score means most gaps will be documentation and evidence capture, which close on your schedule; a high score means controls that exist on paper and have never operated, and those close on the calendar's schedule. The budget planner will give you a cost band for the remediation line; it will not give you a duration, and this article does not either.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.