A useful gap assessment is not a list of non-conformities but a work plan with priorities, owners and proof.
- A NIS2 gap assessment compares the status of your controls with the ACN basic security measures for the entity's category (important or essential).
- In Nispo the status comes from automated checks on the integrated systems, your team's documents and findings from services such as penetration tests.
- The result is a prioritised list of gaps, each of which can become a task with an owner and a due date, kept up to date over time.
How it works
A gap assessment answers three questions: which requirements apply, which are covered today, and what is missing and in what order to tackle it. It is not an audit or a certification: it is where the work starts.
- Category and scope. They determine the requirements: Annex 1 (important) or Annex 2 (essential) of the ACN measures.
- Control status. Automated checks update the technical controls; for the others the owner uploads the evidence.
- Classification. Each control is compliant, non-compliant, under review or not started.
- Priorities and plan. Gaps are ranked by priority and impact and become tasks with an owner and a due date.
Where the data comes from
| Source | Examples | How it gets in |
|---|---|---|
| Microsoft 365, Google Workspace, AWS, Google Cloud | Admin MFA, privileged accounts, devices, cloud resources | Automatically |
| Team documents | Approved policies, business continuity plan, training register | Upload and approval |
| Non-connected systems | Backups, firewalls, on-premise servers | Uploaded evidence |
| Suppliers | Questionnaires, DPAs, certifications | Supplier module |
| Security services | Penetration test and vulnerability assessment findings | Tasks in the register |
What you get
- The applicable requirements with the status of each, also by area.
- Gaps with priority and suggested action, already linked to owners and due dates.
- A PDF or CSV export for management or your consultant.
An illustrative example: in a 180-employee important entity the first gaps could be three admins without MFA (detected automatically), a business continuity plan never approved and a critical supplier without a questionnaire. Three different problems, in the same register.
Nispo shows what is covered by evidence, not whether a measure is adequate for your risk: that judgement stays with the organisation and, in supervision, with ACN.