A useful gap assessment is not a list of non-conformities but a work plan with priorities, owners and proof.

Key facts
  • A NIS2 gap assessment compares the status of your controls with the ACN basic security measures for the entity's category (important or essential).
  • In Nispo the status comes from automated checks on the integrated systems, your team's documents and findings from services such as penetration tests.
  • The result is a prioritised list of gaps, each of which can become a task with an owner and a due date, kept up to date over time.

How it works

A gap assessment answers three questions: which requirements apply, which are covered today, and what is missing and in what order to tackle it. It is not an audit or a certification: it is where the work starts.

  1. Category and scope. They determine the requirements: Annex 1 (important) or Annex 2 (essential) of the ACN measures.
  2. Control status. Automated checks update the technical controls; for the others the owner uploads the evidence.
  3. Classification. Each control is compliant, non-compliant, under review or not started.
  4. Priorities and plan. Gaps are ranked by priority and impact and become tasks with an owner and a due date.

Where the data comes from

SourceExamplesHow it gets in
Microsoft 365, Google Workspace, AWS, Google CloudAdmin MFA, privileged accounts, devices, cloud resourcesAutomatically
Team documentsApproved policies, business continuity plan, training registerUpload and approval
Non-connected systemsBackups, firewalls, on-premise serversUploaded evidence
SuppliersQuestionnaires, DPAs, certificationsSupplier module
Security servicesPenetration test and vulnerability assessment findingsTasks in the register

What you get

  • The applicable requirements with the status of each, also by area.
  • Gaps with priority and suggested action, already linked to owners and due dates.
  • A PDF or CSV export for management or your consultant.

An illustrative example: in a 180-employee important entity the first gaps could be three admins without MFA (detected automatically), a business continuity plan never approved and a critical supplier without a questionnaire. Three different problems, in the same register.

Nispo shows what is covered by evidence, not whether a measure is adequate for your risk: that judgement stays with the organisation and, in supervision, with ACN.

A 30-minute demo: we connect your systems (Microsoft 365, Google Workspace, AWS or Google Cloud) and show you your real controls, evidence and gaps.