We conduct a comprehensive vulnerability assessment using professional scanning tools with manual verification to filter false positives, classify vulnerabilities by CVSS, and provide a practical remediation roadmap.
What's included
- Select the target framework (NCA ECC-2:2024, SAMA CSF, ISO/IEC 27001:2022 or PDPL) and define the assets, systems and business units in scope
- Assess each control against the framework requirement and assign a compliance status (Implemented, Partially Implemented, Not Implemented, Not Applicable)
- Review policies, procedures and operational evidence and interview control owners to confirm controls work in practice, not just on paper
- Rate every gap by regulatory impact, severity and exploitability to drive remediation priority
- Produce a gap register and a remediation roadmap with timelines, effort estimates and clear ownership
- Surface quick wins that can be closed immediately ahead of longer-term projects
Methodology & standards
Scope and framework: agree the target framework, asset boundaries and assessment criteria
Evidence gathering: review documentation and configurations and run field interviews with the relevant teams
Gap analysis and rating: compare each control to the requirement and assign a compliance status and severity
Remediation planning: prioritize gaps and propose compensating controls and closure projects
Executive readout: present the overall compliance posture and the expected impact of remediation
Deliverables
- A detailed gap register with the compliance status and supporting evidence for each control
- A current-state versus target-framework assessment matrix
- A prioritized remediation roadmap with timelines and resource estimates
- A quick-wins list that can be closed within weeks
- An executive summary for the board covering overall compliance percentage and top risks
- A results presentation and a working session with the teams
Regulatory controls it satisfies
Typical timeline
A gap assessment typically runs two to four weeks depending on scope size, number of systems and the target framework.
Common questions
How is a gap assessment different from a formal audit?
A gap assessment is an internal advisory exercise that surfaces shortfalls and prioritizes remediation before a formal audit. It does not issue a certificate or a binding compliance verdict; it prepares you to pass one.
Can you assess against more than one framework at once?
Yes. We use a unified control-mapping matrix that measures a single control against several frameworks, for example NCA ECC, SAMA CSF and ISO 27001, to avoid duplicated effort and consolidate remediation.
From the same practice