What Is a PCI DSS Gap Analysis & What Should You Expect to Find?
Before an organization commits to a full PCI DSS assessment, most experienced QSAs recommend starting with a gap analysis. It is a lower-pressure, exploratory step that tells you where you actually stand before the clock starts on a formal engagement. Here is what a PCI gap analysis is, why it matters, and what typically comes out of one.
What Is a PCI Gap Analysis?
A gap analysis is a preliminary review of your environment against the requirements of PCI DSS, conducted to identify where you already meet the standard and where you fall short. Unlike a formal assessment, a gap analysis does not result in a Report on Compliance or an Attestation of Compliance. There is no pass or fail. Its entire purpose is to give you an honest, detailed picture of your current state so you can plan remediation before a real assessment begins.
Think of it as a diagnostic rather than a verdict. A good gap analysis walks through the same requirements a formal assessment would cover, but with more room for open conversation about your environment, your architecture, and the tradeoffs behind decisions you have already made.
Why It Matters
Walking into a formal PCI DSS assessment without knowing where your gaps are is a little like taking a final exam without ever seeing a practice test. You might do fine, but you are also just as likely to be blindsided by something you did not think to check ahead of time, whether that is a missing policy, an outdated network diagram, or a segmentation assumption that turns out not to hold up. A few reasons why a gap analysis is crucial:
-
It gives you a realistic remediation timeline before you are on the clock with an acquirer or a formal deadline.
-
It surfaces scoping issues early, before they turn into disputes during the actual assessment.
-
It helps you budget accurately, since remediation costs are far easier to estimate once you know specifically what needs to change.
-
It reduces the chance of surprises that stall or extend a formal assessment once it is underway.
For organizations going through PCI DSS for the first time, a gap analysis is close to essential. For organizations that have been through it before, a gap analysis before each renewal cycle is still worthwhile, since environments change and last year's clean report does not guarantee this year's will look the same.
What Happens During a PCI Gap Analysis
Scoping Discussion
The process usually starts with a conversation about your cardholder data environment: where data is stored, processed, or transmitted, which systems and third parties touch it, and how your network is segmented. This is where a lot of early surprises show up, since organizations sometimes discover a system is in scope that they had assumed was not, or vice versa. A gap analysis is often the first time an organization seriously considers reducing its PCI DSS scope rather than just documenting it as-is.
Documentation Review
The assessor will ask for existing policies, procedures, network diagrams, data flow diagrams, and evidence of current controls. If documentation is thin or out of date, that alone is often one of the first findings, since PCI DSS requires not just that controls exist but that they are documented and kept current.
Control-By-Control Walkthrough
The assessor works through the applicable PCI DSS requirements, comparing what the standard calls for against what your organization currently has in place. This is typically less formal than a full assessment interview, with more back-and-forth about why something is configured the way it is and what options exist to close a gap.
Findings Summary
At the end, you should receive a clear, organized summary of gaps, typically prioritized by risk and effort to remediate. A useful gap analysis report does not just list what is missing. It gives you enough context to understand why each item matters and roughly what closing it will involve.
PCI Gap Analysis vs. Risk Assessment vs. Formal Assessment
These terms get used loosely, and it is easy to conflate them. A gap analysis compares your current environment specifically against PCI DSS requirements and tells you where you fall short. A risk assessment is different: PCI DSS Requirement 12.3.1 calls for a targeted, requirement-specific risk analysis wherever the standard allows flexibility in how a control is implemented, and it has its own defined criteria. A general enterprise risk assessment does not automatically satisfy this requirement, even if your organization already performs one for other purposes. A formal assessment, whether a Report on Compliance completed by a QSA or a Self-Assessment Questionnaire, is the official process that results in a document you can hand to your acquirer or card brand as evidence of compliance.
A gap analysis sits before all of this, as preparation. It is not a required deliverable under PCI DSS and carries no official weight with your acquirer, but it is often the difference between a formal assessment that goes smoothly and one that turns up unpleasant surprises partway through.
How Long Does a PCI Gap Analysis Take?
A gap analysis is typically faster than a full assessment, often completed in two to four weeks depending on the size and complexity of your environment. Larger organizations, or those with multiple locations, complex third-party relationships, or a sprawling cardholder data environment, should expect that timeline to extend well beyond four weeks. Because there is no formal evidence package to assemble and no official report to produce, the process can still move more quickly and with less disruption to your team's day-to-day work than a full assessment would.
That said, rushing a gap analysis defeats its purpose. The value comes from a thorough, honest look at your environment, not from checking a box quickly so you can move on to the formal assessment. A gap analysis performed too hastily can miss the very issues it was meant to catch, leaving you no better prepared than if you had skipped it.
Common Findings
Every environment is different, but certain gaps show up often enough to be worth mentioning specifically. Most of these are not signs of negligence. They are simply the natural result of environments growing and changing faster than documentation and controls keep pace, which is exactly the kind of drift a gap analysis is designed to catch. Those common gaps may include:
-
Incomplete or outdated network and data flow diagrams that do not reflect the current environment.
-
Segmentation that looks solid on paper but has not been validated with actual testing.
-
Missing or stale policies, particularly around incident response, vendor management, and access control review.
-
Logging and monitoring that technically exists but does not cover all in-scope systems or is not reviewed consistently.
-
Third-party and vendor relationships that touch cardholder data without a clear compliance responsibility matrix in place.
-
Encryption or key management practices that do not fully meet current requirements, especially after a PCI DSS version update.
None of these findings are unusual, and none of them are cause for alarm on their own. The value of a gap analysis is catching them now, while there is time to plan and budget for remediation, rather than during a formal assessment when the clock is already running.
What to Expect After the Analysis
Once you have your findings, the next step is building a remediation plan. A good gap analysis report should make this easier by grouping findings into rough tiers, for example items that are quick fixes, items that need budget or vendor involvement, and items that require a longer-term architectural change.
Timelines for remediation vary widely depending on what turned up. Policy gaps can often be closed in weeks. Segmentation or architectural changes can take considerably longer, sometimes months, particularly if they involve new tooling or a network redesign. A realistic gap analysis report will be honest about which category each finding falls into rather than treating everything as equally urgent.
Many organizations use the gap analysis as the basis for a phased project plan, closing higher-risk and lower-effort items first while scoping out timeline and budget for the larger items. This also gives you a natural point to loop in your QSA for the formal assessment once the bulk of remediation is complete, rather than starting that engagement from a position of uncertainty.
Choosing Who Performs the Analysis
A gap analysis does not have to be performed by the same firm that eventually conducts your formal assessment, though there are advantages to using one that at least understands PCI DSS at the same depth a QSA would. Someone without hands-on assessment experience may miss nuances in scoping or interpret a requirement more loosely than an actual assessor would, which defeats some of the purpose of doing the exercise in the first place.
Look for the same qualities you would want in a QSA: relevant industry experience, a clear and collaborative process, and a track record of giving clients an honest picture rather than a rosy one. A gap analysis is only useful if it tells you the truth about where you stand, even when that truth is inconvenient.
Compass IT Compliance helps organizations conduct thorough, honest PCI DSS gap analyses that go beyond simply flagging problems. Our approach identifies where an environment falls short of compliance requirements and, just as importantly, translates those findings into a realistic remediation plan that fits the organization's resources and timeline. Rather than handing over a static checklist, we work with clients to prioritize gaps by risk and effort, so remediation efforts focus on what matters most. Reach out to us to get started.
Contact Us
Share this
You May Also Like
These Related Stories
.jpg)
When to Hire a PCI Compliance Consultant (and What They Actually Do)

What is a SOC 2 Gap Assessment? The First Step to Compliance

.webp?width=2169&height=526&name=Compass%20white%20blue%20transparent%202%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
No Comments Yet
Let us know what you think