A pre-assessment exercise where an organization compares its existing cybersecurity practices against required standards such as NIST SP 800-171. The analysis highlights areas of non-compliance, helping organizations understand what work must be done before a formal CMMC assessment. A gap analysis often results in actionable recommendations that feed into an SSP or POA&M, making it a valuable first step in compliance readiness.