# PCI DSS Gap Analysis: How to Find and Close Compliance Gaps > A PCI DSS gap analysis compares your current controls against the standard's requirements before a formal assessment. How to scope it, run it, and turn the findings into a remediation plan. Source: https://playciso.com/blog/pci-dss-gap-analysis-guide · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- A PCI DSS gap analysis is how you find out whether you can pass — before it counts. It compares your current controls against the standard's requirements, surfaces the gaps, and gives you a remediation plan, so a formal assessment or Self-Assessment Questionnaire becomes a confirmation rather than a gamble. The work lives and dies on getting one thing right: scope. ## Step 1 — Define scope (the most important step) PCI DSS applies to the **cardholder data environment (CDE)** — systems that store, process or transmit cardholder data — plus everything connected to or able to affect it. Scope too narrowly and you pass the analysis but remain non-compliant where it matters; too broadly and you waste effort. Good network segmentation reduces scope, which is why scoping and segmentation are the foundation of an efficient PCI programme. ## Step 2 — Map controls to requirements Go requirement by requirement and record what control you have today, where the evidence is, and whether it fully meets the requirement. ## Step 3 — Identify and rate the gaps List every requirement you do not fully meet, and rate each gap by risk and remediation effort so you can prioritise. ## Step 4 — Build a remediation plan Assign owners and target dates to each gap, fix the high-risk/low-effort items first, and re-check closed gaps before the formal assessment. ## Step 5 — Then complete the SAQ or assessment Which Self-Assessment Questionnaire applies depends on how you handle card data; the gap analysis tells you whether you can honestly attest compliance and what to fix first if not. Work through it with the [PCI DSS tools →](/pci), run the interactive [PCI gap analysis](/pci/gap), and prep for the assessment with [certification prep](/tools/cert-prep). ## Frequently asked questions **What is it?** A pre-assessment comparing current controls to PCI DSS requirements to find and fix gaps before it counts. **Why is scope key?** PCI applies to the CDE and connected systems; wrong scope means wasted effort or hidden non-compliance — segmentation reduces it. **How to run it?** Scope, map controls to requirements, rate gaps, remediate with owners/dates, re-check. **Relation to the SAQ?** The gap analysis prepares you to honestly complete the SAQ; run it, remediate, then attest.