After a skills gap analysis, test the assumptions behind the required-skills list and the proficiency ratings before funding the training plan, because both ends of the gap are judgements. In a 2019 report, US federal auditors found that more than half the positions they sampled from a government-wide cybersecurity workforce inventory carried a code that contradicted the job's own written duties.
A skills gap analysis compares the skills an organisation or role needs with the skills its people currently hold, and lists the shortfalls to close.
The textbook sequence after a skills gap analysis
The analysis follows a settled pattern. It starts from the work: strategy documents, role profiles or an external framework define the skills required and the proficiency each role needs. It then takes stock of current capability, usually through self-assessment, manager ratings or both, and occasionally through tests or certifications. The difference between required and current levels becomes the gap, typically laid out as a matrix of people against skills with the shortfalls shaded.
The next step is the one the analysis was commissioned for. Gaps are ranked by how much the work depends on them, and each is assigned a route: build the skill through training, buy it through hiring, borrow it through contractors, or redeploy people who already have it. For the gaps judged closable in-house, the ranked list becomes a training program with courses, cohorts, dates and a budget.

Approval then turns on cost and coverage: how many people, how many courses, how many dollars per closed gap. The matrix is rerun after training, often a year later, and the shaded cells are expected to lighten. It is the same shape as the sequence after any gap analysis: current state, target state, actions to close the distance.
By the time the plan reaches a budget committee, the gap figures read as measurements. Every cell in the matrix looks equally solid, whether it came from a practical test, a manager's impression or a self-rating nobody checked.
The value in that sequence
The sequence does useful work. Without it, training spend tends to follow the course catalogue, the loudest manager or last year's budget. A skills gap analysis ties spend to the work the organisation says it needs done, and the build, buy, borrow choice forces a question many training plans skip: whether training is the cheapest way to get the capability at all.
The matrix also makes capability visible to people who never see it day to day. A leadership team can see that only three people hold a skill the operating model depends on. A gap analysis is often the first document that shows a single point of failure in people rather than systems, which makes it a useful input to a wider situation analysis.
Ranking imposes discipline too. Not every gap deserves money, and separating the gaps worth closing from the rest saves spend before any course is booked. The rerun gives the organisation a baseline to compare against. The analysis is good at locating shortfalls; what it cannot do is check the ground each shortfall is measured from.
The structural blind spot
Three assumptions ride inside every gap. The required-skills list assumes the future work will need what the role profile says. The current ratings assume they describe what people can actually do. The training plan assumes the shortfall is a skills problem and that people will use what they learn. The matrix records all three as given.
The ratings are the softest part. A meta-analysis of 55 studies by Mabe and West (1982) found a mean correlation of .29 between people's self-evaluations of ability and measured performance, with wide variation between studies. A matrix built largely on self-ratings is a record of opinions about capability, however precise its shading looks.
The third assumption is rarely examined at all. Cappelli's review of US skills-shortage claims (2015) found very little evidence consistent with them. In Saks and Belcourt's 2006 survey of training professionals in 150 organisations, respondents estimated that 62 per cent of trainees applied training on the job immediately, 44 per cent after six months and 34 per cent after a year. Even those figures are estimates, not observations.
The required list can be wrong too: in what each role does, not in how well its holder does it. Once the list is wrong, every rating measured against it inherits the error. Readiness ratings in succession planning carry the same weakness.
Pick the skill your training budget targets first and write down what has to be true for closing that gap to change how the work gets done. Start the Walk →
How US federal agencies learned this
US federal agencies ran this analysis at national scale. The Federal Cybersecurity Workforce Assessment Act of 2015 required them to code every civilian IT, cybersecurity and cyber-related position against work roles in the NICE cybersecurity workforce framework by April 2018, then identify the work roles of critical need by April 2019. The codes were the inventory; the critical needs were the gap.
In March 2019, the Government Accountability Office reported on the coding. Twenty-two of 24 agencies had given 15,779 positions in the IT management series, about 19 per cent, the code 000, reserved for positions that perform no IT, cybersecurity or cyber-related functions. At six agencies examined in detail, 63 of 120 randomly sampled positions carried codes inconsistent with the duties in their own position descriptions.
The errors were ordinary. Ten agencies said they may have assigned the 000 code in error, 13 had not finished validating their codes, and 12 said the Office of Personnel Management's guidance was unclear. At EPA, first-line supervisors made the final call and read the work roles differently. GSA and NASA gave 000 to positions below their own 25 per cent threshold for cybersecurity duties.
The critical-needs work went ahead regardless. Agencies had already sent preliminary reports to the Office of Personnel Management naming information systems security manager, IT project manager and systems security analyst as the top three roles of critical need. GAO concluded that until positions were accurately categorised, the agencies' ability to identify critical staffing needs "will be impaired." The gap list arrived on schedule, but the inventory under it had not been checked.
Testing assumptions before committing resources
The missing step sits between the gap list and the training budget. It asks what the list takes for granted. The five-step Universal Decision-Making Method gives it an order: Frame, Tentative Elements, Assumptions, Sufficient Certainty, then Implement and Monitor. Frame states which work the capability is for; the Tentative Elements are the list, the ratings and the plan, held as proposals. The Assumptions are rarely written down. Take a hypothetical matrix row.
Each number needs its own test. Sample the ratings against observed work or a short practical task, starting with the gaps that carry the most spend. Check the required list against the work actually planned, not the profile on file. Sufficient Certainty is judged gap by gap: a cheap course on a doubtful rating can proceed; a year-long academy for a whole function needs its ratings checked first.
Implement and Monitor ties each funded gap to a work signal, such as tasks done unaided six months on. A 2025 GAO review of five departments found none had evaluated whether its cybersecurity workforce actions had been effective. Tracking assumptions after sign-off is the same work as keeping a situation analysis useful after approval.
A skills gap is the distance between two judgements. Test both before paying to close it.
You could fund a training plan against every rated gap and still leave the required-skills list it measures against untested.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.