Compliance Readiness Checklist

Score your SOC 2, HIPAA, PCI-DSS, ISO 27001 or CMMC readiness in minutes. Weighted gap analysis, ranked remediation plan and exportable PDF report.

Advertisement

Free Compliance Readiness Checklist for SOC 2, HIPAA and CMMC

Most compliance projects fail in the same place: nobody can say, in a sentence, how far along the organisation actually is. Leadership asks “are we ready for the audit?” and the honest answer is a shrug. This compliance readiness checklist replaces the shrug with a number. You pick the frameworks you are working toward, answer a structured set of control questions, and get a weighted readiness score per framework, a category-by-category breakdown, a ranked list of gaps, and a remediation plan you can hand to whoever owns the work.

It is built for the person who has been handed compliance on top of an existing job — the IT manager at a 40-person clinic, the first security hire at a Series A SaaS company, the operations lead at a defence subcontractor who just found the word CMMC in a new contract. It is not an audit, and it does not issue a certificate. It is the thing you do before you spend money on an auditor, so that the auditor’s findings are not a surprise.

Which Frameworks the Checklist Covers

You can assess against one framework or several at once. Because the underlying controls overlap heavily, answering a question about access reviews scores against SOC 2, HIPAA and CMMC simultaneously rather than making you answer it three times.

FrameworkWho needs itWhat it governs
SOC 2SaaS and service organisations whose customers ask for an attestation reportThe AICPA Trust Services Criteria — security plus optionally availability, processing integrity, confidentiality and privacy
HIPAACovered entities and business associates handling protected health informationThe Security, Privacy and Breach Notification Rules at 45 CFR Parts 160 and 164
PCI-DSSAnyone who stores, processes or transmits payment card dataCardholder data environment controls set by the PCI Security Standards Council
ISO 27001Organisations pursuing a certifiable information security management systemThe ISMS clauses plus the Annex A control set
NIST CSFAny organisation wanting a common risk language across functionsGovern, Identify, Protect, Detect, Respond, Recover
CMMC Level 1DoD contractors handling Federal Contract InformationBasic safeguarding practices drawn from FAR 52.204-21
CMMC Level 2DoD contractors handling Controlled Unclassified InformationThe security requirements of NIST SP 800-171

How to Use the Checklist

  1. Build your profile. Industry, headcount band, current status (nothing yet, in progress, already certified), target date, and three flags that change which questions matter: do you handle payment data, protected health information, or personal data?
  2. Select your target frameworks. Pick one to start with if you are new to this. Pick several if you are trying to see where a single control programme can satisfy multiple auditors at once.
  3. Answer the control questions. Each has four responses — Yes (fully implemented and documented), Partial (implemented but incomplete), No (not implemented), and N/A. Partial credit is real: it scores 0.5, so a half-built control does not look identical to a missing one.
  4. Read the scores. You get an overall percentage, a score per framework, and a score per control category, so you can see whether your weakness is concentrated (incident response is a hole) or spread evenly (everything is at 60%).
  5. Work the gap list. Gaps are ranked by priority, and each carries a plain-language description of the problem, a concrete fix, an effort estimate in hours/days/weeks/months, and a rough cost band.
  6. Export the report. The PDF is formatted for circulation — scores, category breakdown, gap register and ranked remediation plan — which is usually what a board or a customer’s security reviewer actually wants to see.

How the Readiness Score Is Calculated

Not every control carries equal weight, so a straight percentage of “yes” answers would be misleading. Each question has a priority (critical, high, medium, low) and a weight, and the score is the weighted sum of your answers divided by the weighted maximum for the questions that apply to you. Questions answered N/A drop out of both the numerator and the denominator rather than counting as failures.

Results land in one of five readiness bands:

  • 0–25% Not Ready — foundational controls are missing. An audit at this stage wastes money.
  • 26–50% Early Stage — some controls exist but there is no coherent programme yet.
  • 51–75% In Progress — the shape of a programme is visible; the work now is evidence and consistency.
  • 76–90% Nearly Ready — close enough to schedule a readiness assessment with a firm.
  • 91–100% Audit Ready — remaining items are refinements rather than blockers.

Critical gaps are counted and surfaced separately, because a single missing critical control — no risk analysis, no incident response plan, no access reviews — will sink an audit regardless of how good the average looks.

The Control Families the Questions Map To

Questions are grouped into categories that mirror how auditors actually structure fieldwork, and each question carries its own mapping to specific clauses in the frameworks it touches.

  • Policies and governance — code of conduct, board oversight, documented and approved security policies. Maps to SOC 2 CC1 (Control Environment) and CC2 (Communication and Information).
  • Risk management — documented risk assessment methodology, a maintained risk register, treatment decisions. Maps to SOC 2 CC3 and, for HIPAA, the risk analysis and risk management specifications at 45 CFR 164.308(a)(1)(ii)(A) and (B), both of which are Required rather than addressable.
  • Access control — provisioning and deprovisioning, least privilege, periodic access reviews, MFA. Maps to SOC 2 CC6, HIPAA 164.308(a)(4) and 164.312(a), and CMMC access control practices.
  • Data protection — classification, encryption at rest and in transit, key management, secure disposal.
  • Vulnerability management — scanning cadence, patch SLAs, penetration testing.
  • Incident response — a documented plan, defined roles, tested at least annually, with notification obligations mapped. Maps to SOC 2 CC7, HIPAA 164.308(a)(6), and the GDPR 72-hour supervisory-authority notification if you also process EU personal data.
  • Business continuity — backups, restore testing, disaster recovery and emergency mode operation. HIPAA makes the data backup plan, disaster recovery plan and emergency mode operation plan Required specifications under 164.308(a)(7).
  • Vendor management — due diligence, contractual security terms, and for HIPAA, a signed Business Associate Agreement with every vendor that creates, receives, maintains or transmits PHI on your behalf.
  • Training and awareness, physical security, and audit and monitoring — the areas most often missing evidence rather than missing controls.

Where Multi-Framework Assessment Pays Off

The strongest argument for assessing several frameworks together is that the overlap is enormous. An access review procedure with documented evidence satisfies a SOC 2 CC6 criterion, a HIPAA information access management specification, and a CMMC access control practice at the same time. Encryption of data in transit shows up in every framework on the list. Once you can see the overlap, the compliance budget conversation changes from “we need three programmes” to “we need one programme with three sets of evidence.”

The divergences matter too, and they are where scores usually differ most. HIPAA is unusual in labelling many implementation specifications “addressable” rather than required — encryption of ePHI at rest under 164.312(a)(2)(iv) and in transmission under 164.312(e)(2)(ii) are both addressable, meaning you must implement them or document why an equivalent alternative is reasonable. A proposed 2025 update to the Security Rule would remove that flexibility, but as of mid-2026 it has not been finalised, so the current rule still applies. CMMC, by contrast, has no such flexibility: for Level 2 the requirements come from NIST SP 800-171 and are assessed as met or not met.

Frequently Asked Questions

Is this checklist a substitute for a real audit?

No. It is a self-assessment. SOC 2 attestation must be performed by a licensed CPA firm, ISO 27001 certification by an accredited certification body, and CMMC Level 2 assessments by an authorised C3PAO or, for some contracts, by self-assessment with an affirming official. This tool tells you where you stand before you engage any of them.

Is any of this legal advice?

No. Everything here is an informational aid. Framework requirements are interpreted in context, and your obligations depend on your contracts, your jurisdiction and the specific data you handle. Confirm anything consequential with qualified legal or compliance counsel before acting on it.

How long does the assessment take?

Roughly 20–45 minutes for a single framework, longer if you select several. The realistic constraint is not the clicking — it is that some questions need input from whoever runs HR onboarding, whoever owns the vendor contracts, and whoever holds the backup schedule.

What score do I need before booking an audit?

There is no official threshold, because the score is ours rather than the framework’s. As a practical rule, below 75% you are buying an expensive gap list; above 90% with no open critical gaps you are in reasonable shape for a readiness assessment.

Does answering N/A hurt my score?

No. N/A removes the question from the calculation entirely rather than scoring it as zero. Use it honestly — marking real gaps as N/A produces a flattering score and a failed audit.

Which framework should a startup do first?

Usually whichever one is blocking a deal. SOC 2 is the common answer for B2B SaaS because enterprise buyers ask for the report. If you handle PHI you do not get to choose — HIPAA applies by law. Start narrow with our SOC 2 gap analysis or the HIPAA quick assessment if you want a faster first pass.

What do I do with the gaps once I have them?

Work top-down by priority, and start with the ones that are documentation rather than engineering — written policies close a surprising share of critical gaps in a week. The security policy generator produces the acceptable use, password, access control, incident response, remote work and data classification policies most frameworks expect.

Does my data leave the browser?

Your answers stay in your browser and are used to calculate scores and build the exported report locally. Nothing is submitted to us for storage, and there is no account to create.

How often should I reassess?

At least annually, and again after anything that changes your control environment: a new product line, a major vendor change, an acquisition, or a shift to a new hosting model. If you want a broader view of the security programme rather than a single framework, the cybersecurity maturity assessment covers the same ground from a capability angle.

What Is a Compliance Checklist

A compliance checklist is a structured tool that maps an organization's security controls and practices against the requirements of specific regulatory frameworks, industry standards, and contractual obligations. Checklists transform complex compliance documents into actionable items that can be assigned, tracked, and verified.

Compliance is not optional for most organizations. Healthcare providers must comply with HIPAA, payment processors with PCI DSS, government contractors with CMMC/FedRAMP, and any organization handling EU personal data with GDPR. A compliance checklist ensures no requirement is overlooked and provides documented evidence of your compliance status.

Major Compliance Frameworks

FrameworkJurisdictionApplies ToKey Requirements
SOC 2Global (US-originated)SaaS/cloud service providersTrust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy)
ISO 27001GlobalAny organizationInformation Security Management System (ISMS) with 93 controls in Annex A
PCI DSSGlobalAny entity processing payment cards12 requirements covering network security, data protection, access control, monitoring
HIPAAUnited StatesHealthcare entities and business associatesPrivacy Rule, Security Rule, Breach Notification Rule
CMMCUnited StatesDoD contractors3 maturity levels with 110+ practices based on NIST 800-171
GDPREU/EEA + global reachAny entity processing EU resident dataData protection principles, data subject rights, breach notification
FedRAMPUnited StatesCloud services for federal agenciesNIST 800-53 controls at Low, Moderate, or High baseline

Common Use Cases

  • Gap analysis: Identify which compliance requirements your organization currently meets and which have gaps requiring remediation
  • Audit preparation: Organize evidence and documentation for upcoming compliance audits by framework requirement
  • Vendor assessment: Evaluate third-party vendors against compliance requirements relevant to your data sharing and integration
  • Security program maturity: Use compliance frameworks as a roadmap for systematically improving your security posture
  • Board reporting: Present compliance status in a structured format that board members and executives can quickly understand

Best Practices

  1. Map controls to multiple frameworks — Many frameworks overlap. A single access control implementation may satisfy SOC 2, ISO 27001, and PCI DSS requirements simultaneously. Map once, comply many.
  2. Maintain continuous compliance — Compliance is not a point-in-time achievement. Implement continuous monitoring, regular evidence collection, and automated compliance checks rather than annual scrambles.
  3. Assign control owners — Every checklist item should have a named owner responsible for implementation, evidence collection, and maintenance. Unowned controls drift into non-compliance.
  4. Automate evidence collection — Screenshots and manual exports are unsustainable. Use GRC platforms and API integrations to automatically collect compliance evidence from your security tools.
  5. Prioritize by risk — Not all compliance requirements carry equal risk. Focus remediation efforts on controls that address your highest-risk areas first, then work through lower-priority items.

Frequently Asked Questions

What compliance frameworks does this checklist cover?+

This compliance checklist covers multiple major regulatory frameworks and security standards including HIPAA for healthcare, SOC 2 for service organizations, PCI DSS for payment card handling, GDPR for data privacy, ISO 27001 for information security management, and NIST Cybersecurity Framework. The tool tailors questions based on your industry and applicable frameworks to ensure relevance to your specific compliance needs.

How does the assessment determine which questions to ask?+

The assessment begins by gathering your company profile including industry sector, company size, data handling practices, and relevant compliance frameworks. Based on this profile, the tool dynamically generates questions that are specifically applicable to your regulatory requirements. A healthcare organization will see HIPAA-focused questions, while an e-commerce business will see PCI DSS and GDPR requirements.

Can I save my progress and continue later?+

Yes, your progress is automatically saved to your browser local storage as you complete the assessment. If you close the browser and return within 7 days, you will be prompted to resume from where you left off or start fresh. This allows you to gather necessary information from different team members without losing your work.

What do the compliance scores and ratings mean?+

The assessment provides scores across multiple dimensions including overall compliance readiness, control implementation status, and risk levels by category. Ratings range from fully compliant to non-compliant, with partial compliance indicating controls that are in place but may need improvement. The results highlight gaps requiring immediate attention and provide prioritized recommendations.

Is this assessment a substitute for a formal compliance audit?+

No, this self-assessment tool is designed for preliminary gap analysis and compliance readiness evaluation, not as a replacement for formal audits or certifications. Use it to identify potential gaps before engaging auditors, prioritize remediation efforts, and track progress over time. For official compliance certification, you will still need qualified assessors or auditors as required by each framework.

Can I share my assessment results with my team or auditors?+

Yes, the tool generates shareable URLs that encode your assessment responses and results. You can copy this link to share with team members, management, or external consultants. The shared link allows others to view your compliance posture without exposing raw assessment data, making it useful for compliance discussions and remediation planning meetings.

How often should I reassess my compliance status?+

You should reassess your compliance status at least quarterly or whenever significant changes occur to your organization, systems, or regulatory landscape. Major triggers include new system deployments, organizational changes, regulatory updates, security incidents, or after implementing remediation measures. Regular assessment helps ensure continuous compliance and identifies new gaps before they become audit findings.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.