Score your SOC 2, HIPAA, PCI-DSS, ISO 27001 or CMMC readiness in minutes. Weighted gap analysis, ranked remediation plan and exportable PDF report.
Most compliance projects fail in the same place: nobody can say, in a sentence, how far along the organisation actually is. Leadership asks “are we ready for the audit?” and the honest answer is a shrug. This compliance readiness checklist replaces the shrug with a number. You pick the frameworks you are working toward, answer a structured set of control questions, and get a weighted readiness score per framework, a category-by-category breakdown, a ranked list of gaps, and a remediation plan you can hand to whoever owns the work.
It is built for the person who has been handed compliance on top of an existing job — the IT manager at a 40-person clinic, the first security hire at a Series A SaaS company, the operations lead at a defence subcontractor who just found the word CMMC in a new contract. It is not an audit, and it does not issue a certificate. It is the thing you do before you spend money on an auditor, so that the auditor’s findings are not a surprise.
You can assess against one framework or several at once. Because the underlying controls overlap heavily, answering a question about access reviews scores against SOC 2, HIPAA and CMMC simultaneously rather than making you answer it three times.
| Framework | Who needs it | What it governs |
|---|---|---|
| SOC 2 | SaaS and service organisations whose customers ask for an attestation report | The AICPA Trust Services Criteria — security plus optionally availability, processing integrity, confidentiality and privacy |
| HIPAA | Covered entities and business associates handling protected health information | The Security, Privacy and Breach Notification Rules at 45 CFR Parts 160 and 164 |
| PCI-DSS | Anyone who stores, processes or transmits payment card data | Cardholder data environment controls set by the PCI Security Standards Council |
| ISO 27001 | Organisations pursuing a certifiable information security management system | The ISMS clauses plus the Annex A control set |
| NIST CSF | Any organisation wanting a common risk language across functions | Govern, Identify, Protect, Detect, Respond, Recover |
| CMMC Level 1 | DoD contractors handling Federal Contract Information | Basic safeguarding practices drawn from FAR 52.204-21 |
| CMMC Level 2 | DoD contractors handling Controlled Unclassified Information | The security requirements of NIST SP 800-171 |
Not every control carries equal weight, so a straight percentage of “yes” answers would be misleading. Each question has a priority (critical, high, medium, low) and a weight, and the score is the weighted sum of your answers divided by the weighted maximum for the questions that apply to you. Questions answered N/A drop out of both the numerator and the denominator rather than counting as failures.
Results land in one of five readiness bands:
Critical gaps are counted and surfaced separately, because a single missing critical control — no risk analysis, no incident response plan, no access reviews — will sink an audit regardless of how good the average looks.
Questions are grouped into categories that mirror how auditors actually structure fieldwork, and each question carries its own mapping to specific clauses in the frameworks it touches.
The strongest argument for assessing several frameworks together is that the overlap is enormous. An access review procedure with documented evidence satisfies a SOC 2 CC6 criterion, a HIPAA information access management specification, and a CMMC access control practice at the same time. Encryption of data in transit shows up in every framework on the list. Once you can see the overlap, the compliance budget conversation changes from “we need three programmes” to “we need one programme with three sets of evidence.”
The divergences matter too, and they are where scores usually differ most. HIPAA is unusual in labelling many implementation specifications “addressable” rather than required — encryption of ePHI at rest under 164.312(a)(2)(iv) and in transmission under 164.312(e)(2)(ii) are both addressable, meaning you must implement them or document why an equivalent alternative is reasonable. A proposed 2025 update to the Security Rule would remove that flexibility, but as of mid-2026 it has not been finalised, so the current rule still applies. CMMC, by contrast, has no such flexibility: for Level 2 the requirements come from NIST SP 800-171 and are assessed as met or not met.
No. It is a self-assessment. SOC 2 attestation must be performed by a licensed CPA firm, ISO 27001 certification by an accredited certification body, and CMMC Level 2 assessments by an authorised C3PAO or, for some contracts, by self-assessment with an affirming official. This tool tells you where you stand before you engage any of them.
No. Everything here is an informational aid. Framework requirements are interpreted in context, and your obligations depend on your contracts, your jurisdiction and the specific data you handle. Confirm anything consequential with qualified legal or compliance counsel before acting on it.
Roughly 20–45 minutes for a single framework, longer if you select several. The realistic constraint is not the clicking — it is that some questions need input from whoever runs HR onboarding, whoever owns the vendor contracts, and whoever holds the backup schedule.
There is no official threshold, because the score is ours rather than the framework’s. As a practical rule, below 75% you are buying an expensive gap list; above 90% with no open critical gaps you are in reasonable shape for a readiness assessment.
No. N/A removes the question from the calculation entirely rather than scoring it as zero. Use it honestly — marking real gaps as N/A produces a flattering score and a failed audit.
Usually whichever one is blocking a deal. SOC 2 is the common answer for B2B SaaS because enterprise buyers ask for the report. If you handle PHI you do not get to choose — HIPAA applies by law. Start narrow with our SOC 2 gap analysis or the HIPAA quick assessment if you want a faster first pass.
Work top-down by priority, and start with the ones that are documentation rather than engineering — written policies close a surprising share of critical gaps in a week. The security policy generator produces the acceptable use, password, access control, incident response, remote work and data classification policies most frameworks expect.
Your answers stay in your browser and are used to calculate scores and build the exported report locally. Nothing is submitted to us for storage, and there is no account to create.
At least annually, and again after anything that changes your control environment: a new product line, a major vendor change, an acquisition, or a shift to a new hosting model. If you want a broader view of the security programme rather than a single framework, the cybersecurity maturity assessment covers the same ground from a capability angle.
A compliance checklist is a structured tool that maps an organization's security controls and practices against the requirements of specific regulatory frameworks, industry standards, and contractual obligations. Checklists transform complex compliance documents into actionable items that can be assigned, tracked, and verified.
Compliance is not optional for most organizations. Healthcare providers must comply with HIPAA, payment processors with PCI DSS, government contractors with CMMC/FedRAMP, and any organization handling EU personal data with GDPR. A compliance checklist ensures no requirement is overlooked and provides documented evidence of your compliance status.
| Framework | Jurisdiction | Applies To | Key Requirements |
|---|---|---|---|
| SOC 2 | Global (US-originated) | SaaS/cloud service providers | Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) |
| ISO 27001 | Global | Any organization | Information Security Management System (ISMS) with 93 controls in Annex A |
| PCI DSS | Global | Any entity processing payment cards | 12 requirements covering network security, data protection, access control, monitoring |
| HIPAA | United States | Healthcare entities and business associates | Privacy Rule, Security Rule, Breach Notification Rule |
| CMMC | United States | DoD contractors | 3 maturity levels with 110+ practices based on NIST 800-171 |
| GDPR | EU/EEA + global reach | Any entity processing EU resident data | Data protection principles, data subject rights, breach notification |
| FedRAMP | United States | Cloud services for federal agencies | NIST 800-53 controls at Low, Moderate, or High baseline |
This compliance checklist covers multiple major regulatory frameworks and security standards including HIPAA for healthcare, SOC 2 for service organizations, PCI DSS for payment card handling, GDPR for data privacy, ISO 27001 for information security management, and NIST Cybersecurity Framework. The tool tailors questions based on your industry and applicable frameworks to ensure relevance to your specific compliance needs.
The assessment begins by gathering your company profile including industry sector, company size, data handling practices, and relevant compliance frameworks. Based on this profile, the tool dynamically generates questions that are specifically applicable to your regulatory requirements. A healthcare organization will see HIPAA-focused questions, while an e-commerce business will see PCI DSS and GDPR requirements.
Yes, your progress is automatically saved to your browser local storage as you complete the assessment. If you close the browser and return within 7 days, you will be prompted to resume from where you left off or start fresh. This allows you to gather necessary information from different team members without losing your work.
The assessment provides scores across multiple dimensions including overall compliance readiness, control implementation status, and risk levels by category. Ratings range from fully compliant to non-compliant, with partial compliance indicating controls that are in place but may need improvement. The results highlight gaps requiring immediate attention and provide prioritized recommendations.
No, this self-assessment tool is designed for preliminary gap analysis and compliance readiness evaluation, not as a replacement for formal audits or certifications. Use it to identify potential gaps before engaging auditors, prioritize remediation efforts, and track progress over time. For official compliance certification, you will still need qualified assessors or auditors as required by each framework.
Yes, the tool generates shareable URLs that encode your assessment responses and results. You can copy this link to share with team members, management, or external consultants. The shared link allows others to view your compliance posture without exposing raw assessment data, making it useful for compliance discussions and remediation planning meetings.
You should reassess your compliance status at least quarterly or whenever significant changes occur to your organization, systems, or regulatory landscape. Major triggers include new system deployments, organizational changes, regulatory updates, security incidents, or after implementing remediation measures. Regular assessment helps ensure continuous compliance and identifies new gaps before they become audit findings.