Every assessment here asks the same kind of question, clause by clause: is this actually in place, and could you prove it? You answer, it scores you, and you find out where you stand before a customer, an auditor or a regulator tells you.
How it works
- Pick a standard and work through it. Nothing to install and nothing to download. Your answers save as you go, so you can stop, gather evidence and come back.
- Score yourself honestly. Every requirement uses the same five-point scale, from nothing in place through to implemented and evidenced. Anything you can justify as out of scope is excluded from the result rather than counted against you.
- See where you stand. A free account gets you your overall readiness score. The optional full report adds your score for every domain, every open gap in priority order, a remediation plan naming the document that closes each one, and your answers as a live Excel workbook.
Not sure which one applies to you?
Four questions. Nothing is stored, and you can start any assessment without answering them.
Information security and cyber
Certifiable management standards and the control catalogues customers and auditors ask for.
ISO 27001
Free assessmentISO/IEC 27001:2022 Information Security Management System
The certifiable information security management standard. Scores you against all seven management clauses and all 93 Annex A controls.
- 120 questions
- about 45 minutes
- saves as you go
SOC 2
In progressSOC 2 Trust Services Criteria
The report North American customers ask for. Scope your categories, then score all 33 common criteria plus availability, confidentiality, processing integrity and privacy.
- around 69 questions
NIST CSF 2.0
In progressNIST Cybersecurity Framework 2.0
Govern, Identify, Protect, Detect, Respond, Recover. The common language for describing cyber maturity to a board.
- around 106 questions
PCI DSS 4.0
In progressPCI DSS v4.0.1 Payment Card Industry Data Security Standard
All twelve requirements at sub-requirement level, scoped to how you actually take payments, with the requirements that became mandatory in March 2025 called out.
- around 73 questions
NIS2
In progressEU NIS2 Directive cybersecurity risk-management measures
Article 21 measures and Article 23 reporting duties, for essential and important entities.
- around 90 questions
CMMC 2.0
In progressCMMC 2.0 Level 2 / NIST SP 800-171 Rev 3
The 110 practices a defence supplier has to evidence before an assessment.
- around 110 questions
AI governance
Governance over the AI systems you build, buy or put in front of customers.
ISO 42001
Free assessmentISO/IEC 42001:2023 Artificial Intelligence Management System
The certifiable AI management standard, and the fastest route to evidencing EU AI Act governance. All seven clauses plus the 38 Annex A controls.
- 67 questions
- about 30 minutes
- saves as you go
EU AI Act
In progressEU Artificial Intelligence Act obligations
Classify your systems, then score the high-risk duties, transparency obligations and literacy requirements against the applicable dates.
- around 80 questions
Privacy and data protection
What you owe the people whose data you hold, wherever they are.
GDPR
In progressEU General Data Protection Regulation (Regulation (EU) 2016/679)
Lawful basis, records of processing, data subject rights, transfers and breach readiness, article by article, the way a supervisory authority would ask for them.
- around 88 questions
HIPAA
In progressHIPAA Security, Privacy and Breach Notification Rules (45 CFR Parts 160 and 164)
Administrative, physical and technical safeguards, the privacy and breach rules, and the addressable-versus-required decisions an OCR investigator will ask you to justify.
- around 96 questions
Continuity and operational resilience
Staying available, and proving you would survive the day it goes wrong.
DORA
In progressEU Digital Operational Resilience Act
ICT risk management, incident reporting, resilience testing and third-party oversight for EU financial entities.
- around 85 questions
ISO 22301
In progressISO 22301:2019 Business Continuity Management System
Business impact analysis, continuity strategy, plans and exercising, as a certifiable management system.
- around 75 questions
Gulf regulatory
The regulator-issued frameworks that apply to licensed entities in Bahrain and Saudi Arabia.
CBB RM-9
In progressCentral Bank of Bahrain Rulebook, Cyber Security Risk Management (RM-9)
The cyber security module Bahraini licensees are examined against, mapped to the Rulebook paragraph numbers.
- around 110 questions
SAMA CSF
In progressSaudi Central Bank Cyber Security Framework
All four domains at the maturity levels SAMA expects of a regulated member organisation.
- around 120 questions
NCA ECC
In progressSaudi National Cybersecurity Authority Essential Cybersecurity Controls
The ECC main and sub-controls every in-scope national organisation has to implement and report on.
- around 115 questions
Questions people ask first
- Is the gap assessment really free?
- Yes. Working through every clause and control, and seeing your overall readiness score, costs nothing. The paid report is optional: it adds your score for each domain, every open gap in priority order, a remediation plan naming the document that closes each one, and your answers as a live Excel workbook.
- Do I need an account?
- You can start answering straight away without one. You need a free account to see your score, because the score and the report are tied to your organisation's record rather than to a browser.
- How long does it take?
- Between about thirty minutes and an hour, depending on the standard and how much you already know off the top of your head. Your answers save as you go, so you can stop, gather evidence and come back.
- Is this a certification, or an audit?
- No. It is a self-assessment: you score yourself, so the result is only as honest as the answers. It is designed to tell you where to start and what to fix before a certification body or a regulator looks at you, not to replace either.
- Can I reuse the assessment later?
- Yes. Come back whenever you like, update the answers you have moved on, and your score updates with them. If you have bought the report for an assessment, you can regenerate it free every time you change your answers.
- Which standard should I start with?
- If nobody has told you which one you need, ISO 27001 is the usual starting point: it is the information security management standard most customers, tenders and regulators recognise, and much of what you build for it is reused by every other framework. The chooser on this page narrows it down if your situation is more specific.