Every assessment here asks the same kind of question, clause by clause: is this actually in place, and could you prove it? You answer, it scores you, and you find out where you stand before a customer, an auditor or a regulator tells you.

How it works

  • Pick a standard and work through it. Nothing to install and nothing to download. Your answers save as you go, so you can stop, gather evidence and come back.
  • Score yourself honestly. Every requirement uses the same five-point scale, from nothing in place through to implemented and evidenced. Anything you can justify as out of scope is excluded from the result rather than counted against you.
  • See where you stand. A free account gets you your overall readiness score. The optional full report adds your score for every domain, every open gap in priority order, a remediation plan naming the document that closes each one, and your answers as a live Excel workbook.

Not sure which one applies to you?

Four questions. Nothing is stored, and you can start any assessment without answering them.

What is driving this?

Pick everything that applies.

Where do you operate, or where are your customers?
What is your sector?
What does your organisation handle?

Pick everything that applies.

Information security and cyber

Certifiable management standards and the control catalogues customers and auditors ask for.

ISO 27001

Free assessment

ISO/IEC 27001:2022 Information Security Management System

The certifiable information security management standard. Scores you against all seven management clauses and all 93 Annex A controls.

  • 120 questions
  • about 45 minutes
  • saves as you go

SOC 2

In progress

SOC 2 Trust Services Criteria

The report North American customers ask for. Scope your categories, then score all 33 common criteria plus availability, confidentiality, processing integrity and privacy.

  • around 69 questions

The documentation toolkit is available now →

NIST CSF 2.0

In progress

NIST Cybersecurity Framework 2.0

Govern, Identify, Protect, Detect, Respond, Recover. The common language for describing cyber maturity to a board.

  • around 106 questions

PCI DSS 4.0

In progress

PCI DSS v4.0.1 Payment Card Industry Data Security Standard

All twelve requirements at sub-requirement level, scoped to how you actually take payments, with the requirements that became mandatory in March 2025 called out.

  • around 73 questions

The documentation toolkit is available now →

NIS2

In progress

EU NIS2 Directive cybersecurity risk-management measures

Article 21 measures and Article 23 reporting duties, for essential and important entities.

  • around 90 questions

CMMC 2.0

In progress

CMMC 2.0 Level 2 / NIST SP 800-171 Rev 3

The 110 practices a defence supplier has to evidence before an assessment.

  • around 110 questions

The documentation toolkit is available now →

AI governance

Governance over the AI systems you build, buy or put in front of customers.

ISO 42001

Free assessment

ISO/IEC 42001:2023 Artificial Intelligence Management System

The certifiable AI management standard, and the fastest route to evidencing EU AI Act governance. All seven clauses plus the 38 Annex A controls.

  • 67 questions
  • about 30 minutes
  • saves as you go

EU AI Act

In progress

EU Artificial Intelligence Act obligations

Classify your systems, then score the high-risk duties, transparency obligations and literacy requirements against the applicable dates.

  • around 80 questions

The documentation toolkit is available now →

Privacy and data protection

What you owe the people whose data you hold, wherever they are.

GDPR

In progress

EU General Data Protection Regulation (Regulation (EU) 2016/679)

Lawful basis, records of processing, data subject rights, transfers and breach readiness, article by article, the way a supervisory authority would ask for them.

  • around 88 questions

The documentation toolkit is available now →

HIPAA

In progress

HIPAA Security, Privacy and Breach Notification Rules (45 CFR Parts 160 and 164)

Administrative, physical and technical safeguards, the privacy and breach rules, and the addressable-versus-required decisions an OCR investigator will ask you to justify.

  • around 96 questions

The documentation toolkit is available now →

Continuity and operational resilience

Staying available, and proving you would survive the day it goes wrong.

DORA

In progress

EU Digital Operational Resilience Act

ICT risk management, incident reporting, resilience testing and third-party oversight for EU financial entities.

  • around 85 questions

ISO 22301

In progress

ISO 22301:2019 Business Continuity Management System

Business impact analysis, continuity strategy, plans and exercising, as a certifiable management system.

  • around 75 questions

The documentation toolkit is available now →

Gulf regulatory

The regulator-issued frameworks that apply to licensed entities in Bahrain and Saudi Arabia.

CBB RM-9

In progress

Central Bank of Bahrain Rulebook, Cyber Security Risk Management (RM-9)

The cyber security module Bahraini licensees are examined against, mapped to the Rulebook paragraph numbers.

  • around 110 questions

SAMA CSF

In progress

Saudi Central Bank Cyber Security Framework

All four domains at the maturity levels SAMA expects of a regulated member organisation.

  • around 120 questions

NCA ECC

In progress

Saudi National Cybersecurity Authority Essential Cybersecurity Controls

The ECC main and sub-controls every in-scope national organisation has to implement and report on.

  • around 115 questions

Questions people ask first

Is the gap assessment really free?
Yes. Working through every clause and control, and seeing your overall readiness score, costs nothing. The paid report is optional: it adds your score for each domain, every open gap in priority order, a remediation plan naming the document that closes each one, and your answers as a live Excel workbook.
Do I need an account?
You can start answering straight away without one. You need a free account to see your score, because the score and the report are tied to your organisation's record rather than to a browser.
How long does it take?
Between about thirty minutes and an hour, depending on the standard and how much you already know off the top of your head. Your answers save as you go, so you can stop, gather evidence and come back.
Is this a certification, or an audit?
No. It is a self-assessment: you score yourself, so the result is only as honest as the answers. It is designed to tell you where to start and what to fix before a certification body or a regulator looks at you, not to replace either.
Can I reuse the assessment later?
Yes. Come back whenever you like, update the answers you have moved on, and your score updates with them. If you have bought the report for an assessment, you can regenerate it free every time you change your answers.
Which standard should I start with?
If nobody has told you which one you need, ISO 27001 is the usual starting point: it is the information security management standard most customers, tenders and regulators recognise, and much of what you build for it is reused by every other framework. The chooser on this page narrows it down if your situation is more specific.