Independent publication. General information only: not an auditor, certification body, law firm or standards body.
Baseline ReadySecurity & Compliance Intelligence Check your readiness

Tool

Compliance readiness assessment

Updated

How it works: answer 13 questions about your security practices. You get a readiness band (Foundation established, Developing, Significant gaps or Review recommended) and a list of what to fix first. It is calculated in your browser; nothing is sent or stored.

A self-assessment, not an audit. Your band reflects your own answers. It is not an audit opinion and does not predict a SOC 2 report or ISO 27001 certification outcome: only a CPA firm or an accredited certification body can reach those conclusions. For the frameworks themselves, see SOC 2 and ISO 27001.

01Security policies

Do you have written, approved security policies that staff have acknowledged?

02Risk assessment

Do you run a documented risk assessment and track how each risk is treated?

03Access control High impact

Is access granted by role, approved, and reviewed on a schedule?

04Multi-factor authentication High impact

Is multi-factor authentication enforced on email, cloud and admin accounts?

05Onboarding & offboarding

Are joiners and leavers handled with a checklist, including removing access on the last day?

06Asset management

Do you keep an up-to-date inventory of devices, systems and data stores?

07Change management

Are production changes reviewed and approved, with a record kept?

08Incident response High impact

Do you have an incident response plan that people know about and have practised?

09Backups & recovery High impact

Are backups taken automatically and restores tested?

10Vendor management

Do you review the security of vendors that handle your data?

11Security awareness

Do staff complete security awareness training when they join and periodically after?

12Business continuity

Do you have a business continuity plan covering how you keep operating through a disruption?

13Evidence collection

Can you show evidence that your controls operate (logs, tickets, screenshots, reports) on request?

Runs in your browser. Nothing is sent or stored.

How the band is worked out

  • Each answer scores 0 (not in place), 1 (partly, or informal) or 2 (in place, with evidence).
  • Significant gaps: the average is below 1.
  • Review recommended: otherwise, if any high-impact area (access control, multi-factor authentication, incident response or backups) is not in place.
  • Foundation established: the average is at least 1.6 and nothing is missing entirely.
  • Developing: everything else.

The areas are common security foundations that both SOC 2 and ISO 27001 examinations look at. They are not the full criteria of either framework.