How it works: answer 13 questions about your security practices. You get a readiness band (Foundation established, Developing, Significant gaps or Review recommended) and a list of what to fix first. It is calculated in your browser; nothing is sent or stored.
A self-assessment, not an audit. Your band reflects your own answers. It is not an audit opinion and does not predict a SOC 2 report or ISO 27001 certification outcome: only a CPA firm or an accredited certification body can reach those conclusions. For the frameworks themselves, see SOC 2 and ISO 27001.
How the band is worked out
- Each answer scores 0 (not in place), 1 (partly, or informal) or 2 (in place, with evidence).
- Significant gaps: the average is below 1.
- Review recommended: otherwise, if any high-impact area (access control, multi-factor authentication, incident response or backups) is not in place.
- Foundation established: the average is at least 1.6 and nothing is missing entirely.
- Developing: everything else.
The areas are common security foundations that both SOC 2 and ISO 27001 examinations look at. They are not the full criteria of either framework.