Readiness assessments · Nine frameworks
PCI DSS, NIST 800-171, CMMC, HIPAA, the FTC Safeguards Rule. We scope what applies to you, score what the standard actually measures, and rank what to fix first — each backed by its own engine, reconciled to the source of record.
Take PCI DSS: most of its controls don't apply to a given business — but you're guessing at the size of your problem until someone shows you which ones you can rule out, and why. Flip the switches and watch the scope move.
Tell it about your business
Nothing selected — assume everything applies. Switch on what's true of you.
What we assess
Each control set below is backed by its own engine — the catalogue reconciled against the source of record, the scoring done the way the standard (or the regulator) actually defines it. No recycled checklists.
Pass/fail · SPRS
Level 1 is the 15 FAR 52.204-21 safeguards for FCI, self-assessed pass/fail. Level 2 is the full 110 of NIST 800-171. We run both on the same engines that power the panels here.
For: the defense industrial base
Program readiness
The written information-security program the FTC now enforces under GLBA — including the 2023 amendments — with the under-5,000-consumer small-entity exemptions applied to your case.
For: non-bank "financial institutions" — dealers, lenders, tax prep, accountants
Readiness · required + addressable
Every safeguard across 45 CFR 164, tagged Required or Addressable and mapped to how you actually handle ePHI. HIPAA defines no official score — so any number we give is a readiness indicator, and we say so.
For: providers, plans & business associates
Annex A · Statement of Applicability
We map all 93 Annex A controls across the four themes — Organizational, People, Physical, Technological — to your Statement of Applicability, with a written justification for anything you exclude.
For: firms pursuing certification or answering security-review questionnaires
SPRS self-score
Your SPRS number — the one the DoD will see — computed exactly the way the DoD Assessment Methodology says to: no partial credit, MFA and FIPS partials, floor of −203.
For: DoD contractors & subs handling CUI
AI governance · readiness read
Govern, Map, Measure, Manage — the four functions of the NIST AI Risk Management Framework, across all 72 subcategories. It defines no official score, so we give you a readiness read of your AI governance, not a grade.
For: anyone building, deploying, or buying AI
Cross-mapping · executive view
Six functions, 22 categories, 106 outcomes — the common language to roll any of the above up for a board or an acquirer, and to see where one framework's work covers another's.
For: mapping and executive reporting
Scoping · live self-serve
We show you which controls apply to your cardholder-data environment and what to fix first. Try it in the panel above, or run the full ten-question check.
For: anyone who takes card payments
Trust Services Criteria · readiness
The 33 mandatory Common Criteria plus the optional categories — Availability, Processing Integrity, Confidentiality, Privacy — scoped to the report your customers actually ask for. It shows where you stand and what to close first, so you walk into a CPA firm's attestation knowing your gaps instead of guessing.
For: SaaS & service orgs facing a customer SOC 2 request
Try the engines
The PCI panel up top asks about your business and scopes controls out. Each engine below runs its own model instead — a real SPRS score, a Level 1 pass/fail, a HIPAA readiness read, the FTC's size-based applicability. Toggle the tiles and watch the number move. These run in your browser as estimators on the same public data; the paid assessment runs the full engine on the answers and evidence you provide.
Toggle off what you have not implemented
How the assessment works
STEP 01
You tell the tool about your environment, and it establishes what's in scope — documenting which controls don't apply to you, with the reason for each exclusion. An unexplained "not applicable" is the first thing an assessor will challenge.
STEP 02
You complete a short self-assessment for each control that's in scope: configuration, access, logging, encryption, policy. The engine scores every answer against the standard the way the standard itself defines it.
STEP 03
You get a readiness score, every gap ranked by severity, and a phased remediation plan your team can execute against. Written to be handed to a board, an acquirer, or an engineer — not to impress you with jargon.
The deliverable
A single PDF, in the language of your framework. No portal to log into, no seat licence, no upsell.
Straight answer
If you're a small merchant who has fully outsourced payments and never touches a card number, your PCI obligation may be a short self-assessment questionnaire you can complete yourself in an afternoon. If you're a contractor with only FCI, CMMC Level 1 is fifteen requirements you can self-attest. We'll tell you that for free, and we'll tell you exactly which questionnaire or level it is.
Where we earn our fee is the messy middle: payments online, some AWS infrastructure that grew organically, CUI you're not sure is contained, an acquirer or a prime asking questions. That's the problem worth running the full assessment on.