Readiness assessments · Nine frameworks

The first look at where
you actually stand.

PCI DSS, NIST 800-171, CMMC, HIPAA, the FTC Safeguards Rule. We scope what applies to you, score what the standard actually measures, and rank what to fix first — each backed by its own engine, reconciled to the source of record.

Take PCI DSS: most of its controls don't apply to a given business — but you're guessing at the size of your problem until someone shows you which ones you can rule out, and why. Flip the switches and watch the scope move.

250 / 250
PCI DSS controls
in scope

Tell it about your business

Nothing selected — assume everything applies. Switch on what's true of you.

What we assess

Nine frameworks, one honest method.

Each control set below is backed by its own engine — the catalogue reconciled against the source of record, the scoring done the way the standard (or the regulator) actually defines it. No recycled checklists.

1 & 2levels

CMMC Levels 1 & 2

Pass/fail · SPRS

Level 1 is the 15 FAR 52.204-21 safeguards for FCI, self-assessed pass/fail. Level 2 is the full 110 of NIST 800-171. We run both on the same engines that power the panels here.

For: the defense industrial base

24elements

FTC Safeguards Rule

Program readiness

The written information-security program the FTC now enforces under GLBA — including the 2023 amendments — with the under-5,000-consumer small-entity exemptions applied to your case.

For: non-bank "financial institutions" — dealers, lenders, tax prep, accountants

63safeguards

HIPAA Security Rule

Readiness · required + addressable

Every safeguard across 45 CFR 164, tagged Required or Addressable and mapped to how you actually handle ePHI. HIPAA defines no official score — so any number we give is a readiness indicator, and we say so.

For: providers, plans & business associates

93controls

ISO/IEC 27001:2022

Annex A · Statement of Applicability

We map all 93 Annex A controls across the four themes — Organizational, People, Physical, Technological — to your Statement of Applicability, with a written justification for anything you exclude.

For: firms pursuing certification or answering security-review questionnaires

110requirements

NIST SP 800-171 Rev 2

SPRS self-score

Your SPRS number — the one the DoD will see — computed exactly the way the DoD Assessment Methodology says to: no partial credit, MFA and FIPS partials, floor of −203.

For: DoD contractors & subs handling CUI

72subcategories

NIST AI RMF 1.0

AI governance · readiness read

Govern, Map, Measure, Manage — the four functions of the NIST AI Risk Management Framework, across all 72 subcategories. It defines no official score, so we give you a readiness read of your AI governance, not a grade.

For: anyone building, deploying, or buying AI

106outcomes

NIST CSF 2.0

Cross-mapping · executive view

Six functions, 22 categories, 106 outcomes — the common language to roll any of the above up for a board or an acquirer, and to see where one framework's work covers another's.

For: mapping and executive reporting

250controls

PCI DSS v4.0.1

Scoping · live self-serve

We show you which controls apply to your cardholder-data environment and what to fix first. Try it in the panel above, or run the full ten-question check.

For: anyone who takes card payments

61criteria

SOC 2 (2017 TSC)

Trust Services Criteria · readiness

The 33 mandatory Common Criteria plus the optional categories — Availability, Processing Integrity, Confidentiality, Privacy — scoped to the report your customers actually ask for. It shows where you stand and what to close first, so you walk into a CPA firm's attestation knowing your gaps instead of guessing.

For: SaaS & service orgs facing a customer SOC 2 request

Try the engines

Every framework, live.

The PCI panel up top asks about your business and scopes controls out. Each engine below runs its own model instead — a real SPRS score, a Level 1 pass/fail, a HIPAA readiness read, the FTC's size-based applicability. Toggle the tiles and watch the number move. These run in your browser as estimators on the same public data; the paid assessment runs the full engine on the answers and evidence you provide.

110 / 110
SPRS score
(estimate)

Toggle off what you have not implemented

How the assessment works

Three steps.

STEP 01

Scope

You tell the tool about your environment, and it establishes what's in scope — documenting which controls don't apply to you, with the reason for each exclusion. An unexplained "not applicable" is the first thing an assessor will challenge.

STEP 02

Assess

You complete a short self-assessment for each control that's in scope: configuration, access, logging, encryption, policy. The engine scores every answer against the standard the way the standard itself defines it.

STEP 03

Report

You get a readiness score, every gap ranked by severity, and a phased remediation plan your team can execute against. Written to be handed to a board, an acquirer, or an engineer — not to impress you with jargon.

The deliverable

What lands in your inbox.

A single PDF, in the language of your framework. No portal to log into, no seat licence, no upsell.

Straight answer

You may not need us.

If you're a small merchant who has fully outsourced payments and never touches a card number, your PCI obligation may be a short self-assessment questionnaire you can complete yourself in an afternoon. If you're a contractor with only FCI, CMMC Level 1 is fifteen requirements you can self-attest. We'll tell you that for free, and we'll tell you exactly which questionnaire or level it is.

Where we earn our fee is the messy middle: payments online, some AWS infrastructure that grew organically, CUI you're not sure is contained, an acquirer or a prime asking questions. That's the problem worth running the full assessment on.