EU AI Act · Article 50 transparency obligations apply as of August 2, 2026.  Check your AI governance free →  ·  Article 50, checked — on ScrutinEyes

Readiness check · Nine frameworks

See where you actually stand.

Pick your framework. You'll get an instant, honest read on what applies and where you land — then request a full, evidence-based assessment whenever you want the deep dive.

Every framework here is reconciled control-by-control against its authoritative source of record — including the published ISO/IEC 27001:2022 and 27002:2022 standards, which we reference under a registered end-user licence. We assess against the standards; we never reproduce copyrighted control text, and readiness is not certification.

↑ Choose a framework to begin.

PCI DSS v4.0.1 · Scoping questionnaire

Answer a few questions about your business.

Most PCI DSS controls don't apply to a given business. Tell us how you handle cards and we'll show which controls are in scope — and rule the rest out, with a reason for each. If you're not sure, answer yes; unknown storage is the most common finding.

Which describes your business?

Service providers carry additional PCI DSS obligations.

Do customers enter card details on a web page you control?

Includes hosted checkout pages you brand or embed.

Do you use physical card terminals or readers?

Card-present terminals bring tamper-inspection requirements.

Do you store full card numbers anywhere?

Including databases, spreadsheets, logs, or backups. If you are not certain, answer yes — unknown storage is the most common finding.

Is there wireless networking in or near your payment environment?

Any Wi-Fi that touches the systems handling card data.

Do you build your own software that touches payments?

Custom code, not off-the-shelf plugins.

Do you run public-facing web applications?

Do you keep card data on paper or removable media?

Receipts, order forms, backup drives.

Do you control physical premises where payment systems live?

Offices, stockrooms, server closets.

Do you rely on third parties for payments or hosting?

Payment gateway, cloud host, managed IT.

We don't store anything unless you give an email to be contacted. Scope answers are used to compute your result and then discarded.

Live estimate

Framework

This runs in your browser on the framework's public structure — flip the switches and watch the number move. The paid assessment runs the full engine on the answers and evidence you provide.

NIST CSF 2.0 · Executive mapping

The common language across everything.

CSF isn't a checklist you scope or score — it's the six-function, 106-outcome map we use to roll any of the other frameworks up for a board or an acquirer, and to show where one framework's work already covers another's. It's part of an assessment rather than a self-serve tool, so request one below and the assessment produces your cross-mapping.

Get the full assessment

The estimate above is a browser-side read on public data. For a verified, evidence-based assessment — a readiness score, ranked gaps, and a phased remediation plan — leave your details and we'll be in touch.

Thanks — we've got it. We'll reach out about your assessment shortly.