Compliance Gap Heatmap
A compliance gap heatmap lets you score each control domain against each framework in scope, then renders the grid in colour and lists the gaps. Unlike a static demo, every cell is a number you enter, so the heatmap and the readiness bars reflect your real assessment, and the work is saved locally to continue later.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
How it works
Tick the frameworks in scope (SOC 2, ISO 27001, GDPR, PCI DSS, HIPAA, NIST CSF) and score each of ten control domains from 0, meaning nothing in place, to 100, meaning evidenced and audited. Leave a cell blank where a domain does not apply to a framework. Each cell colours itself green above 90, amber from 50, and red below, so the weak areas are visible without reading numbers.
What it computes
- A per-framework readiness bar, the average of that framework's scored domains, so you can see you are 85 percent ready for SOC 2 but 40 percent for PCI DSS.
- A ranked gap list of every domain scoring under 50, worst first.
- A CSV export of the whole grid for a report or a tracker.
The advice it gives
The tool points at the lowest domain that appears under the most frameworks, because one control set usually satisfies several standards at once. Fixing access control or incident response typically moves SOC 2, ISO 27001 and NIST CSF together, so sequencing by shared weakness is more efficient than working one framework at a time.
Honest scoring
The output is only as good as the scores. A domain marked 100 because a policy exists, without evidence it is followed, produces a heatmap that lies to you. Score against evidence you could show an auditor, not against intent. Everything is stored in your browser and can be cleared; nothing is uploaded.
Related tools
- Compliance Readiness Score — Score readiness against a compliance framework across policy, technical controls and evidence, and identify the gaps that block certification.
- Compliance Calendar — Enter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.
- PCI-DSS Checklist — Interactive checklist of the 12 PCI DSS requirements for handling card data, with progress saved in your browser. Covers what changed in version 4.0.
- Policy Lifecycle Tracker — Track when each security and compliance policy was last reviewed, set an annual, quarterly or two-year cycle, and see which reviews fall due within 30 days.
Frequently Asked Questions
Where do the scores come from?
You enter them. Each domain-by-framework cell is a number from 0 to 100 that you assign based on your own assessment. The heatmap, readiness bars and gap list are all computed from those inputs.
Is my assessment saved?
Yes, in your browser's local storage, so you can close the tab and continue later on the same device. It is not synced anywhere. Use the CSV export to move it into your own systems.
Which domain should I fix first?
The lowest-scoring domain that appears under the most frameworks in scope. One strong control set for, say, access control or incident response usually satisfies several standards at once, so shared weaknesses give the best return.
Can I export the heatmap?
Yes. The Copy as CSV button produces the full grid, domains as rows and frameworks as columns, which you can paste into a spreadsheet or a report.
How should I score a domain honestly?
Score against evidence you could produce for an auditor, not against a policy existing on paper. A domain rated 100 with no proof it operates gives a false picture; err toward the lower number when evidence is thin.
Privacy & Security
Generated locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Compliance Readiness Score
ComplianceScore readiness against a compliance framework across policy, technical controls and evidence, and identify the gaps that block certification.
Compliance Calendar
ComplianceEnter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.
PCI-DSS Checklist
ComplianceInteractive checklist of the 12 PCI DSS requirements for handling card data, with progress saved in your browser. Covers what changed in version 4.0.