Compliance Readiness Score
Score readiness against a compliance framework across policy, technical controls and evidence, and identify the gaps that block certification.
This is an indicative self-assessment, not a formal audit. Radiatus runs end-to-end compliance programs — get a tailored gap analysis below.
Get your free compliance gap-analysis report
A Radiatus GRC specialist reviews your answers and sends a prioritised remediation plan. No obligation.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Readiness has three separate dimensions
Organisations preparing for certification consistently over-score themselves because they measure one dimension and assume the others follow. Policy is whether a documented, approved statement exists. Implementation is whether the control is actually operating. Evidence is whether you can demonstrate it operated throughout the audit period. A written access review policy that nobody performs, or one performed diligently with no record, both fail an audit despite feeling like progress.
Evidence is where most programmes fall short
Auditors sample a period, typically three to twelve months, and ask for proof that a control operated throughout. Retrospectively generating that evidence is not possible: if quarterly access reviews were not recorded when they happened, the quarters are gone. This is why the practical start of a compliance programme is turning on logging, ticketing and approval trails, months before the audit, rather than writing policies.
Scope determines effort more than framework choice
The single largest driver of cost is what falls inside the boundary. A well-drawn scope covering one product and its supporting infrastructure is a fraction of the work of one covering an entire organisation. Systems that store, process or transmit the data in question are in scope; everything else can often be excluded with proper segmentation. Getting scope wrong at the outset is the most expensive mistake available.
Frameworks overlap heavily
SOC 2, ISO 27001, and the security requirements of GDPR and HIPAA share a large common core: access control, change management, incident response, vendor management, logging and risk assessment. Building controls once and mapping them to multiple frameworks is far cheaper than running separate programmes. Where they genuinely differ is in emphasis and in the certification process rather than in the underlying controls.
A score is a starting point
Self-assessment identifies gaps and sequences work. It is not an audit and carries no external weight. Its value is prioritisation: knowing that evidence collection needs to begin immediately while a policy can be drafted next month is worth more than a percentage.
Frequently Asked Questions
Privacy & Security
Your answers are scored in your browser. Your email is only used to send your report and is never sold.
How to Use
Pick the framework you are assessing (ISO 27001, SOC 2, HIPAA or GDPR), answer Yes/No to each control question, then calculate your readiness score. Request the free report for a prioritised remediation plan.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.