Compliance

Compliance Readiness Score

Score readiness against a compliance framework across policy, technical controls and evidence, and identify the gaps that block certification.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Readiness has three separate dimensions

Organisations preparing for certification consistently over-score themselves because they measure one dimension and assume the others follow. Policy is whether a documented, approved statement exists. Implementation is whether the control is actually operating. Evidence is whether you can demonstrate it operated throughout the audit period. A written access review policy that nobody performs, or one performed diligently with no record, both fail an audit despite feeling like progress.

Evidence is where most programmes fall short

Auditors sample a period, typically three to twelve months, and ask for proof that a control operated throughout. Retrospectively generating that evidence is not possible: if quarterly access reviews were not recorded when they happened, the quarters are gone. This is why the practical start of a compliance programme is turning on logging, ticketing and approval trails, months before the audit, rather than writing policies.

Scope determines effort more than framework choice

The single largest driver of cost is what falls inside the boundary. A well-drawn scope covering one product and its supporting infrastructure is a fraction of the work of one covering an entire organisation. Systems that store, process or transmit the data in question are in scope; everything else can often be excluded with proper segmentation. Getting scope wrong at the outset is the most expensive mistake available.

Frameworks overlap heavily

SOC 2, ISO 27001, and the security requirements of GDPR and HIPAA share a large common core: access control, change management, incident response, vendor management, logging and risk assessment. Building controls once and mapping them to multiple frameworks is far cheaper than running separate programmes. Where they genuinely differ is in emphasis and in the certification process rather than in the underlying controls.

A score is a starting point

Self-assessment identifies gaps and sequences work. It is not an audit and carries no external weight. Its value is prioritisation: knowing that evidence collection needs to begin immediately while a policy can be drafted next month is worth more than a percentage.

Frequently Asked Questions

Privacy & Security

Your answers are scored in your browser. Your email is only used to send your report and is never sold.

Data: Minimal
Client-side-Side
Active
v1.0

How to Use

Pick the framework you are assessing (ISO 27001, SOC 2, HIPAA or GDPR), answer Yes/No to each control question, then calculate your readiness score. Request the free report for a prioritised remediation plan.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.