Skip to content

Free · No signup for your score

Find out what you’re missing.

Most teams discover their gaps during a failed Stage 1 audit or a customer security review they can’t answer. Both are expensive ways to learn. This takes four minutes.

12 questions
Every one mapped to a named Annex A control
6 domains
Governance, access, cloud, development, detection, suppliers
Real output
A score, ranked gaps and a timeline you can act on

Twelve questions.
An honest answer.

Every question maps to a named ISO 27001:2022 control. At the end you get a readiness score, your gaps ranked by what they would actually cost you, and a realistic timeline, whether or not you ever talk to us.

Takes
About 4 minutes
Covers
6 control domains
Costs
Nothing, ever

Your score and top three gaps are free and ungated. We ask for an email only if you want the full written report, and that’s one email, not a sequence.

How it’s scored

No black box. Here’s the method.

Each question is worth up to three points and maps to a specific ISO 27001:2022 control. Your score is the percentage of available points, and your band is a straight threshold on that percentage, there is no weighting we haven’t shown you.

A self-assessment is not an audit. It cannot sample your evidence, test whether a control actually operated, or catch the thing you believe is true but isn’t. Treat the score as a map of where to look, not a certificate.

We built it to be useful even if you never contact us. If it tells you that certification is premature for your stage, that is a real answer and you should take it. We say the same thing on calls.