Free self assessment
Score your readiness before the auditor does
Pick the standard you are working towards, answer a short control survey, and get a readiness score with the gaps ranked. No cost, no obligation, and a senior assessor reviews anything you want a second opinion on.
20+
Frameworks covered
From PCI DSS and ISO 27001 to NIS2 and CMMC 2.0.
15 min
Typical time to complete
Short control surveys, written in plain English.
Free
No cost, no obligation
You keep the output whether or not you engage us.
Get your ISO 27001 assessment
Twenty-two control questions across the six ISO 27001 domains, scored against all 93 Annex A requirements as you answer.
- A banded readiness score projected onto all 93 Annex A controls
- Every gap listed, ordered by the risk it carries into an audit
- A lead auditor will walk the result with you if you want
No card, no account. We ask for your details on the next step so the result can reach you.
How it works
Four steps, about fifteen minutes
Pick a framework
Choose the standard you are assessed against, or the one you are heading towards.
Answer the control survey
Short, plain-English questions grouped by control domain. No jargon, no scoring tricks.
Get your readiness score
A domain-by-domain score with the weakest areas surfaced first.
Review with an assessor
Optional. A senior, empanelled assessor walks the result with you and sizes the remediation.
01 / 07
Payments and cards
PCI DSS v4.0.1
All twelve requirements, with scope and SAQ eligibility checked first.
- QSA-reviewed
02 / 07
Information security
ISO/IEC 27001:2022
Clauses 4 to 10 plus the 93 Annex A controls, scored by theme.
- Certifiable
SOC 2
Trust Services Criteria across security, availability, confidentiality, processing integrity and privacy.
- Type I and II
03 / 07
Data privacy
DPDP Act, 2023
Consent, notice, rights, grievance SLAs, breach duties and processor governance.
- India
GDPR
Lawful basis, rights handling, RoPA, DPIA and transfer safeguards.
- EU and UK
ISO/IEC 27701
Privacy information management extension to an existing 27001 system.
- PIMS
04 / 07
Healthcare
HIPAA
Security and Privacy Rule safeguards, plus breach notification readiness.
- PHI
HITRUST CSF
The harmonised control set often demanded by US healthcare buyers.
- Certifiable
05 / 07
Cyber frameworks
NIST CSF 2.0
Govern, Identify, Protect, Detect, Respond and Recover, scored by function.
- Outcome-based
CERT-In cyber audit
Readiness against the directions, including logging and reporting duties.
- India
CIS Controls v8.1
The 18 controls and their implementation groups, sized to your maturity.
- IG1 to IG3
NIST SP 800-53 Rev. 5
The federal catalogue, filtered to the baseline that fits your system.
- Control catalogue
CMMI V3.0
Process maturity at level 2 or 3, for organisations asked to evidence capability.
- Level 2 and 3
06 / 07
BFSI, India
RBI Cyber Security Framework
Baseline and advanced controls, PSS audit and localisation checks.
- Banks, NBFCs, PSOs
SEBI CSCRF
Graded cyber resilience requirements for regulated market entities.
- Intermediaries
SWIFT CSP (CSCF)
Mandatory and advisory controls ahead of your annual attestation.
- Annual attestation
NPCI UPI / TPAP audit
Participant and third-party app provider security expectations.
- UPI ecosystem
07 / 07
Resilience and international
ISO 22301
Business continuity management, tested rather than documented.
- BCMS
UAE IA / NESA
The UAE Information Assurance standard for regulated entities.
- Middle East
NIS2 Directive
EU obligations for essential and important entities, including management liability.
- European Union
CMMC 2.0 Level 2
Readiness for organisations in the US defence supply chain.
- United States
More resources
Keep going
Talk to us
Want an assessor to review your score?
Send us the output and a senior, empanelled assessor will walk it with you, size the remediation and tell you honestly how far you are from an audit.
support@threatsys.co.in