Would your security program pass an enterprise customer's review?
The domains that appear in every enterprise security questionnaire, mapped to the SOC 2 Trust Services Criteria with ISO 27001 crosswalks. You get the gaps that stall deals, the evidence a reviewer will ask for, and the full assessment to take next.
Ready to see where you stand?
You'll get a computed readiness indicator across Governance & policy, Identity & access, Data protection, Infrastructure & application security, Monitoring & incident response, Continuity & recovery, Vendors & people, Evidence & answers, the evidence that would answer each gap, and the full assessment to take next. Any critical gap is called out on its own, even when the overall score looks strong.
Assessment methodology: aligned to the AICPA SOC 2 Trust Services Criteria (2017, with 2022 points of focus) and ISO/IEC 27001:2022 Annex A. It reports a readiness indicator from your answers; it is not an audit, an attestation or a prediction of any customer's decision.
See your full results
Enter your email to unlock your readiness indicator, domain scores, top gaps, the evidence that would close them and recommended next steps.
- Overall readiness indicator and tier
- 8 domain scores with the SOC 2 Trust Services Criteria mapping
- Your highest-priority gaps, critical ones flagged
- The evidence that would answer each gap
- Recommended next steps and an email copy
Your Enterprise Security Readiness Readiness Indicator
Executive summary
Domain scores
Weighted: Governance & policy 15% · Identity & access 15% · Data protection 10% · Infrastructure & application security 15% · Monitoring & incident response 15% · Continuity & recovery 10% · Vendors & people 10% · Evidence & answers 10%. Expand a domain to see the contributing questions, your answers and the SOC 2 Trust Services Criteria references they map to.
Your highest-priority gaps
Evidence that would answer each gap
What an assessor, a customer or an auditor would ask to see. Having it is the difference between a readiness indicator and a verified result.
Recommended next steps
Assessment methodology: aligned to the AICPA SOC 2 Trust Services Criteria (2017, with 2022 points of focus) and ISO/IEC 27001:2022 Annex A. It reports a readiness indicator from your answers; it is not an audit, an attestation or a prediction of any customer's decision.
Please note: This assessment provides a readiness indicator based on the information provided. It is not an audit, a certification, or a guarantee of security outcomes.
Recommended full assessment: Enterprise Security Readiness Assessment
Enterprise deals stall in security review. The questionnaire arrives with 300 questions, three people answer it from memory over two weeks, the answers contradict last quarter's, and nobody can point to the evidence. The problem is not the questionnaire; it is that answers are not connected to controls and evidence. 30 minutes to scope. No obligation.