How this calculator works
| Metric | Formula |
|---|---|
| Area score | 0–3 per question (first answer 0, last answer 3) |
| Readiness | sum of area scores ÷ 36 × 100 |
| Level | ≥ 80% and no weak areas audit-ready · ≥ 60% well advanced · ≥ 35% developing · otherwise early stage |
Worked example
With these inputs:
- Framework you are working towards: ISO 27001
- Security policies and ownership: Informal, no owner
- Do you know what systems and personal data you have?: Partly, in people’s heads
- Security risk assessment: Done once, informally
- Access control and multi-factor authentication: MFA on some systems
- Encryption of data: HTTPS only
- Patching and vulnerability management: Automatic updates on some systems
- Logging and monitoring: Logs exist but nobody reviews them
- Incident response: Know who to call
- Backups and business continuity: Backups, never tested
- Vendors and data processors: A list of vendors
- Staff security awareness: Occasional reminders
- Privacy rights and data retention: Privacy notice only
ISO 27001 readiness: 33%. Readiness for ISO 27001: 33% (Early stage), with 12 areas needing significant work.
| Level | Early stage |
|---|---|
| Score | 12 of 36 |
| Areas needing significant work | 12 |
| Weakest area | Policies & ownership |
Open this example in the calculator
How the frameworks compare
| ISO 27001 | SOC 2 | GDPR | DPDP Act | |
|---|---|---|---|---|
| What it is | International standard for an information security management system | US attestation report on security controls (AICPA) | EU / UK data protection law | India’s Digital Personal Data Protection Act 2023 |
| Outcome | Certificate, valid 3 years with yearly surveillance audits | Auditor’s report (Type I or Type II) | Legal compliance, no certificate | Legal compliance, no certificate |
| Usually asked for by | Enterprise and international customers | US customers, especially for SaaS | Anyone handling EU / UK personal data | Anyone handling personal data of people in India |
Where each area appears in the frameworks
The same control usually satisfies several frameworks, so one programme can prepare you for more than one.
| Area | ISO 27001:2022 | SOC 2 (TSC) | GDPR | DPDP Act |
|---|---|---|---|---|
| Policies & ownership | A.5.1, A.5.2 | CC1.3, CC5.3 | Art. 24 | Sec. 8(1), 8(5) |
| Data & asset inventory | A.5.9, A.5.12 | CC6.1 | Art. 30 | Sec. 8(5) |
| Risk assessment | Clause 6.1.2, 8.2 | CC3.1–CC3.4 | Art. 32, 35 | Sec. 8(5) |
| Access control & MFA | A.5.15, A.5.18, A.8.5 | CC6.1–CC6.3 | Art. 32 | Sec. 8(5) |
| Encryption | A.8.24 | CC6.1, CC6.7 | Art. 32(1)(a) | Sec. 8(5) |
| Patching & vulnerabilities | A.8.8 | CC7.1 | Art. 32(1)(d) | Sec. 8(5) |
| Logging & monitoring | A.8.15, A.8.16 | CC7.2 | Art. 32 | Sec. 8(5) |
| Incident response | A.5.24–A.5.28 | CC7.3–CC7.5 | Art. 33, 34 | Sec. 8(6) |
| Backups & continuity | A.8.13, A.5.30 | A1.2, A1.3 | Art. 32(1)(c) | Sec. 8(5) |
| Vendors & processors | A.5.19–A.5.22 | CC9.2 | Art. 28 | Sec. 8(2) |
| Staff awareness | A.6.3 | CC1.4, CC2.2 | Art. 39(1)(b) | Sec. 8(5) |
| Privacy rights & retention | A.5.34 | P1–P8 (privacy criteria) | Art. 5(1)(e), 12–17 | Sec. 5, 8(7), 11–13 |
Typical path to certification or compliance
- Agree scope: which systems, locations and data are covered.
- Run a gap assessment (this tool is a quick start) and a risk assessment.
- Implement missing controls and write the policies that describe them.
- Collect evidence that controls operate: access reviews, logs, training records, tested restores.
- Run an internal audit, fix findings, then book the external audit if needed.
Open this calculator with your numbers
Every option can be set in the web address, so you can bookmark a scenario or send it to a colleague. AI assistants such as ChatGPT, Gemini, Claude and Perplexity can use the same parameters to open this calculator with your numbers and the result already on the page.
| Parameter | What it sets | Accepted values |
|---|---|---|
framework |
Framework you are working towards | one of iso27001, soc2, gdpr, dpdp |
policies |
Security policies and ownership | one of l0, l1, l2, l3 |
assets |
Do you know what systems and personal data you have? | one of l0, l1, l2, l3 |
risk |
Security risk assessment | one of l0, l1, l2, l3 |
access |
Access control and multi-factor authentication | one of l0, l1, l2, l3 |
encryption |
Encryption of data | one of l0, l1, l2, l3 |
vulnerabilities |
Patching and vulnerability management | one of l0, l1, l2, l3 |
monitoring |
Logging and monitoring | one of l0, l1, l2, l3 |
incidents |
Incident response | one of l0, l1, l2, l3 |
backups |
Backups and business continuity | one of l0, l1, l2, l3 |
vendors |
Vendors and data processors | one of l0, l1, l2, l3 |
training |
Staff security awareness | one of l0, l1, l2, l3 |
privacy |
Privacy rights and data retention | one of l0, l1, l2, l3 |
Also available as plain text for AI assistants and a free JSON API (OpenAPI spec).
Sources
- ISO/IEC 27001:2022 — Information security management systems
- AICPA — SOC 2 Trust Services Criteria
- GDPR — official text (EUR-Lex)
- Digital Personal Data Protection Act, 2023 (MeitY)
Last reviewed by the Infikey Technologies team.
Disclaimer
This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.