Security & compliance · Free tool

Security compliance readiness assessment: ISO 27001, SOC 2, GDPR and DPDP

Security compliance readiness is how close your controls are to what an auditor or regulator expects. ISO 27001, SOC 2, GDPR and India’s DPDP Act share the same foundations: policies, an inventory of data, risk assessment, access control with MFA, encryption, patching, monitoring, incident response, backups, vendor management, training and privacy rights. Score each area below to see your gaps mapped to the framework you are targeting.

Free, no sign-up · By Infikey Technologies · Updated

Use the calculator

Your numbers

Reset
Security policies and ownership
Do you know what systems and personal data you have?
Security risk assessment
Access control and multi-factor authentication
Encryption of data
Patching and vulnerability management
Logging and monitoring
Incident response
Backups and business continuity
Vendors and data processors
Staff security awareness
Privacy rights and data retention

Result

ISO 27001 readiness

33%

Readiness for ISO 27001: 33% (Early stage), with 12 areas needing significant work.

Early stage: begin with ownership, an inventory of data and a risk assessment, then MFA and backups — the controls that prevent the most common incidents.

Score by area
  • Policies & ownership 1 / 3
  • Data & asset inventory 1 / 3
  • Risk assessment 1 / 3
  • Access control & MFA 1 / 3
  • Encryption 1 / 3
  • Patching & vulnerabilities 1 / 3
  • Logging & monitoring 1 / 3
  • Incident response 1 / 3
  • Backups & continuity 1 / 3
  • Vendors & processors 1 / 3
  • Staff awareness 1 / 3
  • Privacy rights & retention 1 / 3
Security & compliance readiness score results
Level Early stage
Score 12 of 36
Areas needing significant work 12
Weakest area Policies & ownership

Gaps and next steps

AreaTodayISO 27001 referenceNext step
Policies & ownershipInformal, no ownerA.5.1, A.5.2Approve an information security policy, name an owner for security and review it every year.
Data & asset inventoryPartly, in people’s headsA.5.9, A.5.12List your systems, devices and the personal data each holds, with an owner for each.
Risk assessmentDone once, informallyClause 6.1.2, 8.2Run a yearly risk assessment and keep a risk register with owners and treatment plans.
Access control & MFAMFA on some systemsA.5.15, A.5.18, A.8.5Enforce MFA everywhere, give least-privilege access and review access every quarter.
EncryptionHTTPS onlyA.8.24Encrypt data in transit and at rest, including laptops and backups, and manage keys.
Patching & vulnerabilitiesAutomatic updates on some systemsA.8.8Patch on a schedule, scan for vulnerabilities monthly and test critical systems yearly.
Logging & monitoringLogs exist but nobody reviews themA.8.15, A.8.16Collect logs centrally, alert on suspicious activity and keep logs long enough to investigate.
Incident responseKnow who to callA.5.24–A.5.28Write an incident response plan with notification steps and rehearse it at least once a year.
Backups & continuityBackups, never testedA.8.13, A.5.30Back up automatically, keep an offline or immutable copy and test restores regularly.
Vendors & processorsA list of vendorsA.5.19–A.5.22Keep a vendor list, check their security and sign data processing agreements.
Staff awarenessOccasional remindersA.6.3Train everyone at joining and every year, and run phishing simulations.
Privacy rights & retentionPrivacy notice onlyA.5.34Publish a clear privacy notice, handle access and deletion requests, and delete data you no longer need.
  • ISO 27001 certification also needs the management system: scope, Statement of Applicability, internal audit and management review.

Estimates for planning only, not professional advice. Infikey Technologies accepts no liability for decisions based on these results — read the disclaimer.

Want an expert to sanity-check these numbers?

Send these results to an Infikey specialist and get a reply for your situation.

Ask an expert

How this calculator works

MetricFormula
Area score0–3 per question (first answer 0, last answer 3)
Readinesssum of area scores ÷ 36 × 100
Level≥ 80% and no weak areas audit-ready · ≥ 60% well advanced · ≥ 35% developing · otherwise early stage

Worked example

With these inputs:

  • Framework you are working towards: ISO 27001
  • Security policies and ownership: Informal, no owner
  • Do you know what systems and personal data you have?: Partly, in people’s heads
  • Security risk assessment: Done once, informally
  • Access control and multi-factor authentication: MFA on some systems
  • Encryption of data: HTTPS only
  • Patching and vulnerability management: Automatic updates on some systems
  • Logging and monitoring: Logs exist but nobody reviews them
  • Incident response: Know who to call
  • Backups and business continuity: Backups, never tested
  • Vendors and data processors: A list of vendors
  • Staff security awareness: Occasional reminders
  • Privacy rights and data retention: Privacy notice only

ISO 27001 readiness: 33%. Readiness for ISO 27001: 33% (Early stage), with 12 areas needing significant work.

LevelEarly stage
Score12 of 36
Areas needing significant work12
Weakest areaPolicies & ownership

Open this example in the calculator

How the frameworks compare

ISO 27001SOC 2GDPRDPDP Act
What it is International standard for an information security management system US attestation report on security controls (AICPA) EU / UK data protection law India’s Digital Personal Data Protection Act 2023
Outcome Certificate, valid 3 years with yearly surveillance audits Auditor’s report (Type I or Type II) Legal compliance, no certificate Legal compliance, no certificate
Usually asked for by Enterprise and international customers US customers, especially for SaaS Anyone handling EU / UK personal data Anyone handling personal data of people in India

Where each area appears in the frameworks

The same control usually satisfies several frameworks, so one programme can prepare you for more than one.

AreaISO 27001:2022SOC 2 (TSC)GDPRDPDP Act
Policies & ownership A.5.1, A.5.2 CC1.3, CC5.3 Art. 24 Sec. 8(1), 8(5)
Data & asset inventory A.5.9, A.5.12 CC6.1 Art. 30 Sec. 8(5)
Risk assessment Clause 6.1.2, 8.2 CC3.1–CC3.4 Art. 32, 35 Sec. 8(5)
Access control & MFA A.5.15, A.5.18, A.8.5 CC6.1–CC6.3 Art. 32 Sec. 8(5)
Encryption A.8.24 CC6.1, CC6.7 Art. 32(1)(a) Sec. 8(5)
Patching & vulnerabilities A.8.8 CC7.1 Art. 32(1)(d) Sec. 8(5)
Logging & monitoring A.8.15, A.8.16 CC7.2 Art. 32 Sec. 8(5)
Incident response A.5.24–A.5.28 CC7.3–CC7.5 Art. 33, 34 Sec. 8(6)
Backups & continuity A.8.13, A.5.30 A1.2, A1.3 Art. 32(1)(c) Sec. 8(5)
Vendors & processors A.5.19–A.5.22 CC9.2 Art. 28 Sec. 8(2)
Staff awareness A.6.3 CC1.4, CC2.2 Art. 39(1)(b) Sec. 8(5)
Privacy rights & retention A.5.34 P1–P8 (privacy criteria) Art. 5(1)(e), 12–17 Sec. 5, 8(7), 11–13

Typical path to certification or compliance

  • Agree scope: which systems, locations and data are covered.
  • Run a gap assessment (this tool is a quick start) and a risk assessment.
  • Implement missing controls and write the policies that describe them.
  • Collect evidence that controls operate: access reviews, logs, training records, tested restores.
  • Run an internal audit, fix findings, then book the external audit if needed.

Every option can be set in the web address, so you can bookmark a scenario or send it to a colleague. AI assistants such as ChatGPT, Gemini, Claude and Perplexity can use the same parameters to open this calculator with your numbers and the result already on the page.

ParameterWhat it setsAccepted values
framework Framework you are working towards one of iso27001, soc2, gdpr, dpdp
policies Security policies and ownership one of l0, l1, l2, l3
assets Do you know what systems and personal data you have? one of l0, l1, l2, l3
risk Security risk assessment one of l0, l1, l2, l3
access Access control and multi-factor authentication one of l0, l1, l2, l3
encryption Encryption of data one of l0, l1, l2, l3
vulnerabilities Patching and vulnerability management one of l0, l1, l2, l3
monitoring Logging and monitoring one of l0, l1, l2, l3
incidents Incident response one of l0, l1, l2, l3
backups Backups and business continuity one of l0, l1, l2, l3
vendors Vendors and data processors one of l0, l1, l2, l3
training Staff security awareness one of l0, l1, l2, l3
privacy Privacy rights and data retention one of l0, l1, l2, l3

Example: https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=soc2&policies=l0&assets=l1&risk=l0&access=l2&encryption=l1&vulnerabilities=l1&monitoring=l0&incidents=l1&backups=l1&vendors=l1&training=l1&privacy=l1

Also available as plain text for AI assistants and a free JSON API (OpenAPI spec).

Sources

Last reviewed by the Infikey Technologies team.

Disclaimer

This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.

FAQ

Security & compliance readiness score questions

How long does ISO 27001 certification take? +

Commonly 6–12 months for a small or mid-size organisation starting with basic controls, less if many controls already exist.

What is the difference between SOC 2 Type I and Type II? +

Type I assesses whether controls are designed properly at a point in time. Type II tests that they worked over a period, usually 3–12 months.

Should I choose ISO 27001 or SOC 2? +

Choose based on your customers: SOC 2 is common in the US, ISO 27001 internationally. The controls overlap heavily, so many companies do both.

Does the DPDP Act apply to my company? +

It applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to people in India.

Is this assessment a substitute for an audit? +

No. It is a quick self-assessment to find gaps and plan work. Certification and legal compliance need a full assessment of your scope and evidence.

Talk to an expert

Want an expert to sanity-check these numbers?

Your inputs and results are attached automatically, so we can reply with specific advice on Cybersecurity.