# Security compliance readiness assessment: ISO 27001, SOC 2, GDPR and DPDP

> Security compliance readiness is how close your controls are to what an auditor or regulator expects. ISO 27001, SOC 2, GDPR and India’s DPDP Act share the same foundations: policies, an inventory of data, risk assessment, access control with MFA, encryption, patching, monitoring, incident response, backups, vendor management, training and privacy rights. Score each area below to see your gaps mapped to the framework you are targeting.

- Interactive version: https://infikeytechnologies.com/tools/security-compliance-readiness-score
- Type: free instant calculator
- Category: Security & compliance
- Last reviewed: 2026-10-05
- Publisher: Infikey Technologies (https://infikeytechnologies.com)

## Example result (default inputs)

| Input | Value |
| --- | --- |
| Framework you are working towards | ISO 27001 |
| Security policies and ownership | Informal, no owner |
| Do you know what systems and personal data you have? | Partly, in people’s heads |
| Security risk assessment | Done once, informally |
| Access control and multi-factor authentication | MFA on some systems |
| Encryption of data | HTTPS only |
| Patching and vulnerability management | Automatic updates on some systems |
| Logging and monitoring | Logs exist but nobody reviews them |
| Incident response | Know who to call |
| Backups and business continuity | Backups, never tested |
| Vendors and data processors | A list of vendors |
| Staff security awareness | Occasional reminders |
| Privacy rights and data retention | Privacy notice only |

**ISO 27001 readiness: 33%.** Readiness for ISO 27001: 33% (Early stage), with 12 areas needing significant work.

Early stage: begin with ownership, an inventory of data and a risk assessment, then MFA and backups — the controls that prevent the most common incidents.

| Metric | Value |
| --- | --- |
| Level | Early stage |
| Score | 12 of 36 |
| Areas needing significant work | 12 |
| Weakest area | Policies & ownership |

### Score by area

| Item | Value | Detail |
| --- | --- | --- |
| Policies & ownership | 1 / 3 |  |
| Data & asset inventory | 1 / 3 |  |
| Risk assessment | 1 / 3 |  |
| Access control & MFA | 1 / 3 |  |
| Encryption | 1 / 3 |  |
| Patching & vulnerabilities | 1 / 3 |  |
| Logging & monitoring | 1 / 3 |  |
| Incident response | 1 / 3 |  |
| Backups & continuity | 1 / 3 |  |
| Vendors & processors | 1 / 3 |  |
| Staff awareness | 1 / 3 |  |
| Privacy rights & retention | 1 / 3 |  |

**Gaps and next steps**

| Area | Today | ISO 27001 reference | Next step |
| --- | --- | --- | --- |
| Policies & ownership | Informal, no owner | A.5.1, A.5.2 | Approve an information security policy, name an owner for security and review it every year. |
| Data & asset inventory | Partly, in people’s heads | A.5.9, A.5.12 | List your systems, devices and the personal data each holds, with an owner for each. |
| Risk assessment | Done once, informally | Clause 6.1.2, 8.2 | Run a yearly risk assessment and keep a risk register with owners and treatment plans. |
| Access control & MFA | MFA on some systems | A.5.15, A.5.18, A.8.5 | Enforce MFA everywhere, give least-privilege access and review access every quarter. |
| Encryption | HTTPS only | A.8.24 | Encrypt data in transit and at rest, including laptops and backups, and manage keys. |
| Patching & vulnerabilities | Automatic updates on some systems | A.8.8 | Patch on a schedule, scan for vulnerabilities monthly and test critical systems yearly. |
| Logging & monitoring | Logs exist but nobody reviews them | A.8.15, A.8.16 | Collect logs centrally, alert on suspicious activity and keep logs long enough to investigate. |
| Incident response | Know who to call | A.5.24–A.5.28 | Write an incident response plan with notification steps and rehearse it at least once a year. |
| Backups & continuity | Backups, never tested | A.8.13, A.5.30 | Back up automatically, keep an offline or immutable copy and test restores regularly. |
| Vendors & processors | A list of vendors | A.5.19–A.5.22 | Keep a vendor list, check their security and sign data processing agreements. |
| Staff awareness | Occasional reminders | A.6.3 | Train everyone at joining and every year, and run phishing simulations. |
| Privacy rights & retention | Privacy notice only | A.5.34 | Publish a clear privacy notice, handle access and deletion requests, and delete data you no longer need. |

- ISO 27001 certification also needs the management system: scope, Statement of Applicability, internal audit and management review.

Open this result on the website: https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=iso27001&policies=l1&assets=l1&risk=l1&access=l1&encryption=l1&vulnerabilities=l1&monitoring=l1&incidents=l1&backups=l1&vendors=l1&training=l1&privacy=l1

## Use from a link or API

Add these query parameters to https://infikeytechnologies.com/tools/security-compliance-readiness-score (pre-filled page), https://infikeytechnologies.com/tools/security-compliance-readiness-score.md (this plain-text page) or https://infikeytechnologies.com/api/tools/security-compliance-readiness-score (JSON).

| Parameter | Meaning | Accepted values |
| --- | --- | --- |
| `framework` | Framework you are working towards | one of iso27001, soc2, gdpr, dpdp |
| `policies` | Security policies and ownership | one of l0, l1, l2, l3 |
| `assets` | Do you know what systems and personal data you have? | one of l0, l1, l2, l3 |
| `risk` | Security risk assessment | one of l0, l1, l2, l3 |
| `access` | Access control and multi-factor authentication | one of l0, l1, l2, l3 |
| `encryption` | Encryption of data | one of l0, l1, l2, l3 |
| `vulnerabilities` | Patching and vulnerability management | one of l0, l1, l2, l3 |
| `monitoring` | Logging and monitoring | one of l0, l1, l2, l3 |
| `incidents` | Incident response | one of l0, l1, l2, l3 |
| `backups` | Backups and business continuity | one of l0, l1, l2, l3 |
| `vendors` | Vendors and data processors | one of l0, l1, l2, l3 |
| `training` | Staff security awareness | one of l0, l1, l2, l3 |
| `privacy` | Privacy rights and data retention | one of l0, l1, l2, l3 |

- Early-stage start-up: https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=soc2&policies=l0&assets=l1&risk=l0&access=l2&encryption=l1&vulnerabilities=l1&monitoring=l0&incidents=l1&backups=l1&vendors=l1&training=l1&privacy=l1
- Growing SaaS company: https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=iso27001&policies=l2&assets=l2&risk=l2&access=l3&encryption=l2&vulnerabilities=l2&monitoring=l2&incidents=l1&backups=l2&vendors=l1&training=l2&privacy=l2
- Mature IT team: https://infikeytechnologies.com/tools/security-compliance-readiness-score?framework=gdpr&policies=l3&assets=l3&risk=l3&access=l3&encryption=l3&vulnerabilities=l3&monitoring=l3&incidents=l3&backups=l3&vendors=l2&training=l3&privacy=l2

## How it is calculated

- **Area score**: 0–3 per question (first answer 0, last answer 3)
- **Readiness**: sum of area scores ÷ 36 × 100
- **Level**: ≥ 80% and no weak areas audit-ready · ≥ 60% well advanced · ≥ 35% developing · otherwise early stage

## How the frameworks compare

|  | ISO 27001 | SOC 2 | GDPR | DPDP Act |
| --- | --- | --- | --- | --- |
| What it is | International standard for an information security management system | US attestation report on security controls (AICPA) | EU / UK data protection law | India’s Digital Personal Data Protection Act 2023 |
| Outcome | Certificate, valid 3 years with yearly surveillance audits | Auditor’s report (Type I or Type II) | Legal compliance, no certificate | Legal compliance, no certificate |
| Usually asked for by | Enterprise and international customers | US customers, especially for SaaS | Anyone handling EU / UK personal data | Anyone handling personal data of people in India |

## Where each area appears in the frameworks

The same control usually satisfies several frameworks, so one programme can prepare you for more than one.

| Area | ISO 27001:2022 | SOC 2 (TSC) | GDPR | DPDP Act |
| --- | --- | --- | --- | --- |
| Policies & ownership | A.5.1, A.5.2 | CC1.3, CC5.3 | Art. 24 | Sec. 8(1), 8(5) |
| Data & asset inventory | A.5.9, A.5.12 | CC6.1 | Art. 30 | Sec. 8(5) |
| Risk assessment | Clause 6.1.2, 8.2 | CC3.1–CC3.4 | Art. 32, 35 | Sec. 8(5) |
| Access control & MFA | A.5.15, A.5.18, A.8.5 | CC6.1–CC6.3 | Art. 32 | Sec. 8(5) |
| Encryption | A.8.24 | CC6.1, CC6.7 | Art. 32(1)(a) | Sec. 8(5) |
| Patching & vulnerabilities | A.8.8 | CC7.1 | Art. 32(1)(d) | Sec. 8(5) |
| Logging & monitoring | A.8.15, A.8.16 | CC7.2 | Art. 32 | Sec. 8(5) |
| Incident response | A.5.24–A.5.28 | CC7.3–CC7.5 | Art. 33, 34 | Sec. 8(6) |
| Backups & continuity | A.8.13, A.5.30 | A1.2, A1.3 | Art. 32(1)(c) | Sec. 8(5) |
| Vendors & processors | A.5.19–A.5.22 | CC9.2 | Art. 28 | Sec. 8(2) |
| Staff awareness | A.6.3 | CC1.4, CC2.2 | Art. 39(1)(b) | Sec. 8(5) |
| Privacy rights & retention | A.5.34 | P1–P8 (privacy criteria) | Art. 5(1)(e), 12–17 | Sec. 5, 8(7), 11–13 |

## Typical path to certification or compliance

- Agree scope: which systems, locations and data are covered.
- Run a gap assessment (this tool is a quick start) and a risk assessment.
- Implement missing controls and write the policies that describe them.
- Collect evidence that controls operate: access reviews, logs, training records, tested restores.
- Run an internal audit, fix findings, then book the external audit if needed.

## FAQ

### How long does ISO 27001 certification take?

Commonly 6–12 months for a small or mid-size organisation starting with basic controls, less if many controls already exist.

### What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are designed properly at a point in time. Type II tests that they worked over a period, usually 3–12 months.

### Should I choose ISO 27001 or SOC 2?

Choose based on your customers: SOC 2 is common in the US, ISO 27001 internationally. The controls overlap heavily, so many companies do both.

### Does the DPDP Act apply to my company?

It applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to people in India.

### Is this assessment a substitute for an audit?

No. It is a quick self-assessment to find gaps and plan work. Certification and legal compliance need a full assessment of your scope and evidence.

## Sources

- [ISO/IEC 27001:2022 — Information security management systems](https://www.iso.org/standard/27001)
- [AICPA — SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services)
- [GDPR — official text (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
- [Digital Personal Data Protection Act, 2023 (MeitY)](https://www.meity.gov.in/data-protection-framework)

## Get expert help

Send these results to an Infikey Technologies specialist from the form on https://infikeytechnologies.com/tools/security-compliance-readiness-score#estimate or via https://infikeytechnologies.com/contact.

More free calculators: https://infikeytechnologies.com/tools.md

## Disclaimer

This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.
