Free tool

Compliance readiness, before the assessor arrives.

Most big contracts and enterprise deals now come with a security bar you have to clear before anyone signs. That bar has names: CMMC Level 2 / NIST 800-171, SOC 2, ISO 27001, and/or ISO 42001. You rarely need them all, and underneath they ask for many of the same things. Mark where you honestly stand on each, with AI in scope, and you get a red / amber / green readiness picture and the prioritized gap list to take to leadership. No email wall, nothing hidden.

How to mark each control

Not started · In progress · Met, evidenced. An assessor scores what you can show, not what you mean to do.

Access & identity

Who can get into your systems, and how you prove who they are · CMMC AC/IA · SOC 2 CC6 · ISO 27001 A.8
Multi-factor authentication is required for admin accounts and anyone signing in remotely.
People and tools get only the access they need to do the job, and that access is reviewed on a regular schedule.
Every AI system, agent, and automated account has its own tracked login, not a shared or anonymous one.

Data protection & boundaries

Keeping sensitive data protected, and watching where AI sends it · CMMC SC/MP · SOC 2 CC6·C1 · ISO 27001 A.8
Sensitive data, including controlled federal information (CUI), is encrypted both where it is stored and while it moves.
You know what data goes into your AI and cloud tools (the prompts, the answers, the training data) and you control it.
Something is in place to stop sensitive data from leaving through AI tools and chat.

Configuration & inventory

Knowing what you run, and locking down how it is set up · CMMC CM · SOC 2 CC8 · ISO 27001 A.8
You have a complete list of your systems, including the AI ones and the high-stakes uses.
Systems are set up to a known secure standard, not however each one happened to be configured.
Changes go through a documented process, with sign-off and a way to undo them.

Audit, logging & monitoring

Keeping a record of what happened, so you can answer for it later · CMMC AU/SI · SOC 2 CC7 · ISO 27001 A.8
Important security events are recorded across your systems, including how AI is used.
Those records are kept as long as policy requires and protected from being changed.
Someone, or something, watches for unusual activity, misuse, and AI-specific problems.

Incident response & continuity

Having a plan for when something goes wrong, and practicing it · CMMC IR · SOC 2 CC7 · ISO 27001 A.5
You have a written plan for when something goes wrong, and you have run through it at least once.
That plan covers AI-specific failures: bad model output, leaked data, and misuse.
You know how fast you must report a problem (a 72-hour clock on some federal work, or whatever you promised customers) and you have rehearsed it.

Governance, risk & assessment

Owning the risk: who decides, who checks, who signs off · NIST 800-171 RA/CA · SOC 2 CC3/CC9 · ISO 27001 cl.6 · ISO 42001
Your risks are written down and kept current, with a plan to close the gaps you find.
Outside vendors and their AI are checked for risk before you put them to work.
Your AI runs under a defined management system (the kind ISO 42001 describes), so the controls and the proof stay in one place.
Your readiness
Not assessment-ready
0% ready · 0 of 18 controls evidenced
By control domain
Close before your assessor arrives

A self-assessment, not a formal gap assessment. Reds and ambers are the findings to close.

A professional SOC 2, NIST 800-171, or CMMC L2 readiness assessment runs $10,000–$20,000 — same gap profile, free.

Market rate: Secureframe & Drata, 2026.

Scored yourself? The Expert Readiness Assessment validates these results against evidence and turns them into a roadmap you can defend.

Book a conversation →
Which regime, and why it pays

Compliance is rarely the goal. It is the gate in front of something you want: a contract, a signed deal, a new market. You usually need only the standards standing between you and your next outcome, not all of them. Here is what each one is, in plain terms, and what clearing it gets you.

CMMC Level 2 · federal / defense

You want to win or keep Department of Defense work. CMMC is the security badge the DoD now requires before it trusts you with sensitive government information. No badge, no contract, and the bigger firms you subcontract under cannot legally hand you the work.

NIST SP 800-171 · federal / defense

You want that government work without nasty surprises in the audit. NIST 800-171 is the actual list of safeguards behind the CMMC badge. Meet it and your security plan holds up when the government checks; miss it and a single gap can stall the award.

SOC 2 · US commercial

You want enterprise and software customers to sign. SOC 2 is the independent report their security teams ask for before they will. Hand them a clean one and the deal moves; show up without it and you are stuck answering security questionnaires while the deal sits.

ISO 27001 · international

You want to sell into Europe and to global enterprises. ISO 27001 is the internationally recognized certificate that says your security is run properly and on purpose, not patched together. Often it is simply the price of being considered.

ISO 42001 · AI assurance

You want people to trust the AI you put in front of them. ISO 42001 is the new standard for governing the AI itself, so you can show a board, a customer, or a regulator that it is under control. It puts you ahead of the EU AI Act and the AI clauses now turning up in contracts.