Compliance readiness self-assessment
Answer 9 quick questions and get a readiness score, the frameworks that best fit your business, and the top gaps to close first. No login, no email required to see your result, and nothing you enter leaves your browser.
Questions people ask
How is the readiness score calculated?
Your score is the share of core GRC practices you already have in place across seven domains: access control and offboarding, written security policies, a risk register, vendor and third-party risk, evidence collection, logging and monitoring, and employee security training. Each answer counts as fully in place, partially in place, or not yet, and the total becomes a percentage. It is a directional self-assessment to show you where to start, not a formal audit or a guarantee of certification.
Which framework should I actually pursue?
It depends on why you are doing this. SaaS companies selling to enterprise usually pursue SOC 2 or ISO 27001. If you handle health data, HIPAA applies. If you take card payments, PCI DSS applies. If you make or ship products or want a quality system, ISO 9001 fits. And if you are just getting started, NIST CSF is a great free foundation. The tool recommends based on your answers, and all of these are live in Keel today.
Is NIST CSF really free in Keel?
Yes. NIST CSF 2.0 is included free on every Keel plan, including the free plan, so you can stand up a real program with no credit card. Paid frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA are available on paid plans, and because everything is crosswalked, the work you do for one carries into the next.
This is a directional self-assessment to help you decide where to start. It is not a formal audit, a certification, or legal advice. Framework names are referenced factually and Keel is not affiliated with or endorsed by the bodies that publish them.