Free tool · about 2 minutes

Compliance readiness self-assessment

Answer 9 quick questions and get a readiness score, the frameworks that best fit your business, and the top gaps to close first. No login, no email required to see your result, and nothing you enter leaves your browser.

0 of 9 answered 0%
1. When someone leaves or changes role, is their access removed from every system on a documented, timely basis?

Access control and offboarding

2. Do you have written, approved security policies that your team actually follows (not just a template in a drawer)?

Written security policies

3. Do you maintain a risk register that scores risks and assigns owners and treatments?

Risk register

4. Do you assess your vendors and third parties for security risk, with a review cadence?

Vendor and third-party risk

5. Can you produce evidence on demand (records, screenshots, exports) that your controls are actually operating?

Evidence collection

6. Do you centrally log and monitor your key systems, and would you notice something unusual?

Logging and monitoring

7. Do your employees complete security awareness training, with a record you could show an auditor?

Employee security training

8. What is driving this for you right now?

Business goal

9. Which best describes your business?

This picks the right framework for you

Please answer every question to see your results.

Your readiness

0%

Your top gaps to close first

Prioritized from your weakest answers. Start at the top.

    Recommended for you

    Every framework below is live in Keel today.

    Close these gaps in Keel, free

    Keel turns this checklist into a real, running program: apply a pre-mapped control set, draft policies, seed your risk register, and collect evidence once so it counts across every framework. NIST CSF and AI Governance Essentials are free on every plan, no credit card.

    Email me my full results (optional)

    We will send your score, gaps, and recommended frameworks so it is easy to share with your team. No spam, unsubscribe anytime.

    By submitting you agree to receive your results and related emails. See our privacy policy.

    On its way

    Check your inbox for your full readiness results. In the meantime, you can start free in Keel and begin closing these gaps.

    Questions people ask

    How is the readiness score calculated?

    Your score is the share of core GRC practices you already have in place across seven domains: access control and offboarding, written security policies, a risk register, vendor and third-party risk, evidence collection, logging and monitoring, and employee security training. Each answer counts as fully in place, partially in place, or not yet, and the total becomes a percentage. It is a directional self-assessment to show you where to start, not a formal audit or a guarantee of certification.

    Which framework should I actually pursue?

    It depends on why you are doing this. SaaS companies selling to enterprise usually pursue SOC 2 or ISO 27001. If you handle health data, HIPAA applies. If you take card payments, PCI DSS applies. If you make or ship products or want a quality system, ISO 9001 fits. And if you are just getting started, NIST CSF is a great free foundation. The tool recommends based on your answers, and all of these are live in Keel today.

    Is NIST CSF really free in Keel?

    Yes. NIST CSF 2.0 is included free on every Keel plan, including the free plan, so you can stand up a real program with no credit card. Paid frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA are available on paid plans, and because everything is crosswalked, the work you do for one carries into the next.