Free tool · about 2 minutes
Compliance readiness self-assessment
Answer 9 quick questions and get a readiness score, the frameworks that best fit your business, and the top gaps to close first. No login, no email required to see your result, and nothing you enter leaves your browser.
Your readiness
Your top gaps to close first
Prioritized from your weakest answers. Start at the top.
Recommended for you
Every framework below is live in Keel today.
Close these gaps in Keel, free
Keel turns this checklist into a real, running program: apply a pre-mapped control set, draft policies, seed your risk register, and collect evidence once so it counts across every framework. NIST CSF and AI Governance Essentials are free on every plan, no credit card.
On its way
Check your inbox for your full readiness results. In the meantime, you can start free in Keel and begin closing these gaps.
Questions people ask
How is the readiness score calculated?
Your score is the share of core GRC practices you already have in place across seven domains: access control and offboarding, written security policies, a risk register, vendor and third-party risk, evidence collection, logging and monitoring, and employee security training. Each answer counts as fully in place, partially in place, or not yet, and the total becomes a percentage. It is a directional self-assessment to show you where to start, not a formal audit or a guarantee of certification.
Which framework should I actually pursue?
It depends on why you are doing this. SaaS companies selling to enterprise usually pursue SOC 2 or ISO 27001. If you handle health data, HIPAA applies. If you take card payments, PCI DSS applies. If you make or ship products or want a quality system, ISO 9001 fits. And if you are just getting started, NIST CSF is a great free foundation. The tool recommends based on your answers, and all of these are live in Keel today.
Is NIST CSF really free in Keel?
Yes. NIST CSF 2.0 is included free on every Keel plan, including the free plan, so you can stand up a real program with no credit card. Paid frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA are available on paid plans, and because everything is crosswalked, the work you do for one carries into the next.