Compliance Readiness Assessment

Answer 8 questions about your business. We'll tell you which frameworks apply and what they require.

Your data stays in your browser
No signup required
No tracking or data collection

How this tool works: Your responses are processed entirely in your browser — nothing you enter is stored, transmitted, or used to identify you. No cookies, no personal data, no tracking. Results are generated on-device only. Privacy Policy

Who this tool is for

Use this quiz when someone has asked you for a certification, a questionnaire, or an attestation and you are not sure which frameworks actually apply. It is written for the people who get that question first: founders closing an enterprise deal, practice managers handling patient data, contracts staff at a defense subcontractor, nonprofit leaders processing donor card payments, and product teams shipping AI features. It is equally useful for a five-person startup and a multi-office firm — the frameworks do not care about headcount, they care about what data you touch and who you sell to.

What it measures — and what “in scope” means

Eight questions establish your regulatory surface: headcount, industry, whether you handle protected health information, whether you process card payments, whether you hold EU residents' data, whether you serve government agencies or prime contractors, whether you use AI or machine learning, and whether enterprise customers demand security certifications. The result lists the frameworks most likely in scope — SOC 2, HIPAA, PCI DSS, GDPR, CMMC or NIST SP 800-171, and emerging AI governance requirements — with a plain-language summary of what each one expects. "In scope" means a framework's own applicability tests are met by your answers; it does not mean you are currently compliant with it.

What your result is not

This is a scoping aid, not legal advice and not a gap assessment. It cannot tell you whether a specific contract clause makes SOC 2 mandatory, whether a particular data flow triggers HIPAA, or which CMMC level a given solicitation requires. Regulations have exceptions, and contracts add obligations that no quiz can see. Use the result to focus a conversation with counsel or an advisor, not to conclude one.

Frequently asked questions

QDo I need SOC 2 if only one customer is asking for it?

Possibly. SOC 2 is not legally required, but if that customer represents meaningful revenue, a Type I report is often the pragmatic answer. The related cost article breaks down what a right-sized engagement actually costs.

QWhat is the difference between CMMC and NIST 800-171?

NIST SP 800-171 is the set of 110 security requirements for protecting controlled unclassified information. CMMC is the Department of Defense program that verifies contractors have implemented them. If you handle CUI on a defense contract, both apply.

QDoes GDPR apply to a U.S. company?

It can. If you offer goods or services to people in the EU or monitor their behavior, GDPR applies regardless of where your company is located.

QWe use ChatGPT and Copilot. Does that create compliance obligations?

It can, depending on what data goes in. Maryland's MODPA, the EU AI Act, and sector rules like HIPAA all reach AI tools that process regulated data. The AI Inventory tool is the right next step.

QCan I get a certificate from this quiz?

No. It tells you which frameworks to investigate. Certifications and attestations come from accredited assessors and CPA firms after an audit.

Related reading

SOC 2 Without the Enterprise Price TagHow Much Does SOC 2 Cost in 2026? The Full Cost Stack — and Where Companies OverspendWhat CMMC 2.0 Actually Means for Small Contractors

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.

Need a Deeper Analysis?

This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.

Schedule a Scope Call