Free Tool
Compliance Readiness Assessment
Answer 8 questions about your business. We'll tell you which frameworks apply and what they require.
How this tool works: Your responses are processed entirely in your browser — nothing you enter is stored, transmitted, or used to identify you. No cookies, no personal data, no tracking. Results are generated on-device only. Privacy Policy
This tool provides general guidance based on the information you provide. It is an initial starting point, not a substitute for professional assessment. Every organization's environment is unique — results should be reviewed with a qualified advisor before making compliance or security decisions.
Next Step
Want a deeper look?
This tool gives you a directional read. A free 20-minute call gives you a clearer picture of the gaps that matter most for your specific situation — and an honest view of whether DARS can help.
Book a free 20-minute call →No commitment. No sales pitch. If we’re not the right fit, we’ll tell you.
Who this tool is for
Use this quiz when someone has asked you for a certification, a questionnaire, or an attestation and you are not sure which frameworks actually apply. It is written for the people who get that question first: founders closing an enterprise deal, practice managers handling patient data, contracts staff at a defense subcontractor, nonprofit leaders processing donor card payments, and product teams shipping AI features. It is equally useful for a five-person startup and a multi-office firm — the frameworks do not care about headcount, they care about what data you touch and who you sell to.
What it measures — and what “in scope” means
Eight questions establish your regulatory surface: headcount, industry, whether you handle protected health information, whether you process card payments, whether you hold EU residents' data, whether you serve government agencies or prime contractors, whether you use AI or machine learning, and whether enterprise customers demand security certifications. The result lists the frameworks most likely in scope — SOC 2, HIPAA, PCI DSS, GDPR, CMMC or NIST SP 800-171, and emerging AI governance requirements — with a plain-language summary of what each one expects. "In scope" means a framework's own applicability tests are met by your answers; it does not mean you are currently compliant with it.
What your result is not
This is a scoping aid, not legal advice and not a gap assessment. It cannot tell you whether a specific contract clause makes SOC 2 mandatory, whether a particular data flow triggers HIPAA, or which CMMC level a given solicitation requires. Regulations have exceptions, and contracts add obligations that no quiz can see. Use the result to focus a conversation with counsel or an advisor, not to conclude one.
Frequently asked questions
QDo I need SOC 2 if only one customer is asking for it?
Possibly. SOC 2 is not legally required, but if that customer represents meaningful revenue, a Type I report is often the pragmatic answer. The related cost article breaks down what a right-sized engagement actually costs.
QWhat is the difference between CMMC and NIST 800-171?
NIST SP 800-171 is the set of 110 security requirements for protecting controlled unclassified information. CMMC is the Department of Defense program that verifies contractors have implemented them. If you handle CUI on a defense contract, both apply.
QDoes GDPR apply to a U.S. company?
It can. If you offer goods or services to people in the EU or monitor their behavior, GDPR applies regardless of where your company is located.
QWe use ChatGPT and Copilot. Does that create compliance obligations?
It can, depending on what data goes in. Maryland's MODPA, the EU AI Act, and sector rules like HIPAA all reach AI tools that process regulated data. The AI Inventory tool is the right next step.
QCan I get a certificate from this quiz?
No. It tells you which frameworks to investigate. Certifications and attestations come from accredited assessors and CPA firms after an audit.
Related reading
Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.
Need a Deeper Analysis?
This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.
Schedule a Scope Call