Compliance Readiness Scorecard
Self-assess your organization's security and compliance posture across 6 critical domains. This scorecard maps to requirements from HIPAA, SOC 2, NIST CSF, PCI DSS, and general state breach notification laws. Answer honestly — knowing your gaps is the first step to fixing them.
Governance & Policy
Select each control that is implemented and operational
Access Control
Select each control that is implemented and operational
Data Protection
Select each control that is implemented and operational
Network Security
Select each control that is implemented and operational
Incident Response
Select each control that is implemented and operational
Security Awareness
Select each control that is implemented and operational
What Does This Scorecard Cover?
This compliance readiness scorecard evaluates six critical domains that map to requirements across multiple regulatory frameworks including HIPAA, SOC 2, NIST Cybersecurity Framework, PCI DSS, and state-level breach notification laws like OK Stat § 74-3113.1.
The scorecard covers 25 individual controls weighted from 1–2 points each based on their impact on overall security posture and regulatory compliance. Controls related to MFA, encryption, incident response, and risk assessments carry higher weight because they address the most commonly exploited vulnerabilities and are central to most compliance mandates.