TOOL · COMPLIANCE READINESS · 12 MIN
Map your controls to a defensible posture.
Score six readiness dimensions against CMMC L2, NIST 800-171, SOC 2, and FedRAMP. Directional baseline only — outputs prioritize where to invest before a formal assessment.
THE SCORECARD
Six dimensions. One composite.
DIMENSIONS · SCORE 1—5
- Control ownershipNamed owners with SLAs for each control family.
- Evidence automationProgrammatic generation of recurring audit artifacts.
- Risk registerLiving register with mitigation owners and dates.
- Policy maturityDocumented, reviewed, version-controlled policy set.
- SecOps tempoDetection, response, and forensics readiness.
- Governance cadenceRecurring control review and risk forum.
SCALE
- · 1 = Ad hoc
- · 2 = Reactive
- · 3 = Standardized
- · 4 = Measured
- · 5 = Optimized
SCORE
COMPOSITE
0%
FOUNDATIONAL
- DIMENSIONS SCORED
- 0 / 6
- RAW SCORE
- 0 / 30
Baseline first: control inventory, ownership, and an evidence repository before any framework filing.