How to take it.

For each question, pick the option that's most honest about your current state — not the policy on paper, not what you've planned. The diagnostic is most useful when it surfaces what isn't actually happening yet.

Yes — documented and operating.Policy exists, evidence exists, it's actually happening.
Partial.Some of it is in place; pieces are missing or undocumented.
No.Not in place today, even informally.
Doesn't apply.Genuinely not relevant — e.g. no AI use yet, no customer data, etc.

Answer the questions above — your readiness report renders here once you're done.

Got the result. Now what?

30 minutes, free, no pitch. We'll walk through where the gaps sit, what's worth fixing before the next customer security review, and what an honest 90-day path to SOC2 + AI governance readiness looks like for a company your size.

Book a Discovery Call →