Tools
These are interactive calculators and assessments for the questions that a static reference page can only answer with a range: which framework applies to your situation, roughly what your SOC 2 program will cost given your specific scope, how far back from a target report date you need to start, and how ready your controls actually are today.
Each tool runs entirely in your browser — there is no account, no email capture, and no data sent to a server to generate your result. Inputs and outputs are heuristics built from the same published pricing and framework data cited on the reference pages, not a quote or a certification decision. Treat the output as a starting point for a conversation with an auditor or certification body, not a substitute for one.
If you already know your answer (you know you need SOC 2 Type II, for example) skip straight to the control reference or a cost page. Use these tools when you are still narrowing down scope, budget, or timeline.
- Control gap analyzer
Heuristic scan of IAM, logging, change, vendor, and incident maturity against multi-framework targets — surfaces priority gaps before audit fieldwork.
- Cross-framework control mapper
Map a security theme (access control, encryption, vendors, incidents) across SOC 2, ISO 27001, GDPR, and HIPAA control families.
- Framework selector
Interactive tool to help you choose between SOC 2, ISO 27001, GDPR, and HIPAA based on buyers, geography, and data types.
- ISO 27001 cost calculator
Heuristic estimate of ISO/IEC 27001 certification costs — Stage 1/2 CB fees, optional consultant, and internal effort bands for SaaS ISMS programs.
- Framework readiness self-assessment
Interactive tool that scores your current posture against a chosen framework and highlights likely evidence gaps before an audit.
- SOC 2 cost calculator
Heuristic estimate of SOC 2 program cost bands — auditor fees, optional automation, and internal effort — based on type, scope, and company size.
- SOC 2 timeline calculator
Work backwards from a target report or deal date to plan gap assessment, observation window, fieldwork, and report delivery for SOC 2.
- Which Trust Services Criteria do I need?
Interactive tool that recommends which SOC 2 Trust Services Categories to include based on what you sell and who buys.