Free tools & readiness checks
Start with a one-minute readiness check — an indicative result straight away, no login, no email. Then the third-party tools we actually recommend to clients, and guides from the team.
getBuckler readiness checks
Where do you stand?
ISO 27001 readiness check
Six questions on scope, risk process, policies and internal audit. Instant indicative result — audit-ready, partway there or early stage. No email required.
Run the checkSOC 2 Type II readiness check
A one-minute check against the Trust Services Criteria, control ownership and evidence collection, with a recommended next step for your review period.
Run the checkPCI DSS readiness check
Quick questions on your cardholder data environment, validation path (SAQ or RoC) and the v4.0.1 requirements, with an indicative readiness level.
Run the checkFree 30-minute assessment call
A working call with a security architect to map where you stand against the framework you need and agree the next step. No cost, no obligation, no sales sequence.
Book a callTry it now
ISO 27001 readiness — 6 questions
Answer a few questions on scope, risk process, policies and internal audit. You get an indicative level and, if you want it, a tailored next step — all on this page.
ISO 27001 readiness check
Six quick questions, about a minute. You see the result straight away — no email required.
Tools we recommend
Free third-party assessment tools
Reputable, genuinely free tools we point clients to. getBuckler is not affiliated with any of them — links open in a new tab.
Framework self-assessment
CIS Controls Self Assessment Tool (CIS CSAT)
Center for Internet Security
Free web app to track and score your implementation of the CIS Critical Security Controls v8 across teams, with progress reporting over time.
CISA Cyber Security Evaluation Tool (CSET)
US Cybersecurity & Infrastructure Security Agency
Free downloadable desktop tool that walks you through a structured self-assessment against standards including NIST CSF, ISO 27001 and CIS Controls, and produces a gap report.
NIST Cybersecurity Framework 2.0
US National Institute of Standards and Technology
The CSF 2.0 core, quick-start guides and reference tool (CPRT) — a free baseline for describing and benchmarking your security programme by function and outcome.
Privacy & data protection
ICO data protection self-assessment toolkit
UK Information Commissioner’s Office
Free checklists for small organisations covering data-protection assurance, records management, information security and direct marketing, with an action list at the end.
CNIL PIA tool
Commission Nationale de l’Informatique et des Libertés (France)
Free open-source software that guides you through a GDPR Data Protection Impact Assessment methodically and generates the DPIA report.
Technical & cloud risk
Prowler
Open source (Toni de la Fuente / ProwlerPro)
Free command-line tool that assesses AWS, Azure, Google Cloud and Kubernetes against CIS Benchmarks and other checks, flagging misconfigurations and risk.
SSL Labs Server Test
Qualys
Free online test that grades a public web server’s TLS configuration and certificate chain and explains each weakness it finds.
HTTP Observatory
Mozilla / MDN
Free scan of a website’s HTTP security headers and related settings, scored with specific remediation guidance.
Have I Been Pwned
Troy Hunt
Free service to check whether your domain’s email addresses have appeared in known data breaches, and to monitor a domain for future exposure.
Want help interpreting the results? We read through them with you on a call and turn them into a plan.
Guides from the team
We're writing practical, engineer-first guides on ISO 27001, SOC 2, DPDPA, GDPR, cloud security and GRC. Until they're published, ask us your specific question directly — we answer with real detail, not a sales pitch.
Ask a compliance questionStart with a short assessment call
A 30-minute call with a security architect to map where you are against the framework you need and agree the next step. No obligation, no sales sequence.
