CloudCompliance

Cloud compliance readiness score

Six short steps, one per control area. You get a score for each area, an overall figure, and the specific gaps an auditor would raise first.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Tick what is true of your production cloud today, not what is planned. The score shows on this page. Nothing is sent anywhere unless you ask for the write-up at the end.

Which standard are you preparing for?

Structure: which of these are true?

Tick all that apply. Leave blank if none.

Identity and access: which of these are true?
Logging and monitoring: which of these are true?
Data protection and resilience: which of these are true?
Change and vulnerabilities: which of these are true?

How the score works

Each area is scored on the share of its items ticked. The overall figure weights identity and logging slightly higher, because those produce the most common audit exceptions. The items come from the cloud compliance checklist, which has the evidence behind each one, and the common findings page explains why each gap matters.

What score is good enough to start an audit?

Above 85 percent with no gaps in identity or logging is a reasonable point to open a SOC 2 Type 2 window. Between 60 and 85, plan a few weeks of fixes first. Below 60, run a readiness project before booking the auditor.

Does this cover the whole SOC 2 or ISO 27001?

No. It covers the cloud controls. Policies, HR, vendor management, risk assessment and incident response come from outside the cloud and are not scored here.

Want help closing the gaps?

Firms in the network fix cloud gaps before the window opens.

Get matched