Tools
Where are our gaps?
Answer questions about how your organisation actually works, and see which parts of a framework you would struggle to evidence. Every question explains itself as it is asked. No account, and nothing leaves your browser unless you ask for the report.
Which framework?
ISO/IEC 27001 2022
You are working towards certification, a customer has asked whether you are certified, or you already hold it and want to find drift before the next audit.
It is a conformity standard: every applicable requirement is meant to be met, and the result is counted on that basis.
118 requirementsAbout 70 minutesNo account needed
NIST Cybersecurity Framework 2.0
You want a broad picture of how your organisation manages cyber risk, with no certification in view. It is free to read, it covers governance and recovery as thoroughly as it covers defences, and it suits an organisation deciding where to start.
It is not a certification and there is nothing to pass. This measures you against every Core outcome, which is not the same as the target a considered organisation would actually set for itself.
106 requirementsAbout 65 minutesNo account needed
The two are not comparable with each other. They ask different questions against different frameworks, and the number each produces is counted from a different denominator. Running both tells you about both; it does not tell you which framework you are doing better at.
Neither is an audit. Both reflect what you tell us about yourself, without evidence and without anybody testing whether something you call done actually works. The framework library covers the same ground in writing, with no questions at all.