Know Where Your Security Stands.Know What to Fix Next.
Free security self-assessments for SaaS and technology companies, mapped to ISO 27001 and CAIQ. Find control gaps and get an actionable remediation plan — not just a score.
Security Score
74/100
ISO 27001 Readiness
68%
CAIQ Coverage
72%
Critical Risks
4
Quick Wins
8
Choose Your Assessment
Select the framework that matches your security goals. Each assessment produces a security score, gap analysis, and remediation roadmap.
ISO 27001
Security Management Assessment
Assess your organization's information security management system against ISO/IEC 27001:2022 Annex A — 93 controls across organizational, people, physical, and technological domains.
CAIQ
Cloud Security Assessment
Evaluate your SaaS or cloud service security controls against the CSA Consensus Assessments Initiative Questionnaire — 17 domains covering IAM, data security, incident management, and more.
AI-CAIQ
AI Security Assessment
Assess AI system governance, model security, data privacy, and operational resilience against CSA's AI-CAIQ v2.0 — 242 control questions across 18 domains, including a dedicated Model Security domain.
Sound familiar?
A customer just asked for your security assessment. Now what?
You're closing a deal, and procurement sends over a questionnaire. Or an investor asks a plain question you can't quite answer: “what's your security posture?”
You don't have a security team. You don't have a $20,000/year compliance platform. What you need is a straight answer, fast — and a plan you can actually act on this week.
EvaluationCat gives you both: a real assessment against ISO 27001 and CAIQ, and a remediation plan written in plain language, not audit jargon.
Do you have ISO 27001, or something equivalent?
Please complete our vendor security questionnaire.
Can you share your current security posture?
We need this before we can move forward with the contract.
How It Works
Complete enterprise InfoSec assessment in 3 steps, get professional reports quickly
Complete Online Questionnaire
Fill in company info and complete the CAIQ security assessment questionnaire. Supports 5-scale selection and evidence file upload.
Get Free Report
The system automatically calculates scores and generates a free report, including overall score, domain scores, and issue list.
Upgrade Remediation Plan
Upgrade to Pro for AI-generated itemized remediation plans, tool selection advice, and implementation roadmaps.
Not Just a Score — Actionable Remediation
Every control gap is translated into a structured, executable task — not a paragraph of generic advice.
Missing MFA for privileged accounts
Why it matters
Privileged accounts have broad access. Without MFA, a single compromised password grants full system control.
How to fix
Enforce MFA on all admin, root, and service accounts. Use TOTP or hardware keys for highest-privilege roles.
Recommended tools
Okta, Auth0, or cloud-native IAM (AWS IAM, Entra ID)
Effort
4–8 hours
Cost
$0–$50/mo
Each assessment produces dozens of structured remediation items like this — ranked, costed, and ready to assign.
Why EvaluationCat
Built for SaaS and technology companies that need to know their security gaps and how to fix them — without hiring a consulting firm.
Dual-Framework Assessment
Assess against ISO 27001:2022 (93 controls) and CSA CAIQ (17 domains). Two complementary frameworks covering both organizational ISMS and cloud service security.
Instant Scoring & Reports
Weighted scoring across domains with ISO 27001 readiness percentage and CAIQ coverage. Free PDF export for bidding, partnerships, and internal review.
Structured AI Remediation
Not AI chat — structured output: issue, risk, why it matters, how to fix, recommended tools, cost, effort, and priority ranking for every gap.
Evidence-Driven
Upload policies, screenshots, and logs as evidence per control. Generate auditable proof lists for compliance preparation and vendor due diligence.
Secure by Design
TLS-encrypted transfers, AES-256 storage, and configurable data retention. Your assessment data is isolated and never shared.
Track Improvement
Compare multiple assessment results over time to visualize security improvement trends and support continuous PDCA improvement.
Plans & Pricing
Start free. Upgrade when you need AI remediation and a full roadmap.
Free
Assess your security posture
- ISO 27001 assessment (93 controls)
- AI-CAIQ v2.0 assessment (242 questions)
- Security score & domain breakdown
- Gap summary with severity levels
- Basic PDF report
- Email report delivery
Pro
Detailed remediation & roadmap
- All Free features
- AI-driven structured remediation
- 30/90/180-day implementation roadmap
- Tool recommendations & cost estimates
- Priority-ranked action items
- Detailed PDF report
Enterprise
Continuous assessment & team
- All Pro features
- Multiple frameworks (ISO 27001, CAIQ & AI-CAIQ)
- Continuous assessments & historical scores
- Team collaboration & evidence vault
- Vendor assessment module
- API access
- Dedicated support
Frequently Asked Questions
Everything you need to know about EvaluationCat security assessments
Understand Before You Assess
Short, jargon-free guides on security questionnaires, frameworks, and how scoring works
What Is a Security Questionnaire?
Plain-English guide to what buyers ask and why.
Questionnaire vs. Assessment
The difference, and which one your deal actually needs.
How to Structure a Self-Assessment
Build an internal questionnaire that maps to real controls.
Frameworks Explained
ISO 27001, CSA CAIQ, and AI-CAIQ — what each covers.
Scoring Methodology
How the security score and readiness are calculated.
Security Assessment Tool
All assessment paths in one place.
Start Your Enterprise InfoSec Assessment Now
Complete the free assessment, get a professional report, understand your security status, and lay the foundation for compliance and security.
