18 externally-testable checks across TLS/SSL, certificate strength, HTTP security headers, and email security (SPF, DMARC, DKIM).
PCI DSS 4.0.1, NIST SP 800-52, ISO 27001, HIPAA, SOC 2, GDPR, Cyber Essentials, DORA, NIS2, and NIST CSF 2.0.
This tool checks externally-testable requirements only. Full compliance requires internal controls, policies, and audits that cannot be verified from outside your organization.
It maps externally-testable SSL/TLS, email authentication and HTTP header findings against PCI DSS, ISO 27001, HIPAA, SOC 2, GDPR, DORA, NIS2, Cyber Essentials and NIST (800-52 and CSF 2.0).
No. This checker only tests what is observable from outside your domain. Real compliance also requires internal controls, policies, staff training and audits that cannot be verified remotely, so treat the result as a technical pre-check.
The score reflects how many externally-testable requirements pass across the selected frameworks. A high score means your public-facing TLS, email and header configuration is in good shape; it is not a formal certification.
Most expect TLS 1.2 or higher (ideally TLS 1.3), strong ciphers with forward secrecy, no deprecated protocols such as SSL 3.0 or TLS 1.0/1.1, a valid trusted certificate, and HSTS for web services.
Yes, running the external compliance check is free and needs no account. Ongoing monitoring and change alerts are available with a free account.
We're new and growing — your feedback helps us improve.