Scoping
Fill the scoping questionnaire to get started
Accurate scoping is what makes a proposal accurate. Pick your framework below and answer a short set of questions about your environment — it takes a few minutes, and a senior consultant responds within 4 business hours.
Scope only — we never ask for pricing or commercial information here. You can send partial answers now and the rest later.
PCI DSS
Payment Card Industry Data Security Standard
The Payment Card Industry Data Security Standard governs how cardholder data is stored, processed and transmitted. This questionnaire establishes your cardholder data environment, the validation route that applies to you, and the assessment effort involved.
Go to form →SOC
System and Organization Controls
SOC reporting evaluates the internal controls behind the services you deliver to customers — security, availability, processing integrity, confidentiality and privacy. This questionnaire scopes your report type, criteria and observation period.
Go to form →GDPR
General Data Protection Regulation
The GDPR sets strict requirements for handling the personal data of individuals in the EU and UK. This questionnaire establishes your role, your processing activities and where your obligations actually bite.
Go to form →NESA
UAE Information Assurance (NESA / SIA)
The UAE Information Assurance Standard sets cybersecurity requirements for entities operating in the Emirates, particularly in critical sectors. This questionnaire establishes your regulator, your sector and the systems in scope.
Go to form →HIPAA
Health Insurance Portability and Accountability Act
HIPAA protects sensitive patient health information. This questionnaire establishes whether you are a covered entity or a business associate, what ePHI you handle, and where the gaps in your safeguards are likely to sit.
Go to form →ISO 27001
ISO/IEC 27001 Information Security Management
ISO 27001 sets out the requirements for an information security management system. This questionnaire establishes your ISMS boundary, your current control maturity and whether you are heading for certification or readiness.
Go to form →VAPT
Vulnerability Assessment and Penetration Testing
VAPT identifies vulnerabilities across your systems and simulates real attacks against them. Testing is priced on what is actually in scope, so this questionnaire counts the assets and establishes the depth of testing required.
Go to form →Other compliance
Any other framework, standard or certification
For any regulatory framework, compliance standard or certification not listed above — including new, industry-specific or customer-mandated requirements. Tell us what you need and we will scope it against the right standard.
Go to form →Not sure which applies, or working to more than one standard at once? Start with other compliance and describe the requirement, or talk to a consultant first. Most organisations end up scoping two or three frameworks together, and the evidence usually overlaps more than people expect.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
