SOC Pro
🔔
JD
US-105US-033US-034US-035US-036US-115
L5 — Compliance Register
Multi-framework gap analysis · GDPR · PCI-DSS · ISO 27001 · SOC2 · Cyber Essentials+
78%
GDPR
61%
PCI-DSS
55%
ISO 27001
40%
Cyber Essentials+
GDPR
PCI-DSS
ISO 27001
SOC2
Cyber Essentials+
Policy Gap Analysis US-105, FR-024A
Drop policy document · Claude maps to ISO 27001 clauses
GDPR Control Status US-033, US-034
ArticleControlStatusFinding RefEvidence
Art. 5(1)(f)Integrity & ConfidentialityFailL2-SQLi-001
Art. 25Data Protection by DesignPartialL4-API-003
Art. 32Security of ProcessingFailL3-MOB-002
Art. 33Breach Notification (72hr)Pass✓ Documented
Art. 35Data Protection Impact AssessmentPartial
Art. 37Data Protection OfficerPass✓ Documented
Financial Fine Exposure US-036
GDPR MAXIMUM FINE EXPOSURE
€20,000,000
or 4% of global annual turnover — whichever is higher
Based on 3 failing Art. 32 controls · ICO enforcement average: £284,000 for SMBs in 2023
FrameworkFine ExposureProbability
GDPR (ICO)Up to €20M or 4% turnoverMedium
PCI-DSS card schemes$5,000–$100,000/monthLow-Med
NIS2 (if applicable)€10M or 2% turnoverLow
Remediation Tracker US-034
Art. 33 — Breach notification procedure
Completed by J.Smith · 12 Jun 2026
Art. 32 — Fix SQL injection (L2-SQLi-001)
In progress · assigned to dev team
3
Art. 25 — API data minimisation review
Not started · due 30 Jun 2026
Overall GDPR compliance progress
78% · 14/18 controls passing
Cyber Essentials+ Self-Assessment US-035
Report pre-filled from scan findings. Review each control and submit to NCSC certification body.
CE+ ControlRequirementAssessmentEvidence from ScansResult
FirewallsAll internet-connected devices protected by firewallAuto-assessedL1: 2 open high-risk ports (3389, 445)FAIL
Secure ConfigurationDefault passwords changed; unnecessary software removedAuto-assessedL2: Directory listing enabledFAIL
Access ControlUser accounts have appropriate privileges; MFA enabledManual review neededL4: No rate limit on /loginPARTIAL
Malware ProtectionMalware protection on all devicesAuto-assessedL8: ClamAV active on 12/12 agentsPASS
Patch ManagementAll software patched within 14 days of releaseAuto-assessedL2: jQuery 1.8.3 outdated; WP 6.3.1 outdatedFAIL