About EvaluationCat
EvaluationCat is a self-serve security assessment platform for SaaS and technology companies. We turn the questionnaires and frameworks your customers, auditors, and investors care about into structured online assessments — so you can walk into any security review prepared, without hiring a consulting firm or buying an enterprise GRC platform.
What EvaluationCat Does
Every assessment on EvaluationCat follows the same three-step path:
1. Assess
Work through the full control set online — five-level maturity rating per control, save and resume anytime.
2. Find Gaps
Get an instant security score with domain breakdown, plus every missing or partial control ranked by severity.
3. Fix
Close each gap with AI-generated remediation: concrete steps, recommended tools, cost and effort, on a 30/90/180-day roadmap.
The result is a shareable report you can hand to management, a customer, or an auditor — see the sample report for a concrete example.
Standards & Frameworks We Cover
Assessments on EvaluationCat are mapped question-by-question to published, recognized frameworks — nothing is invented in-house. Each control question traces back to a specific control in the standard, so your answers and evidence stay reusable.
ISO/IEC 27001:2022
Information Security Management Systems
- 93 Annex A controls across four domains: organizational, people, physical, and technological
- The international standard for managing information security — the baseline most enterprise buyers recognize
- Self-assessment establishes your readiness baseline; certification itself requires an accredited external audit
CSA CCM v4 / CAIQ 4.1
Cloud Controls Matrix & Consensus Assessments Initiative Questionnaire
- 207 controls across 17 security domains, from IAM to supply chain transparency
- Published by the Cloud Security Alliance as part of the STAR program
- The standardized question set enterprise buyers send during cloud vendor due diligence
CSA AI-CAIQ v2.0
AI-specific extension of the CAIQ
- 242 control questions across 18 domains, including a dedicated Model Security domain
- Covers model governance, training data provenance, prompt-level abuse resistance, and production monitoring
- Designed for AI-native SaaS products and teams adding AI features to existing products
Not sure which one fits your question? The frameworks overview compares all three side by side.
How Scoring Works
Every control is rated on a five-level maturity scale (from fully implemented to not started, with not-applicable excluded). Scores are weighted by control importance and aggregated into a domain breakdown and an overall security score, plus a framework-specific readiness percentage. Gap severity and the 30/90/180-day remediation roadmap are derived from the same data. The full calculation is documented in our scoring methodology.
Who It's For
- SaaS companies facing enterprise security reviews: Answer procurement questionnaires with evidence instead of scrambling before every deal — see the guide for SaaS security reviews.
- Startups and small teams without a security function: Find the gaps that would block your next enterprise deal and fix them in a realistic order.
- Teams building AI products: Get ahead of AI-specific questions from buyers with a structured AI-CAIQ assessment.
Our Principles
- Self-assessment, not certification: EvaluationCat helps you assess readiness and find gaps. It does not issue certificates — certification against ISO 27001 requires an accredited external audit.
- Mapped to real standards: every question traces to a published control; no invented checklists.
- Plain language: remediation plans are written to be acted on by engineers and founders, not deciphered like audit jargon.
- Free to start: the full assessment, scoring, gap summary, and basic report are free. You only pay for the AI remediation plan and roadmap.
Contact Us
If you have any questions, feature requests, or partnership ideas, please reach out via support@evaluationcat.com and we will get back to you as soon as possible.
