Free tools
Six tools for the questions buyers and primes put to you: what ISO 27001 costs, where your management system sits, and what the defence supply chain expects. No account required to see your result.
ISO 27001 Cost Calculator
LiveFour questions on people in scope, starting position, internal capacity and evidence standard. Returns a price band for the readiness, Guided and Sprint routes, with published UK prices.
Gives an instant Goldline price band and a separate estimate of the certification body audit fee, based on the ISO/IEC 27006-1:2024 Annex C audit day table.
4 questions · 1 minute
ISO 27001 Readiness Check
LiveA 12-question diagnostic against the mandatory clauses and key Annex A controls. Calibrated for senior practitioners. Output is a 5-domain maturity profile across Foundation, Documentation, Implementation, Operational Effectiveness, and Continual Improvement.
Branded PDF profile with narrative analysis and prioritised remediation areas.
12 questions · 5 minutes
ISO 27001 to 42001 Bridge
LiveSenior-practitioner diagnostic for organisations holding ISO 27001 and considering ISO 42001 certification. Surfaces bridge feasibility, expected duration, and key risks specific to your AI system landscape.
Output is a structured diagnostic of bridge feasibility, expected duration range, and key risks specific to your AI system landscape, with indicative engagement scope.
6 questions · 5 minutes
AI Governance Readiness Check
LiveA 12-question diagnostic across six dimensions, on-screen 6-dimension maturity breakdown, calibrated by senior practitioner ISO 42001 implementation and AI governance practice.
Produces a maturity score across governance, risk, human oversight, transparency, data quality, and continual improvement. Highlights the dimensions most exposed to EU AI Act high-risk enforcement.
12 questions · 5 minutes
Defence Cyber Readiness Check
LiveSenior-practitioner diagnostic for UK Tier 2 and Tier 3 defence suppliers. Maps your posture to DEFSTAN 05-138 Cyber Risk Profiles (Very Low through Very High), with six-domain RAG scoring across Cyber Essentials Plus, ISO 27001, JOSCAR, incident response, supplier risk, and personnel security.
Output is a DEFSTAN 05-138 profile assignment, a six-domain RAG scorecard, and a prioritised remediation pack aligned to DEFCON 658, JOSCAR Stage 2, and prime supplier flow-down requirements.
12 questions · 5 minutes
Microsoft Sensitive Use Classifier
LiveSix questions on what your AI system does, who it affects and whose data it processes. Nothing is stored and no email is asked for.
Reads your answers against the Microsoft Supplier Data Protection Requirements and shows where your system sits, and what Microsoft expects if it falls inside the definition. An interpretation aid, not a determination.
6 questions
Get notified when tools launch
One email per tool launch. No marketing lists. No newsletter. Unsubscribe any time by replying to the launch email.
Need delivery support beyond diagnostics?
Goldline implements ISO 27001, ISO 42001, SOC 2, and Cyber Essentials Plus end-to-end. Senior practitioner-led, fixed-scope, calibrated to your buyer.
