VITI Security now hosts 26 free compliance calculators covering India’s DPDP Act and CERT-In directions, US frameworks like HIPAA, CCPA, CMMC and SOX, the EU’s GDPR, NIS2, DORA and AI Act, and global standards including PCI DSS, SOC 2 and ISO 27001. Every tool runs free in your browser at the compliance tools hub - no sign-up, no email wall - and returns a number you can act on: a penalty estimate, a reporting deadline, an audit cost band, or a readiness score.
We built these because the first compliance question is almost always "how bad could this get?" and the honest answer used to require a paid consultation. A fintech wondering whether DORA applies, a hospital estimating HIPAA penalty tiers, a D2C brand trying to work out which PCI self-assessment questionnaire it belongs to - these are questions with structured answers, and a calculator gets you to a defensible first estimate in about two minutes.
The tools compute everything client-side, in your browser. Nothing you enter is sent to us or stored. The figures are indicative planning estimates built on statutory base amounts and published benchmarks, not legal advice - use them for triage and board conversations, then bring in counsel or an auditor for the decisions that follow.
India compliance tools (DPDP, CERT-In, SEBI, RBI)
Seven tools for the Indian regulatory stack. Note: the hub lists these only for visitors browsing from India, but every direct link below works from anywhere.
- DPDP Fine Calculator - Penalty exposure under the DPDP Act 2023 Schedule, where slabs run to ₹250 crore per instance for failed security safeguards.
- CERT-In 6-Hour Reporting Clock - How much of the mandatory 6-hour incident reporting window you have left, and what the report must contain.
- DPDP Consent Readiness Checker - Scores your consent flow against notice, withdrawal, language and dark-pattern requirements.
- Significant Data Fiduciary Checker - Estimates your likelihood of being notified as an SDF under DPDP Act s.10 - and the obligations that follow.
- DPDP Data Principal Request Estimator - Costs out the monthly workload of handling access, correction and erasure requests.
- SEBI CSCRF Readiness Scorecard - Ten-control readiness check against SEBI’s Cybersecurity and Cyber Resilience Framework for brokers, AMCs and MIIs.
- RBI Cyber Security Framework Scorecard - Checks your bank, NBFC or payment operation against RBI’s cyber security expectations, including the 2-6 hour incident reporting duty.
US compliance tools (HIPAA, CCPA, CMMC, SOX)
- HIPAA Civil Penalty Calculator - Penalty ranges by culpability tier and records affected, from "unaware" through uncorrected willful neglect.
- CCPA/CPRA Applicability & Exposure Calculator - Whether the CCPA applies to your business and what the per-violation statutory exposure looks like.
- US State Breach Notification Estimator - Notification deadlines and attorney-general duties across the major state breach laws, plus rough notification cost.
- US State Privacy Law Applicability Checker - Which of the state comprehensive privacy laws likely apply, and the obligations that come with them.
- CMMC Readiness Calculator - Your likely CMMC level, control readiness, and a rough assessment cost band for DoD contractors.
- SOX ITGC Cost Estimator - First-year and ongoing IT general controls readiness plus audit cost, by auditor tier and system scope.
- Cyber Insurance Premium Estimator - A rough annual premium band - and the control gaps, like missing MFA, that can get you declined.
EU compliance tools (GDPR, NIS2, DORA, ePrivacy, AI Act)
- GDPR Fine Calculator - The Article 83 statutory cap for your turnover and tier, plus an indicative applied-fine band.
- NIS2 Scope Checker - Whether NIS2 applies to your organisation, your entity class, core obligations and fine exposure.
- DORA Readiness Scorecard - Scores a financial entity against the ten core DORA pillars, in force since 17 January 2025.
- GDPR DSR Cost Calculator - The monthly cost of your data subject request workload against the one-month response clock.
- Cookie Consent Fine Calculator - Consent-banner enforcement exposure based on CNIL practice, with a prioritized fix list.
- EU AI Act Risk Classifier - Classifies your AI use case as prohibited, high-risk, limited or minimal, with the obligations for each.
Global tools (PCI DSS, SOC 2, ISO 27001, breach cost)
- Which Privacy Laws Apply to My Business? - Five questions in, a list of the privacy regimes that likely apply to you out - the flagship wizard.
- Which PCI SAQ Do I Need? - Your likely Self-Assessment Questionnaire, merchant level, and non-compliance fee exposure.
- SOC 2 Cost & Timeline Estimator - Audit fees, tooling spend, internal effort and a realistic Type I or Type II timeline.
- ISO 27001 Cost & Timeline Estimator - Certification-audit fees, internal ISMS effort and the timeline to certificate by company size.
- Data Breach Cost Calculator - Total breach cost - response, notification, legal - built on IBM per-record benchmarks by industry and region.
- Ransomware Incident Cost Calculator - The full cost of a ransomware incident: downtime, recovery effort, forensics, and the ransom question.
How do you use the calculators?
- Open the hub at /free-compliance-tools/ and pick your region or framework.
- Enter rough numbers - ranges are fine, and nothing you type leaves your browser.
- Read the headline figure first, then the line-by-line breakdown beneath it.
- Note the assumptions and notes under each result; they name the statute or benchmark behind every figure.
- Treat the output as triage: fix the biggest gap first, then re-run to see the exposure move.
Where the tools fit alongside our services
Each calculator ends where a real engagement begins. If your DPDP penalty estimate is a number your board will not accept, our DPDP Act compliance work covers the reasonable-security-safeguards half of the law. Healthcare teams can go from the HIPAA penalty calculator to our healthcare IT security practice, and regulated finance teams from the SEBI and RBI scorecards to our BFSI security work. The calculators give you the estimate; the services close the gap.
What these calculators are - and what they are not
They are planning instruments. Every figure is traceable to a statute, a regulatory circular, or a published benchmark (IBM’s Cost of a Data Breach series, Sophos’ State of Ransomware, CNIL enforcement decisions), and the tools say so in their notes. They are not legal advice, not audit opinions, and not quotes. A calculator can tell you the DPDP Schedule caps a security-safeguards failure at ₹250 crore per instance; it cannot tell you how a Data Protection Board proceeding would weigh your specific facts. For that, you need counsel - and for the security controls that change the answer, you need engineers.
Free compliance calculators FAQ
Are the compliance calculators really free?
Which compliance frameworks do the calculators cover?
Why do I see different tools on the hub when I browse from outside India?
Do the calculators store what I enter?
Can I use a calculator result in an audit or as legal advice?
What should I do if a result looks bad?
Want a real number, not an estimate?
Run a free Vexta vulnerability scan against your own infrastructure, or book a scoping call and we will tell you honestly which gaps matter and which frameworks you can ignore for now.

