01
Describe your company and what data it handles
Tell the tool what your product does, where it runs (for example AWS or GCP), who your customers are, and what customer data you store or process. The more concrete the description, the more specific the gap analysis.
02
Pick your scope and report type
Security is always included as the Common Criteria. Add Availability, Confidentiality, Processing Integrity, or Privacy only if your customers actually need them. Choose Type I (control design at a point in time) or Type II (operating effectiveness over a period).
03
Review your readiness report
You get a readiness score, a prioritized control-gap table mapped to real AICPA criteria, an evidence checklist with owners, and starter policy templates you can copy or download. Use it to plan remediation before you engage an audit firm.