Free tool
How Mature Is Your Security Program? A 26-Point Self-Check
These are the 26 capabilities a mature security and compliance program has - the same maturity lists we publish on our GRC and Cyber Risk Management pages, in one place. Check what your business actually has in place today. It takes about five minutes.
Your score updates as you go. It's free, and no email is required to see your results.
One rule for honest math: only check an item if you could show evidence of it this week. A policy nobody can find, or a backup nobody has restored, doesn't count yet. If you'd have to guess, leave it unchecked - the unchecked items are the useful ones.
You checked 0 of 26.
Govern 0/4 · Manage Risk 0/8 · Comply 0/4 · Operate & Defend 0/10
FAQ
Common questions
Do I need to enter my email to see my score?
No. Your score and result appear on this page as you check items. Email is only for sending yourself a copy, and that option appears after your results - never before.
How were these 26 items chosen?
They're the same maturity lists we publish on our GRC and Cyber Risk Management service pages: 16 governance, risk, and compliance capabilities and 10 operational security capabilities. No vendor product lists, no padding - it's the standard we hold customer programs to.
What counts as "having" an item?
Evidence, not intention. If you could produce the policy, the restore log, or the access review this week, check it. If it exists in someone's head or on a to-do list, it isn't a control yet - leave it unchecked.
What happens after I see my score?
Nothing automatic. Every unchecked item links to the page that explains how it gets addressed, and if you want the score verified against your real environment, that's what the Cyber Risk & Compliance Gap Assessment does.
