Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. Against the frameworks
  2. What is in place today
  3. Across the lifecycle
  4. How these numbers were produced
  5. What was assessed
  6. Where the gaps are
  7. Recommended next improvements

Left out

  • The three numbers
  • Coverage by capability

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1Against the frameworks

  • NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
  • OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

2What is in place today

Every control this assessment recorded as being in place — the Ist side of the coverage number, named rather than counted.

What is in placeToolHow it runsEnforcementWeight carriedEffectivenessMaturity
Trivy dependency scan on pull requests and in CITrivyautomateda warning3675%2
Trivy gate on the container buildTrivyautomateda warning2775%2
Argo CD reconciliation against GitArgo CDcontinuousa warning2450%2
Checkov Terraform scan on pull requests and in CICheckovautomateda warning1259%2
Entra Workload Identity on AKSno toolautomatednot enforced1225%2
Trivy image scan in CI and registryTrivyautomatedblocking1294%4
Defender for Cloud vulnerability assessment in productionMicrosoft Defender for Cloudcontinuousa warning1073%2
Renovate dependency update pull requestsRenovateautomatednot enforced925%2
Semgrep rules on pull requestsSemgrepautomateda warning967%2
SonarQube pull request gateSonarQubeautomatedblocking994%4
Annual third-party penetration testno toolmanualnot enforced60%1
Default-deny NetworkPolicies in the clusterno toolautomatedblocking663%2
DefectDojo as the finding destinationDefectDojoautomatedinformational650%2
SonarQube analysis of the main branchSonarQubeautomateda warning675%2
Azure Key Vault for application secretsno toolautomatednot enforced325%2
Azure Policy deny assignments on resource deploymentsno toolautomatedblocking363%2
DefectDojo SLA policy per severityDefectDojoautomatedinformational357%2
Kyverno policies in audit modeKyvernocontinuousinformational340%2
Azure Monitor log pipelineno toolcontinuousinformational240%2
Gitleaks over the repository and its historyGitleaksautomatedblocking294%4
Architecture board sign-off on major changesno toolmanualapproval-required129%1
Branch protection requiring a second reviewerGitHub Advanced Securitysemi-automatedapproval-required141%1
CODEOWNERS review on the payment pathsGitHub Advanced Securitysemi-automatedapproval-required141%1
Defender for Cloud posture on the production subscriptionMicrosoft Defender for Cloudcontinuousa warning173%2
Incident response runbook, rehearsed twice a yearno toolmanualnot enforced10%1
OWASP ZAP baseline scan against TESTOWASP ZAPsemi-automatedinformational145%1
STRIDE workshop held at design timeno toolmanualnot enforced10%1

Weight, not a count: a scope carries the weight of the requirement level behind it, and the coverage percentage is over those same weights. A control carrying zero weight is in place but covers nothing this profile requires.

3Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

4How these numbers were produced

Nothing on this report was measured by a scanner. Every figure is derived from the answers given in the assessment, by the same engines that produce the interactive views — a number here and the same number on the coverage map cannot disagree, because there is only one of each.

Coverage is 198 of 419 weighted scopes, over 250 required scopes. A scope is one combination of environment, technology, lifecycle phase and control point that a requirement demands, and it counts as covered when something in place matches it. 131 scopes are not matched by anything.

Effectiveness is scored only over components this release can assess. 35% of the weight could not be — evidence collection and ownership are not modelled yet — and was excluded rather than guessed, which is why effectiveness is not simply coverage seen from another angle.

Maturity is averaged over everything the profile requires, with uncovered scope counting as level 0.

100% of that weight was assessed with at least one criterion left out, because this release has no model for it. A level therefore means “level N as far as this release can see”.

Framework percentages are over the requirements this control catalog addresses, never over the whole framework. A requirement the catalog does not map, and a requirement asking for a control your profile never required, are both excluded from the percentage rather than counted against you.

The gap table prints at most 15 of the critical and high gaps. The complete list, at every severity and with the scope each sits in, is in the CSV export.

There is no PDF renderer behind this page. It is laid out for your browser’s print dialogue, which is also where “save as PDF” lives — so what you print is the document you are looking at, not a second rendering of it that could differ.

5What was assessed

Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.

No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.

6Where the gaps are

170 gaps in total, 95 of them critical or high.

SeverityControlWhereWhat is wrong
criticalAuthenticated Dynamic ScanProduction · CI Pipelinenothing covers it
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalVulnerable Dependency GateProduction · Java · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Java · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · Spring Boot · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Spring Boot · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · React · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · React · Release Gatenothing covers it
criticalAdmission Policy EnforcementProduction · Kubernetes · Admissionnothing covers it
criticalIaC Misconfiguration DetectionProduction · Helm · Pull Requestit runs elsewhere, but not for this technology
criticalIaC Misconfiguration DetectionProduction · Helm · CI Pipelineit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Continuous Scanit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Runtimeit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Azure · Continuous Scanit runs elsewhere, but not for this technology

The remaining 80 critical or high gaps are in the CSV export.

7Recommended next improvements

  1. 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
  2. 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
  3. 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  4. 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  5. 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes

At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.