Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. Against the frameworks
  2. Where the gaps are
  3. What was assessed
  4. Across the lifecycle
  5. The three numbers

Left out

  • Coverage by capability
  • What is in place today
  • Recommended next improvements
  • How these numbers were produced

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1Against the frameworks

  • NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
  • OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

2Where the gaps are

170 gaps in total, 95 of them critical or high.

SeverityControlWhereWhat is wrong
criticalAuthenticated Dynamic ScanProduction · CI Pipelinenothing covers it
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalVulnerable Dependency GateProduction · Java · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Java · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · Spring Boot · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Spring Boot · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · React · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · React · Release Gatenothing covers it
criticalAdmission Policy EnforcementProduction · Kubernetes · Admissionnothing covers it
criticalIaC Misconfiguration DetectionProduction · Helm · Pull Requestit runs elsewhere, but not for this technology
criticalIaC Misconfiguration DetectionProduction · Helm · CI Pipelineit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Continuous Scanit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Runtimeit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Azure · Continuous Scanit runs elsewhere, but not for this technology

The remaining 80 critical or high gaps are in the CSV export.

3What was assessed

Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.

No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.

4Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

5The three numbers

Coverage

47%

Effectiveness

61%

Maturity

1.0 / 5 (Available)

198 covered221 not covered

Coverage
198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
Effectiveness
How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
Maturity
Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.