Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. Against the frameworks
  2. How these numbers were produced
  3. Across the lifecycle
  4. What was assessed
  5. Coverage by capability
  6. The three numbers

Left out

  • Where the gaps are
  • What is in place today
  • Recommended next improvements

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1Against the frameworks

  • NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
  • OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

2How these numbers were produced

Nothing on this report was measured by a scanner. Every figure is derived from the answers given in the assessment, by the same engines that produce the interactive views — a number here and the same number on the coverage map cannot disagree, because there is only one of each.

Coverage is 198 of 419 weighted scopes, over 250 required scopes. A scope is one combination of environment, technology, lifecycle phase and control point that a requirement demands, and it counts as covered when something in place matches it. 131 scopes are not matched by anything.

Effectiveness is scored only over components this release can assess. 35% of the weight could not be — evidence collection and ownership are not modelled yet — and was excluded rather than guessed, which is why effectiveness is not simply coverage seen from another angle.

Maturity is averaged over everything the profile requires, with uncovered scope counting as level 0.

100% of that weight was assessed with at least one criterion left out, because this release has no model for it. A level therefore means “level N as far as this release can see”.

Framework percentages are over the requirements this control catalog addresses, never over the whole framework. A requirement the catalog does not map, and a requirement asking for a control your profile never required, are both excluded from the percentage rather than counted against you.

The gap table prints at most 15 of the critical and high gaps. The complete list, at every severity and with the scope each sits in, is in the CSV export.

There is no PDF renderer behind this page. It is laid out for your browser’s print dialogue, which is also where “save as PDF” lives — so what you print is the document you are looking at, not a second rendering of it that could differ.

3Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

4What was assessed

Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.

No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.

5Coverage by capability

Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.

CapabilityCoverageMaturityOpen gaps
API Security Testing0%09
Fuzzing0%04
Kubernetes Security0%09
Runtime Security0%012
Security Requirements0%01
DAST7%0.18
Vulnerability Scanning17%0.325
Penetration Testing29%0.37
Admission Control33%0.73
Network Security33%0.712
Drift Detection50%112
IaC Security50%16
Threat Modeling50%0.51
Secrets Management60%1.22
Cloud Configuration Security67%1.32
Code Review Security67%0.71
Secret Scanning67%2.71
SIEM67%1.31
Workload Identity67%1.36
SCA73%1.59
Container Security100%40
Incident Response100%10
SAST100%3.20
Secure Architecture100%10
Vulnerability Management100%20

6The three numbers

Coverage

47%

Effectiveness

61%

Maturity

1.0 / 5 (Available)

198 covered221 not covered

Coverage
198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
Effectiveness
How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
Maturity
Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.