Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. Against the frameworks
  2. The three numbers
  3. Across the lifecycle
  4. Coverage by capability

Left out

  • What was assessed
  • Where the gaps are
  • What is in place today
  • Recommended next improvements
  • How these numbers were produced

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1Against the frameworks

  • NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
  • OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

2The three numbers

Coverage

47%

Effectiveness

61%

Maturity

1.0 / 5 (Available)

198 covered221 not covered

Coverage
198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
Effectiveness
How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
Maturity
Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.

3Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

4Coverage by capability

Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.

CapabilityCoverageMaturityOpen gaps
API Security Testing0%09
Fuzzing0%04
Kubernetes Security0%09
Runtime Security0%012
Security Requirements0%01
DAST7%0.18
Vulnerability Scanning17%0.325
Penetration Testing29%0.37
Admission Control33%0.73
Network Security33%0.712
Drift Detection50%112
IaC Security50%16
Threat Modeling50%0.51
Secrets Management60%1.22
Cloud Configuration Security67%1.32
Code Review Security67%0.71
Secret Scanning67%2.71
SIEM67%1.31
Workload Identity67%1.36
SCA73%1.59
Container Security100%40
Incident Response100%10
SAST100%3.20
Secure Architecture100%10
Vulnerability Management100%20