Custom · 6 sections
Choose and order sections
In this report
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1Where the gaps are
170 gaps in total, 95 of them critical or high.
| Severity | Control | Where | What is wrong |
|---|---|---|---|
| critical | Authenticated Dynamic Scan | Production · CI Pipeline | nothing covers it |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Vulnerable Dependency Gate | Production · Java · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Java · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · React · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · React · Release Gate | nothing covers it |
| critical | Admission Policy Enforcement | Production · Kubernetes · Admission | nothing covers it |
| critical | IaC Misconfiguration Detection | Production · Helm · Pull Request | it runs elsewhere, but not for this technology |
| critical | IaC Misconfiguration Detection | Production · Helm · CI Pipeline | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Continuous Scan | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Runtime | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Azure · Continuous Scan | it runs elsewhere, but not for this technology |
The remaining 80 critical or high gaps are in the CSV export.
2What was assessed
Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.
No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.
3Coverage by capability
Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.
| Capability | Coverage | Maturity | Open gaps |
|---|---|---|---|
| API Security Testing | 0% | 0 | 9 |
| Fuzzing | 0% | 0 | 4 |
| Kubernetes Security | 0% | 0 | 9 |
| Runtime Security | 0% | 0 | 12 |
| Security Requirements | 0% | 0 | 1 |
| DAST | 7% | 0.1 | 8 |
| Vulnerability Scanning | 17% | 0.3 | 25 |
| Penetration Testing | 29% | 0.3 | 7 |
| Admission Control | 33% | 0.7 | 3 |
| Network Security | 33% | 0.7 | 12 |
| Drift Detection | 50% | 1 | 12 |
| IaC Security | 50% | 1 | 6 |
| Threat Modeling | 50% | 0.5 | 1 |
| Secrets Management | 60% | 1.2 | 2 |
| Cloud Configuration Security | 67% | 1.3 | 2 |
| Code Review Security | 67% | 0.7 | 1 |
| Secret Scanning | 67% | 2.7 | 1 |
| SIEM | 67% | 1.3 | 1 |
| Workload Identity | 67% | 1.3 | 6 |
| SCA | 73% | 1.5 | 9 |
| Container Security | 100% | 4 | 0 |
| Incident Response | 100% | 1 | 0 |
| SAST | 100% | 3.2 | 0 |
| Secure Architecture | 100% | 1 | 0 |
| Vulnerability Management | 100% | 2 | 0 |
4Recommended next improvements
- 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
- 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
- 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes
At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.
5Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
6Against the frameworks
- NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
- OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

