Custom · 3 sections
Choose and order sections
Left out
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
2Against the frameworks
- NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
- OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
3Coverage by capability
Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.
| Capability | Coverage | Maturity | Open gaps |
|---|---|---|---|
| API Security Testing | 0% | 0 | 9 |
| Fuzzing | 0% | 0 | 4 |
| Kubernetes Security | 0% | 0 | 9 |
| Runtime Security | 0% | 0 | 12 |
| Security Requirements | 0% | 0 | 1 |
| DAST | 7% | 0.1 | 8 |
| Vulnerability Scanning | 17% | 0.3 | 25 |
| Penetration Testing | 29% | 0.3 | 7 |
| Admission Control | 33% | 0.7 | 3 |
| Network Security | 33% | 0.7 | 12 |
| Drift Detection | 50% | 1 | 12 |
| IaC Security | 50% | 1 | 6 |
| Threat Modeling | 50% | 0.5 | 1 |
| Secrets Management | 60% | 1.2 | 2 |
| Cloud Configuration Security | 67% | 1.3 | 2 |
| Code Review Security | 67% | 0.7 | 1 |
| Secret Scanning | 67% | 2.7 | 1 |
| SIEM | 67% | 1.3 | 1 |
| Workload Identity | 67% | 1.3 | 6 |
| SCA | 73% | 1.5 | 9 |
| Container Security | 100% | 4 | 0 |
| Incident Response | 100% | 1 | 0 |
| SAST | 100% | 3.2 | 0 |
| Secure Architecture | 100% | 1 | 0 |
| Vulnerability Management | 100% | 2 | 0 |

