Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. Across the lifecycle
  2. The three numbers
  3. Recommended next improvements
  4. Where the gaps are

Left out

  • What was assessed
  • Coverage by capability
  • Against the frameworks
  • What is in place today
  • How these numbers were produced

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

2The three numbers

Coverage

47%

Effectiveness

61%

Maturity

1.0 / 5 (Available)

198 covered221 not covered

Coverage
198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
Effectiveness
How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
Maturity
Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.

3Recommended next improvements

  1. 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
  2. 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
  3. 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  4. 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  5. 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes

At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.

4Where the gaps are

170 gaps in total, 95 of them critical or high.

SeverityControlWhereWhat is wrong
criticalAuthenticated Dynamic ScanProduction · CI Pipelinenothing covers it
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalVulnerable Dependency GateProduction · Java · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Java · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · Spring Boot · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Spring Boot · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · React · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · React · Release Gatenothing covers it
criticalAdmission Policy EnforcementProduction · Kubernetes · Admissionnothing covers it
criticalIaC Misconfiguration DetectionProduction · Helm · Pull Requestit runs elsewhere, but not for this technology
criticalIaC Misconfiguration DetectionProduction · Helm · CI Pipelineit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Continuous Scanit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Runtimeit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Azure · Continuous Scanit runs elsewhere, but not for this technology

The remaining 80 critical or high gaps are in the CSV export.