Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. What was assessed
  2. Against the frameworks
  3. Across the lifecycle
  4. Recommended next improvements

Left out

  • The three numbers
  • Coverage by capability
  • Where the gaps are
  • What is in place today
  • How these numbers were produced

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1What was assessed

Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.

No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.

2Against the frameworks

  • NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
  • OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.

3Across the lifecycle

The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.

PhaseCoverageOpen gaps
Plan0%1
Design67%1
Code78%10
Build89%6
Test14%15
Release0%12
Deploy29%21
Operate38%58
Monitor / Respond32%7

4Recommended next improvements

  1. 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
  2. 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
  3. 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  4. 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
  5. 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes

At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.