Custom · 6 sections
Choose and order sections
In this report
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1Recommended next improvements
- 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
- 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
- 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes
At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.
2What was assessed
Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.
No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.
3Against the frameworks
- NIST SSDF 1.1 — 57%2 satisfied, 6 partial, 2 not satisfied. A further 7 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
- OWASP SAMM 2.0 — 51%2 satisfied, 6 partial, 2 not satisfied. A further 3 ask for controls your profile did not require — the framework is stricter than your baseline there — and 2 are not addressed by this control catalog at all. Both are excluded from the percentage rather than counted against you.
4The three numbers
Coverage
47%
Effectiveness
61%
Maturity
1.0 / 5 (Available)
198 covered221 not covered
- Coverage
- 198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
- Effectiveness
- How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
- Maturity
- Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.
5Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
6Where the gaps are
170 gaps in total, 95 of them critical or high.
| Severity | Control | Where | What is wrong |
|---|---|---|---|
| critical | Authenticated Dynamic Scan | Production · CI Pipeline | nothing covers it |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Vulnerable Dependency Gate | Production · Java · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Java · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · React · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · React · Release Gate | nothing covers it |
| critical | Admission Policy Enforcement | Production · Kubernetes · Admission | nothing covers it |
| critical | IaC Misconfiguration Detection | Production · Helm · Pull Request | it runs elsewhere, but not for this technology |
| critical | IaC Misconfiguration Detection | Production · Helm · CI Pipeline | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Continuous Scan | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Runtime | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Azure · Continuous Scan | it runs elsewhere, but not for this technology |
The remaining 80 critical or high gaps are in the CSV export.

