A worked example. Nothing here belongs to you — start your own assessment to see yours.
Coverage
47%198 of 419 weighted scopes
Effectiveness
61%
Maturity
1.0 / 5
198 weight covered221 weight not covered
Do we have the necessary security controls everywhere we need them?
Are those controls actually effective, or do scanners just run alongside?
Has this become a governable, measurable, continuously improved process?
Where a capability looks covered because only part of the stack is actually scanned.
Your stack, and what is actually demanded of each part of it. A percentage here is only meaningful next to the ones beside it: a capability reads as in place when one technology is scanned and the rest are not.
45 required scopes are asked once for the whole application rather than per technology — a threat model and a secret-scanning gate are not a property of Java or of Terraform, so demanding them per technology would be demanding them several times over.
Secrets ManagementNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Secret ScanningNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Secure ArchitectureNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Security RequirementsNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
SIEMNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Threat ModelingNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Vulnerability ManagementNot scoped by technology. One implementation satisfies it for the whole application, so it is asked once rather than once per technology.
Vulnerability ScanningDefined for Language, Framework, Runtime, Container, Datastore. Kubernetes is not in those — it is demanded of Java, Spring Boot, React, PostgreSQL, Docker instead, and its absence here is not a gap.