Cybersecurity › Free assessment

How secure is your company?
Measure it in 15 minutes.

A free self-assessment based on the NIST Cybersecurity Framework 2.0: 106 questions across the six functions of security, no registration, a PDF report with your maturity level and priority gaps. The tool is public and the report is yours. If you then want to read the result with people who do security every day, the way to do it is at the bottom of the page.


Before buying anything, know where you stand.

Most companies have no picture of their own security: they have an antivirus, a firewall, a backup, and the feeling that it is enough. A structured assessment asks everyone the same questions, in the same order, and returns a measurable level for each function. It is the starting point of any serious journey, from NIS2 to ISO/IEC 27001, and the cheapest way not to spend in the wrong place.

106

Guided multiple-choice questions on processes, roles and controls. No technical data to enter: it is answered by whoever knows the company, not whoever knows the servers.

15’

The time it usually takes to complete. You can pause and resume. At the end the PDF report downloads immediately, without waiting for a sales email.

6

The NIST CSF 2.0 functions on which maturity is measured: Govern, Identify, Protect, Detect, Respond, Recover. A score for each, and an overall one.

What it measures

The six functions of the NIST CSF 2.0.

They are the same areas NIS2, ISO/IEC 27001 and any auditor ask about. The report tells you, for each one, where you stand.

Govern

Strategy, roles and responsibilities, policies, risk and supply chain management, management oversight. The function that is new in version 2.0, and the one NIS2 places on the shoulders of management bodies.

Identify

Knowing what you protect: inventory of devices, data, applications, suppliers and people; risk assessment; vulnerability management and continuous improvement.

Protect

The measures that reduce the likelihood of an incident: identity and access management, training, data protection, platform security, infrastructure resilience.

Detect

Noticing in time: continuous monitoring of network, endpoints, identities and suppliers; analysis of anomalous events; the ability to tell whether an event is an incident.

Respond

What happens when it happens: incident management, analysis, containment, internal and external communication, notifications to the authorities within the timeframes required by regulation.

Recover

Getting back to work: recovery plans, verified backups, restart priorities, communication during recovery and lessons learned for the next time.

How it works

Three steps, the third one optional.

The assessment is a public tool: use it whenever you want, as many times as you want, and the report is yours. You only take the third step if you need it.

About 15 minutes

Answer

106 guided multiple-choice questions across the six functions of the framework. No technical data to enter, no account to create.

PDF

Get the report

The overall maturity level and the level per function, strong areas and priority gaps. A document you can share with management as it is.

Alone or with us

Act

Use the report to set priorities. If you wish, we read it together in a no-obligation conversation and turn the gaps into a plan.

Read the report with us

Got the PDF? Let’s talk about it.

Write to us and attach or describe the result. In a no-obligation conversation we read the six functions together, separate the gaps that matter from those that can wait and tell you frankly what we would do and what your team can do on its own. We reply within 24 working hours.

  • Report review function by function, with priorities
  • Guidance on what to verify with technical tools (vulnerability assessment, phishing tests)
  • No obligation to buy: if the picture is good, we tell you

Frequently asked questions about the assessment

The questions we hear before and after the report is downloaded.

Fifteen minutes today, a clear direction tomorrow.

The assessment is the first step of everything we do in cybersecurity: from NIS2 compliance to the path towards ISO 27001 certification.