Regulatory compliance
25 questions · 6 categories · ~12 min

UKSC / NIS2 readiness

Whether the act applies to you directly or as a supplier to an essential entity — and where your biggest gap is. Risk management, incidents, supply chain, delivery process, continuity.

25 questions · 6 categories · ~12 min

DORA readiness

For banks, fintechs, payment institutions and ICT providers to the financial sector. ICT risk framework, incidents, resilience testing, supplier register, continuity.

25 questions · 5 categories · ~12 min

CRA readiness

Whether the rules on products with digital elements cover your product. Vulnerability reporting, bill of materials, updates, technical documentation.

3 pola · ok. 2 min

Maximum regulatory fine

The upper cap of the fine you are exposed to given your turnover and status. A number worth showing the board before someone else asks.

Process maturity
30 questions · 6 categories · ~15 min

Delivery process maturity

Our most complete assessment, based on OWASP SAMM. Governance, design, build, verification, deployment, response.

25 questions · 6 categories · ~12 min

Build pipeline security

The build pipeline has access to code, secrets and production. Check whether it is the shortest path from an attacker to your clients.

25 questions · 6 categories · ~12 min

Client questionnaire readiness

A big client sends a questionnaire of several hundred questions and the contract stalls. Check how much of it you could fill in today — and what it will cost you.

Kalkulatory
5 fields · ~2 min

Security questionnaire cost

What one questionnaire from an enterprise client really costs you — in team hours and in contract delay.

4 pola · ok. 2 min

Cost of fixing a vulnerability

Compare the cost of fixing the same bug caught at design, in code review, in testing and in production.

5 fields · ~2 min

Rough implementation estimate

The order of magnitude for implementing a secure delivery process — before you ask anyone for a quote.

The results are indicative and do not replace an audit or legal advice. They are based only on your answers — we do not inspect your systems. This is a starting point for a conversation, not a conformity assessment.

Want to reduce risk
and IT costs?

We reply within 24h on business days