Whether the act applies to you directly or as a supplier to an essential entity — and where your biggest gap is. Risk management, incidents, supply chain, delivery process, continuity.
For banks, fintechs, payment institutions and ICT providers to the financial sector. ICT risk framework, incidents, resilience testing, supplier register, continuity.
Whether the rules on products with digital elements cover your product. Vulnerability reporting, bill of materials, updates, technical documentation.
The upper cap of the fine you are exposed to given your turnover and status. A number worth showing the board before someone else asks.
Our most complete assessment, based on OWASP SAMM. Governance, design, build, verification, deployment, response.
The build pipeline has access to code, secrets and production. Check whether it is the shortest path from an attacker to your clients.
A big client sends a questionnaire of several hundred questions and the contract stalls. Check how much of it you could fill in today — and what it will cost you.
What one questionnaire from an enterprise client really costs you — in team hours and in contract delay.
Compare the cost of fixing the same bug caught at design, in code review, in testing and in production.
The order of magnitude for implementing a secure delivery process — before you ask anyone for a quote.
The results are indicative and do not replace an audit or legal advice. They are based only on your answers — we do not inspect your systems. This is a starting point for a conversation, not a conformity assessment.