Quick maturity assessment
Twenty-five questions about the controls that hold a security program together, in the order they usually get built. At the end you see which of the five levels your organization is on, and how many controls are missing for the next one.
Before you start
Twenty-five questions, one per screen, about the controls that hold a security program together. It takes about 5 minutes.
- Based on NIST CSF 2.0, with 25 controls spread across five levels.
- The result is self-declared: nobody verifies the answers on this page.
- We ask for no name, no email and no company details to answer.
Your answers stay in your browser while you answer. We ask for no identification.
How the quick assessment works
- 1
Answer 25 questions, one per screen, about the controls in your organization.
- 2
See which of the five levels you are on and how many controls are missing for the next one.
- 3
Create a free account to see which controls those are and pick up where you left off.
Frequently asked questions
- Do I need to sign up to answer?
- No. Answering and seeing your level takes no sign-up at all. The free account is what shows you which controls are missing, one by one, and lets you carry on with the answers already imported.
- Why a level instead of a percentage?
- Because the levels are cumulative: you only reach level 2 with every level-1 control in place. A percentage would hide the case where what is missing is precisely the basics, such as a tested backup.
- Does this count as an audit or a certification?
- No. The result is self-declared — nobody verifies the answers here. On the platform, each answer is backed by attached evidence and reviewed.
Need more?
From a one-off tool to a full program
Tools solve today's task. The Aranis platform runs the program: vendor assessment, organizational risk, privacy and continuity, with evidence and an audit trail.