Please read and accept the terms of use to continue.
What this is
This is a free self-assessment tool. It gauges the maturity of your vulnerability management programme — how you find, prioritise, and fix security weaknesses — and offers recommended practices drawn from widely recognised standards and guidance. It is general guidance.
What this isn't
It is not a professional security audit, not a penetration test, and not legal advice. Every recommendation is optional, and following it reduces common risks but does not guarantee security or any particular outcome.
Your responsibility
Responsibility for your organisation's security remains with you.
Verify any recommendation against your own circumstances.
Find out where your vulnerability management programme sits on the four-tier maturity spectrum — and which gaps to close first. Free edition: all 28 checks, scored in your browser.
How This Works
Answer 28 questions across eight areas — from asset inventory through scanning, prioritisation, remediation, and reporting. Each takes 10–20 seconds. At the end you'll get a weighted maturity score, a tier band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised vulnerability management practice; which recommendations fit your organisation is your call.
Part 1 — Asset Inventory (The Foundation)
You cannot assess what you don't know you have. A maintained spreadsheet counts; an out-of-date one doesn't.
Findings get fixed when one accountable person owns the asset. "The IT team" is not a name.
Criticality classification is what lets a medium flaw on a vital system outrank a critical flaw on a test box.
A periodic cross-check against what the network actually shows keeps the list honest and surfaces shadow assets.
Part 2 — Scanning Coverage & Cadence
A reliable cadence beats a one-off scan. Monthly is a common operating rhythm; quarterly is a reasonable floor.
Unauthenticated scans see only the outside of each system — typically a small fraction of the real vulnerability picture.
Unscanned assets are unassessed risk. Coverage is the first number a programme should be able to state.
Externally reachable systems are the first thing attackers try; they warrant a faster look.
Part 3 — Prioritisation & Triage
The KEV catalogue lists flaws confirmed as exploited in the wild. A KEV match is the strongest single "fix this now" signal available.
EPSS estimates how likely a flaw is to be exploited soon. It cuts false urgency from high-severity findings nobody is attacking.
Severity is not risk. The same flaw matters differently on an internet-facing payment server and an isolated lab machine.
Triage is what turns a scan report into a work queue. Written rules survive personnel changes; habits don't.
Part 4 — Remediation & SLAs
Even a simple framework (Critical: 30 days, High: 60, Medium: 90) creates accountability. Without one, findings age silently.
A ticket system or a disciplined spreadsheet both work. What matters is an owner, a due date, and a visible status.
"We patched it" and "the scanner no longer detects it" are different statements. Verification catches the fixes that didn't take.
SLAs become real when a breach is visible to someone senior through a defined route — not when it's discovered by accident.
Part 5 — Patch Operations
A predictable rhythm keeps the backlog flat and makes emergency work the exception rather than the norm.
When an actively exploited flaw lands, a pre-agreed fast lane beats improvising the approval chain at midnight.
Testing and rollback planning are what let you patch quickly without breaking the business — the two goals are not in conflict.
Part 6 — Cloud & Container Workloads
Cloud security posture management (CSPM) finds misconfigurations — exposed storage, weak account settings — that network scanners never see. Skip if you run no cloud: answer "Yes" to keep scoring fair.
Container fixes flow through the pipeline, not the patch window. Skip if you run no containers: answer "Yes" to keep scoring fair.
When the next Log4Shell-class flaw is disclosed, dependency visibility is the difference between answering "are we affected?" in hours or in weeks. Skip if you build no software: answer "Yes".
Part 7 — Exceptions & Risk Acceptance
Four written fields beat a silent backlog. The exception record is what answers "why was this open for a year?" when an auditor or insurer asks.
Each review renews, closes, or escalates every entry. Without it, exceptions become permanent by neglect.
Risk accepted for the long haul deserves a named, sufficiently senior signature — a record of who accepted what, and when.
Part 8 — Metrics & Governance
Even a one-page monthly summary builds the habit of visibility. What gets measured gets managed; what doesn't, drifts.
The people who fund the programme should hear about risk in risk language, not scanner language — quarterly is a common rhythm.
An annual health check is how a programme improves deliberately instead of drifting. One afternoon a year, well spent.
Free Edition snapshot · scored entirely in the browser — answers never leave the device
Your Vulnerability Management Maturity Results
0/ 68
—
—
Asset inventory
0 / 10
Scanning coverage & cadence
0 / 12
Prioritisation & triage
0 / 10
Remediation & SLAs
0 / 10
Patch operations
0 / 6
Cloud & container workloads
0 / 6
Exceptions & risk acceptance
0 / 8
Metrics & governance
0 / 6
Your Recommended Priority Actions
Free guide
Your First Vulnerability Management Wins
A short, plain-English guide to the five moves that take a programme from "we should do something about vulnerabilities" to a working routine — inventory, first authenticated scan, the KEV habit, starter deadlines, and a one-page report. Enter your email and we'll send it over.
Optional, and separate from your assessment — your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready to Close These Gaps?
The free assessment shows where you stand. The paid editions add the working documents — asset register, triage decision tree, SLA tables, exception forms, board-report templates and more — so you have the artefacts, not just the score.