Now supporting NIST CSF 2.0

Measure and improve
your cybersecurity
maturity.

Structured assessments, AI-driven findings, and audit-ready reports — purpose-built for compliance teams.

Aligned withISO 27001NIST CSFSOC 2CIS ControlsGDPR

Overview

Maturity Dashboard

ACTIVE
Score
3.4/ 5.0
Done
68%complete
Findings
12open
Access Control
84%
Network Security
62%
Data Protection
56%
Incident Response
78%
Avg 4.2 hrs
142 / 210 questions

Structured Assessments

Guided questionnaires built on real frameworks.

Run assessments mapped to ISO 27001, NIST CSF, SOC 2, and CIS Controls. Every question is scoped to a domain, scored automatically, and tracked against your target maturity level.

  • Configurable frameworks and scoring thresholds
  • Domain-by-domain progress tracking
  • Evidence attachment per question
  • Multi-assessor collaboration support

NIST CSF · Access Control

Domain Assessment

Progress

2 / 4

Is MFA enforced for all privileged accounts?

Yes — enforced via SSO

Are access reviews conducted quarterly?

Partially — annual only

Is least-privilege access enforced?

Are service accounts audited?

4 domains remaining

AI-Assisted Findings

Findings and recommendations — generated instantly.

As soon as your team completes a domain, CMA's AI engine analyses responses and scoring gaps to produce structured findings with severity ratings and recommended remediation steps.

  • Auto-generated findings from questionnaire responses
  • High / Medium / Low severity classification
  • Remediation guidance per finding
  • Gap analysis against framework benchmarks

AI Analysis

Generated Findings

12 findings
F-001

MFA not enforced for admin accounts

High

Immediate remediation required. Impacts overall maturity score.

F-002

Incident response plan not tested annually

Medium

Address within 30 days. Moderate risk exposure.

F-003

Encryption at rest not enabled for backups

High

Immediate remediation required. Impacts overall maturity score.

F-004

Security awareness training overdue

Low

Low priority. Schedule for next review cycle.

Recommendations auto-generated based on your responses

Maturity Dashboard

Your security posture, at a glance.

Track overall maturity scores, domain breakdowns, completion rates, and open findings from a single dashboard. Share live progress with leadership without waiting for the final report.

  • Real-time maturity score across all domains
  • Per-domain progress and gap visualisation
  • Open finding counts and severity breakdown
  • Shareable read-only links for stakeholders

Overview

Maturity Dashboard

ACTIVE
Score
3.4/ 5.0
Done
68%complete
Findings
12open
Access Control
84%
Network Security
62%
Data Protection
56%
Incident Response
78%
Avg 4.2 hrs
142 / 210 questions

Professional Reports

Audit-ready PDF reports in one click.

Export a fully formatted, timestamped report with an executive summary, domain breakdowns, all findings, evidence references, and a remediation roadmap — ready for auditors, regulators, or leadership.

  • Executive summary + full technical sections
  • Evidence-linked findings with timestamps
  • Remediation plan with ownership fields
  • Formatted for ISO, NIST, SOC 2 audits

Export

Assessment Report

PDF · 25 pages
Executive Summary
pp. 1–3
Maturity Score Breakdown
pp. 4–7
Domain Analysis
pp. 8–14
Findings & Remediation
pp. 15–22
Evidence References
pp. 23–25

Cover page

Cybersecurity Maturity Assessment

Conducted against NIST CSF · Q1 2026

ConfidentialInternal Use Only
Timestamped · Evidence-linked

Workflow

From assessment to report
in four steps.

1

Create Assessment

Select a framework, define scope, and configure scoring parameters.

2

Answer Questions

Work through domain questionnaires and attach evidence per question.

3

Generate Findings

Review AI-generated findings with severity ratings and gap analysis.

4

Export Report

One-click PDF reports for leadership, auditors, and compliance records.

Security & Compliance

Designed with the same rigor
you apply to your own programs.

Data Integrity

Validated, versioned data with role-based access controls ensuring only authorized personnel view or modify results.

Audit-Ready Reports

Timestamped reports with evidence references — ready for internal audits, external reviews, and regulatory submissions.

Standards Aligned

Mapped to ISO 27001, NIST CSF, SOC 2, and CIS Controls for globally accepted evaluation criteria.

Get started

Start your first assessment today.

No credit card required. Setup in minutes.