Free AI Security Readiness Assessment — Scored in 5 Minutes
One quick step

Your PDF report and partner matching, in one step.

We only ask once — this covers both the PDF report and partner matching if you request them.

Free Diagnostic

Five minutes. A real answer on your AI security posture.

Answer 12 questions about your environment. Get a scored readiness report mapped to BOD 26-04's four-variable model and the AI Defense Matrix's 8 AI-specific asset classes — from agent identities to training data to the AI-generated code already in your repos. No email required to see your score. No vendor sponsorship influences results.

What this assessment covers.

Domain 1 · Vulnerability Response Readiness

Four questions mapped to the four variables of CISA BOD 26-04's prioritization model: KEV Status (how you monitor the Known Exploited Vulnerabilities catalog), Asset Exposure (per-asset internet exposure), Exploit Automation (whether a flaw can be exploited at machine speed), and Technical Impact (forensic triage before patching). Also referenced: FedRAMP VDR/VER, CISA Vulnrichment, and FIRST's EPSS.

Domain 2 · Security for AI

Eight questions, one per asset class of the AI Defense Matrix, each scored as its own category bar in your results:

AI-Workload Platforms
AI Orchestration Tools
AI-Generated Code
AI Gateways and Routers
AI Model
Training Data
Runtime AI Data
AI Agent Identities

Each asset class is cross-mapped to NIST CSF 2.0, the NIST AI Risk Management Framework, MITRE ATLAS, and the OWASP LLM and Agentic Security Top 10s.

What you get

A 0–100 score with a maturity label, a per-domain and per-asset-class breakdown, and your three weakest answers written up as gaps with the framework requirement each one maps to. A full PDF report covering all twelve findings is available afterward, and partner matching is optional.

12 questions · about five minutes

One question at a time. Your score at the end.

You can move backward and forward freely. "Don't know" is a valid answer — it scores as zero and surfaces as a gap, which is more useful than a guess.

{{ stepLabel }}
{{ stepCounter }}
Organization name (required)
{{ g.label }} {{ g.hint }}
{{ qFramework }}
{{ qText }}
{{ stepHint }}
We record anonymized results to build the independent readiness benchmark. No personal information is captured unless you request the PDF report.
{{ orgNameValue }}
Your AI Security Readiness Score
{{ score }}/100
{{ scoreLabel }}
Domain & category breakdown
{{ ds.name }}{{ ds.pct }}%
Your top three gaps
{{ gap.title }}

{{ gap.body }}

{{ gap.fw }}
{{ gap.cta }}
✓ Report downloaded
Your PDF has been saved to this device; please check your downloads folder.

Download your PDF report.

Every finding across all twelve questions, scored and mapped to the frameworks above. It downloads straight to this device — we don't email it, and nothing else is sent.

Early Access — Partner Matching

Want hands-on help closing these gaps?

Tell us which areas matter most — we've pre-selected your weakest domains — and we'll introduce you to a vetted partner. No cost, no obligation.

How scoring works — and who doesn't influence it.

Scoring is published openly: 12 questions, each scored 0–3, normalized to 0–100. Each of the 12 questions carries equal weight toward your overall score. Because Security for AI spans eight distinct asset classes against four for Vulnerability Response Readiness, it also carries more weight in your total — reflecting how much of the AI-era threat surface these questions actually cover. Vendors cannot pay to alter the logic, the questions, or the gap-to-category mappings.

Built on public frameworks — CISA BOD 26-04, FedRAMP VDR/VER, MITRE ATLAS — and the AI Defense Matrix's 8 asset classes, each cross-mapped to NIST CSF 2.0, MITRE ATLAS, and the OWASP LLM and Agentic Security Top 10s.

Category structure adapted from the AI Defense Matrix by Lenny Zeltser and Sounil Yu, licensed CC BY-SA 4.0.
Distribution partners assisted in reaching survey respondents. They had no access to, review of, or influence over survey design, response data, analysis, or conclusions prior to publication.