SELF-ASSESSMENTS
Find out where you stand before you hire anyone
One assessment for each requirement that shows up most often in procurement, and one for anyone who wants to know where their own risk is. You answer objective questions and the full result appears on screen, area by area.
Sign up and take the result with you
The result appears on screen either way. Identify yourself with a work email and your company details and you take more with you: the PDF is generated on the spot, with your company name on the document, and the detailed reading of each area arrives by email. Without signing up, the result stays on screen only.
Multiple choice questions, no free-text fields
A score per area, not one number on its own
With sign-up: instant PDF and the detailed reading by email
You can stop halfway and come back later, in the same tab
When the question is where to invest first
IT risk (oitenta20®)
Do you know where your risk is?
16 questions
Take the assessment: IT risk (oitenta20®)Continuity (Cyber Antifrágil®)
If everything stopped tomorrow, would you know what to do?
16 questions
Take the assessment: Continuity (Cyber Antifrágil®)Social engineering (Jigphish®)
Is your team ready for the next phish?
16 questions
Take the assessment: Social engineering (Jigphish®)Penetration testing (EHaaS)
Would your defenses survive a real attack?
16 questions
Take the assessment: Penetration testing (EHaaS)Secure code (SastAction®)
Would your code survive a security review?
16 questions
Take the assessment: Secure code (SastAction®)Privacy operations (DPO Backoffice®)
Is your privacy program more than paperwork?
16 questions
Take the assessment: Privacy operations (DPO Backoffice®)Compliance management (NosConformes®)
Are you ready for your next audit?
16 questions
Take the assessment: Compliance management (NosConformes®)
When the goal is a certificate
ISO/IEC 27001
Where your company stands on the road to certification
20 questions
Take the assessment: ISO/IEC 27001ISO/IEC 27701 (privacy)
How much of your privacy programme is already a management system
20 questions
Take the assessment: ISO/IEC 27701 (privacy)ISO/IEC 42001 (AI governance)
Where your company stands on AI governance
21 questions
Take the assessment: ISO/IEC 42001 (AI governance)SOC 2
How close your company is to holding up under an audit
18 questions
Take the assessment: SOC 2NIST CSF 2.0
Where your company stands across the six CSF 2.0 functions
21 questions
Take the assessment: NIST CSF 2.0CIS Controls
Where to start, when everything looks urgent
21 questions
Take the assessment: CIS Controls
When a regulator is asking
LGPD (Brazilian data protection law)
What your company could show today, if somebody asked
20 questions
Take the assessment: LGPD (Brazilian data protection law)BACEN and Resolution 4,893
Where your institution stands against the rule in force
21 questions
Take the assessment: BACEN and Resolution 4,893
When a customer or the supply chain is asking
TISAX (automotive supply chain)
Where your company stands today
14 questions
Take the assessment: TISAX (automotive supply chain)TPN (media studios)
Which assessment is yours, and what is missing for it to hold up
20 questions
Take the assessment: TPN (media studios)PCI DSS
Which PCI DSS is yours, and what is missing to get there
25 questions
Take the assessment: PCI DSSPCI DSS for IATA agencies
Where your agency stands today
14 questions
Take the assessment: PCI DSS for IATA agencies
All of them are self-declared: they stand as a picture of what your team knows today, not as an audit or a formal compliance assessment. Use them to decide where to start.
Not sure which one fits your case?
Describe the requirement that reached you, in the words they used. Our team will tell you which assessment makes sense, and if none does, they will say so.
Talk to a specialist