Free Quick Check: 11 areas of security in about 8 minutes, with AI readiness included. Start now >
Cyber SecurityMaturity Assessment

Measure Your Cyber Security Maturity In Minutes.

MaturityIQ assesses your organisation against 40+ frameworks, turns every gap into a dated action, and gives you reports for the board and for IT. Start with the free Quick Check.

No card neededAbout 8 minutesReadiness, not certification
Dashboard · illustration with sample data

Current score

65%

Up 19 points since June

Mar 21%

Jun 46%

Sep 65%

Endpoint Security85%
Identity & Access80%
Incident Response70%
Vulnerability Management40%
Supplier Security31%
CRITICAL · DUE WITHIN 30 DAYSOWNER: IT MANAGER

Require multi-factor authentication for remote and administrator sign-ins

FeaturesWhat You Get

Everything You Need To Assess, Fix And Prove Security.

Free Quick Check

A fast baseline across 11 areas of security in about 8 minutes, with AI readiness and AI management included and a clear list of what to fix first.

40+ Frameworks, One Library

ISO/IEC 27001, SOC 2, NIST CSF 2.0, Cyber Essentials, NIS2, DORA and more. Each gives a readiness score, area by area.

A Dated 12-Month Plan

Every gap becomes an action with an owner, a due date, what done looks like and the evidence to keep. Critical items fall due within 30 days.

Evidence, Reviewed

Upload evidence against each action. An internal or external auditor accepts it or sends it back with a comment.

Documents, Verified Once

Track the policies and records each framework expects. A document verified once counts for every framework that asks for it.

Reports For The Board And IT

An executive report, a technical report, and a progress report after each reassessment that shows exactly what changed.

IDENTITY & ACCESS · QUESTION 3 OF 6

How do you make sure only the right people can sign in remotely?

Nothing in placeL0 ABSENT
Done sometimes, not written downL1 INITIAL
Done consistently for most systemsL2 MANAGED
Documented, owned and applied everywhereL3 DEFINED
Measured and improved on a scheduleL4 OPTIMISING
AboutMaturityIQ

Built For The Day Someone Asks, “How Secure Are We?”

Describe what you do today in plain language. Every answer maps to one of five levels, from Absent to Optimising, so the score means the same thing every time you measure it.

For CISOs And Security Leads

One score, area by area, and a plan you can put in front of the board.

For IT Managers

Plain-language questions and a clear order of work, without hiring a consultant first.

For MSPs And IT Service Firms

Assess every client under your own logo and name, and show what your work achieved.

HowIt Works

From First Answer To Board Report In 4 Steps.

STEP 1

Assess

Answer in plain language.

Every answer maps to one of five levels, from Absent to Optimising.

STEP 2

Plan

Every gap becomes a dated action.

Each has an owner, a due date and the evidence to keep. Critical items fall due within 30 days.

STEP 3

Prove

Evidence is reviewed, not assumed.

An internal or external auditor accepts it or sends it back with a comment.

STEP 4

Report

Reports for the board and for IT.

After a reassessment, the progress report shows exactly what changed.

InsideThe App

See What Your Team Will Work With.

Try It Free

REMEDIATION

Every Gap Becomes A Dated Action

CRITICAL · DUE WITHIN 30 DAYSEFFORT M

Require multi-factor authentication for remote and administrator sign-ins

Owner
IT Manager
Due
30 Oct 2026
Done when
MFA is enforced for every remote and administrator sign-in, with no standing exemptions.
Evidence
A screenshot of the enforced policy and the list of exempt accounts, if any.

DOCUMENTS

Evidence A Reviewer Has Accepted

DOCUMENTS · 3 OF 26

Information Security PolicyVERIFIED

ISO 27001 · SOC 2 · NIS2

Incident Response PlanWAITING FOR REVIEW

ISO 27001 · DORA · PCI DSS

Supplier Security PolicySENT BACK

ISO 27001 · SOC 2

Reviewer: add the next review date.

REPORTS

Proof Of What Changed

PROGRESS REPORTBASELINE TO THIRD ASSESSMENT
21%
30 MAR
46%
29 JUN
65%
28 SEP

Improved
Identity & Access, Endpoint Security, Incident Response

Slipped
Vulnerability Management, Supplier Security

FrameworksThe Library

One Library, 40+ Frameworks.

Pick the standard your customer, regulator or board is asking about. MaturityIQ reports your readiness for it. It does not certify, and it is not legal advice.

Information Security Management

ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27003 and more

Governance And Process

COBIT 2019, CMMI v2.0, C2M2 v2.1

Risk, Resilience And Incidents

ISO 22301:2019, NIST SP 800-30, NIST SP 800-37 and more

Cloud

ISO/IEC 27017, ISO/IEC 27018, CSA Cloud Controls Matrix v4 and more

Privacy And Data Protection

GDPR, UK GDPR, NIST Privacy Framework

Sector And Regulation

SOC 2, PCI DSS v4.0, HIPAA / HITECH and more

Industrial And OT

ISA/IEC 62443-2-1, NIST SP 800-82

Application And Software Security

OWASP ASVS 4.0, OWASP SAMM 2.0, OWASP Top 10:2021 and more

AI

NIST AI RMF

SimplePricing Plans

Easy-To-Understand Pricing For Every Team.

Start free. Pay when you need the full picture. Prices are in US dollars per month.

BlogNews And Guides

Our Latest Insights.

Frameworks · Coming soon

ISO/IEC 27001 Or SOC 2: Which One Is Your Customer Really Asking For?

Guides · Coming soon

What A Readiness Score Tells You, And What It Does Not

Guides · Coming soon

The First 30 Days: Which Security Gaps To Close First

FAQsGood To Know

Questions People Ask Before They Start.

No. MaturityIQ measures readiness. Certification comes from an accredited body; MaturityIQ helps you get ready for that audit and keep the evidence it asks for.

ContactUs

Talk To A Person.

A question about plans, an MSP application, or something not working. Tell us and a person will reply.