Skip to main content

Self-assessment

IT maturity self-assessment

A quick initial review against three frameworks - KSĮ / NIS2, CIS Controls v8 and SIM3. Answers are not stored; the assessment runs in the browser. A full PDF report is delivered in a separate stage.

Mobile-first WCAG 2.1 AA No tracking cookies Clear questions for a non-technical audience

Framework

KSĮ / NIS2

4 questions
1. Has a cybersecurity manager (CISO function) been appointed with clearly defined responsibilities?

KSĮ Art. 21 - management accountability and a designated person.

2. Has a cybersecurity risk assessment (KSRA) been carried out in the last 12 months?

KSRA - mandatory for organisational compliance by 2026-04-17.

3. Do you have an incident management procedure with NKSC notification deadlines (24 / 72 hours)?

KSĮ requires an early warning within 24 hours and a notification within 72 hours.

4. Has your supply chain been reviewed from a security perspective (subcontractors, cloud services)?

Supplier risk management - a critical NIS2 requirement.

At this stage the assessment runs in the browser; answers are not sent anywhere. A full expert version with an example base and a PDF report will be added in the next stage.
Discuss with an expert

JavaScript required - answers are evaluated in the browser.

Framework

CIS v8

5 questions
1. Do you maintain an up-to-date inventory of enterprise (hardware) assets?

CIS Control 1 - Inventory and Control of Enterprise Assets.

2. Are software versions and permitted applications managed (allow-list)?

CIS Control 2 - Inventory and Control of Software Assets.

3. Has data classification been completed and do you know where sensitive data is stored?

CIS Control 3 - Data Protection.

4. Are configurations standardised against CIS Benchmarks or an equivalent standard?

CIS Control 4 - Secure Configuration.

5. Is identity management centralised (SSO, MFA for every privileged user)?

CIS Control 5 / 6 - Account & Access Management.

At this stage the assessment runs in the browser; answers are not sent anywhere. A full expert version with an example base and a PDF report will be added in the next stage.
Discuss with an expert

JavaScript required - answers are evaluated in the browser.

Framework

SIM3

4 questions
1. Does the SOC / CSIRT function have a written mandate and a clearly defined constituency?

SIM3 Organization - Mandate, Constituency.

2. Do staff have a formal training and competency maintenance plan?

SIM3 Human - Skillset Description, Internal Training.

3. Do you have a secure communication tool for incident response (signed email, an out-of-band channel)?

SIM3 Tools - Secure Information Handling.

4. Is the incident management process documented and periodically reviewed?

SIM3 Processes - Incident Reporting Process.

At this stage the assessment runs in the browser; answers are not sent anywhere. A full expert version with an example base and a PDF report will be added in the next stage.
Discuss with an expert

JavaScript required - answers are evaluated in the browser.

Want a more structured learning path next?

NKSC offers a free cybersecurity training platform - four levels from staff-level basic up to CISO and SOC. Use it as the team's reference point before procuring commercial training.