Security Health Check

Answer 10 questions about your security practices. Get an instant maturity score with plain-language interpretation.

Your data stays in your browser
No signup required
No tracking or data collection

Who this tool is for

This check is for anyone who needs an honest first read on an organization's security posture without commissioning a full assessment: founders and executive directors who have never had a security review, operations or IT leads who inherited the program, board members asking "are we okay?", and security leaders who want a quick baseline before a deeper engagement. It works for a 12-person nonprofit and a 400-person professional services firm alike — the ten questions cover the practices every organization needs regardless of headcount; only the depth of implementation changes.

What it measures — and what “in scope” means

The ten questions map to the control areas that show up in nearly every framework — NIST CSF, CIS Controls, SOC 2, ISO 27001, HIPAA, and CMMC Level 1: documented policies, incident response, backup management, patching, user access, data classification, third-party risk, staff training, risk assessment, and leadership support. Each answer is scored on a maturity scale from informal or absent to documented, tested, and regularly reviewed. Your score is a weighted average across those areas, and the interpretation tells you which two or three areas are dragging it down. "In scope" here means the practices as they exist today, not what is planned or budgeted — answer for what you could show an auditor this week.

What your result is not

The score is a self-assessment, not an audit. It reflects the accuracy of your answers, it does not verify that controls work, and it is not evidence you can hand to a customer, an insurer, or a regulator. A high score does not mean you are compliant with any specific framework; a low score does not mean you are about to be breached. Treat it as a prioritization aid: it tells you where to look first. For a defensible assessment with tested controls and documented findings, you need an independent review.

Frequently asked questions

QHow long does the security health check take?

About ten minutes. There are ten multiple-choice questions, and nothing is saved between sessions, so you can retake it as often as you like.

QIs this a substitute for a SOC 2, HIPAA, or CMMC gap assessment?

No. It is a maturity snapshot across the control areas those frameworks share. A gap assessment tests specific requirements against evidence; this tool asks how mature your practices are in general terms.

QWhat is a good score?

Most organizations with no dedicated security function score in the middle third. The useful information is not the number but the two or three lowest-scoring areas — those are your next projects.

QDoes DARS see my answers?

No. The check runs entirely in your browser. Nothing is transmitted, stored, or logged. Close the tab and it is gone.

QWhich security controls should I fix first?

Multi-factor authentication, tested backups, and patching consistently deliver the most protection per hour invested. The related article on the five controls to implement first walks through why.

Related reading

Five Security Controls Every Small Organization Should Implement FirstThe First Four Hours of a Cyber Incident When You Have No CISOAI Governance for Small Teams: A Practical Starting Point

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.

Need a Deeper Analysis?

This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.

Schedule a Scope Call