Free Tool

Vulnerability Management Program Scorecard
six domains, five tiers, one defensible read

A free, interactive vulnerability management programme scorecard. Score six capability domains (governance and ownership, asset and scope coverage, detection and intake, prioritisation and risk calibration, remediation throughput and SLA discipline, verification and audit trail) on the five-tier maturity scale (Initial, Developing, Defined, Managed, Optimised). The tool computes per-domain scores, an overall maturity rating, and a tier interpretation that turns a fuzzy "is our VM programme any good" question into one defensible read for leadership review and audit-committee briefing. Anchored to ISO/IEC 27001 Annex A 8.8, SOC 2 CC7.1, PCI DSS Requirements 6.3 and 11.3, NIST SP 800-53 RA-5 and SI-2, NIST SP 800-40r4, and CISA BOD 22-01.

No credit card required. Free plan available forever.

Loading tool...

Score the discipline against the live programme, not against memory

SecPortal pairs the operator queue and the leadership view to one engagement record, so the scorecard reads against findings, scans, retests, and audit evidence rather than against a separate spreadsheet. Free plan available.

No credit card required. Free plan available forever.