BASE METAL KIT · 01 OF 04
MATURITY ASSESSMENT
REACTOR MODE
a maturity assessment
Data Security and Governance, measured honestly.
Twenty-one plain questions across seven domains. Answer where you actually are, not where you mean to be, and the tool returns a read on each domain, an overall posture, and a short roadmap of the highest-leverage moves to make next. Built on NIST CSF 2.0, CIS Controls v8, and ISO 27001 and 27701. It runs entirely in your browser. Nothing you enter leaves this page.
A low score is not a grade. It is your base metal: the honest starting point of the work. Every transmutation begins here, so answer plainly and let the result point the way.
The maturity ladder · rate each statement on this scale
0 of 21 answered
Answer all 21 to reveal your posture
the result
82
Pb
Base metal
→
79
Au
The result
Honest answers in. A posture and a roadmap out.
Your posture today
Absent
By domain
Your roadmap
The moves below are ordered by leverage: the lowest-maturity domains first, because that is where the next hour of work returns the most. Each routes to the artifact in this kit that does the work.
A note on the kit's shape
Base Metal is four artifacts, not seven. Three domains have a document of their own: Inventory and Classification has the Classification Policy, Protection and Handling has the Handling Matrix, and Governance has the Operating Model.
The other four are operationalized inside those documents by design. Access and Identity and Retention and Disposal live as lifecycle stages in the Handling Matrix and as activities in the Operating Model. Vendor Risk and Detection, Response and Recovery live as activities in the Operating Model. This keeps the guidance in one place rather than spread thin across documents that would repeat each other. Where your roadmap points to one of these, it names the exact section to turn to.