Get the security policies and documentation
your business needs.
When insurers and customers ask about your security, have both the policies and the proof ready. Start with a free scored assessment report. The full 21-file package is $1,295, with no subscription or recurring fees.
Your answers drive both the score and the documentation.
The assessment covers all six NIST CSF 2.0 functions and gives you a scored maturity profile with a tier analysis. Your documentation package is then built around the answers you provided, so the policies, worksheets, and checklists reflect your organization instead of simply filling your name into a generic template.
You also get a clear record showing how your assessment responses connect to the documents in your package.
Three steps, start to finish
Complete the assessment
Answer questions across ten sections covering your organization's current cybersecurity practices. Progress saves automatically. Pick up where you left off at any time.
Receive your free report
See scored maturity across all six CSF functions, an AI tier classification with rationale, and prioritized recommendations, within a couple of minutes of finishing. All at no cost.
Download the full documentation package
Ten security policies drafted from your answers, plus the assessment report, the Q&A record, and nine working files: a cyber insurance application worksheet, vendor questionnaire responses, an executive memorandum, a findings register with the CSF coverage matrix, a remediation tracker in Excel and Word, a RACI matrix, an evidence request checklist, and an incident response quick card. Delivered as a ZIP of editable files, usually 20 to 30 minutes after purchase.
Watch the two-minute walkthrough
From the first assessment question to your scored report and finished policy documents.
There are other ways to get security policies and documentation.
They usually require more money, more time, or more work from your team.
Useful when you need ongoing security leadership. If your immediate need is policies, evidence, and documentation, a monthly advisory relationship may be more than you need.
You get the files, but the work is still yours. Each document has to be rewritten to reflect your systems, responsibilities, requirements, and actual security practices.
Built for managing compliance programs over time. That usually means licensing, setup, administration, and another system for your team to maintain.
$1,295 one time. No subscription, no sales call, and no onboarding. Your scored report is free whether you purchase the documentation package or not.
The documents are based on the answers you gave in the assessment, and the package includes a record showing how those answers connect to your documentation. That gives you something a generic template or one-off AI-generated document does not: a clear link between what you reported and what appears in your policies, worksheets, and checklists.
The free report, and the full package
Your Maturity Report
Generated within a couple of minutes of submitting. No payment required.
- Scored maturity across all six CSF functions
- AI-generated NIST CSF tier classification with supporting rationale
- Prioritized recommendations mapped to your lowest-scoring areas
- A clear baseline to track your improvement over time
The free maturity report as it appears on screen, generated for a fictional healthcare company.
Up to 21 Tailored Documents
Generated from your assessment responses, with your platforms, obligations, and recovery objectives written into the text. Ten policies, your assessment report, and nine working artifacts, delivered as a ZIP ready for your team to review and adopt.
- 01Information Security PolicyView sample
- 02Acceptable Use PolicyView sample
- 03Access Control & Identity Management PolicyView sample
- 04Data Classification & Handling PolicyView sample
- 05Logging, Monitoring, and Alerting PolicyView sample
- 06Vendor & Third-Party Risk Management PolicyView sample
- 07Backup & Recovery PolicyView sample
- 08Incident Response PolicyView sample
- 09Vulnerability & Patch Management PolicyView sample
- 10Secure Development (SDLC) Policy (included if you develop software)View sample
And the working documents that put them to use
- 11Cyber Insurance Application WorksheetView sample
- 12Vendor Security Questionnaire Response PackView sample
- 13Remediation Tracker (Excel and Word)View sample
- 14Executive and Board MemorandumView sample
- 15Findings Register and CSF Coverage MatrixView sample
- 16Roles and Responsibilities (RACI) MatrixView sample
- 17Evidence Request ChecklistView sample
- 18Incident Response Quick CardView sample
- 19Assessment Q&A Summary
Start with the free assessment
About 20 minutes. The scored report arrives a couple of minutes after you finish, at no cost, whether or not you buy the package.
Begin Assessment →You'll review our terms and data handling disclosures before you begin.