Skip to content
FortaRisks
The whole platform

Your security maturity, measured and dated

A guided assessment, one question per control, against the framework that matters to you. You get an A-F grade and a CMMI maturity level from 0 to 5. No external questionnaire to start, and no misleading composite score: posture measures operational risk, compliance measures regulatory risk.

A-F

Posture grade

0 to 5

CMMI maturity

31

Frameworks assessable natively

"We are fairly mature." On what, measured when, against which target?

Most organizations can name their tools but not their level. With no scale, no target and no date, you cannot tell leadership whether you are progressing, or justify the next budget. Classic maturity questionnaires demand weeks of collection before producing a single number, and that number ages the moment it is published.

Value you can see

Outcomes your team will feel.

  • A defensible number in days

    A-F grade, CMMI maturity, chosen target: enough to answer the board without waiting for an audit.

  • No false zeros

    What is not measured is shown as such. Coverage always travels with the grade.

  • Evidence serves twice

    The evidence register also feeds compliance: collection is not redone framework by framework.

Key capabilities

  • A measurement that starts without an external questionnaire

    The assessment is guided, one question per control, with three possible answers: yes, partial, no. You get an A-F grade and a CMMI maturity level from 0 to 5, per domain and overall. Six approaches are available depending on the time you have, from a fast baseline to an exhaustive evidence-backed assessment.

  • Assess against the framework that matters to you

    ISO 27001, SOC 2, CIS Controls, PCI DSS, NIST CSF 2.0, NIST Privacy Framework, ISO 42001, OWASP: nine frameworks are assessed natively by questionnaire, and you can define your own. Each profile gets its framework assignment, its scope and its target, so you can measure a subsidiary, a plant or a service line separately.

  • The assessment screen is an audit workstation

    For every control you see what to verify (5,956 assessment objectives), what to provide (evidence levels, 316 artifact types) and which alternatives are acceptable (compensating controls). Evidence lands in a single register, reusable by compliance.

  • History, trend and forecast maturity

    A snapshot is taken every day. You read your 30-day delta, your trajectory, and the forecast maturity if the current pace holds. A grade with no date is worthless in front of a board; this one is dated and comparable.

  • A NIST CSF 2.0 reading on top, whichever framework you assessed

    Whichever framework you assess against, your posture can be read converged on the 6 NIST CSF 2.0 functions and their 22 categories, with a configurable target and a radar view. It is the language an executive committee understands, obtained by projection from the SCF baseline: an extra reading, not a starting constraint.

Every gap becomes an action, not a spreadsheet row.

Maturity gaps feed the Action Center with an owner and a deadline, and the risk register as operational risk. A control raised at the next assessment closes the action on its own.

Three moments where posture decides

  • New in role

    New CISO, 90 days to a diagnosis

    A CISO joins a 600-person manufacturer. No formal baseline exists. They run a baseline assessment in four days, land a D grade and an average CMMI maturity of 1.4, with two NIST functions below the critical threshold (Detect, Recover). The 90-day plan is written on that basis, costed, and the first leadership review happens with a dated number instead of an impression.

  • Budget

    Justifying an investment request

    Leadership asks why a logging project should be funded. The NIST CSF breakdown shows the Detect function at 0.9 when the target is 3, and the gap analysis costs the remediation effort. The request stops being a technical opinion and becomes a measured gap, with a cost and a trajectory.

  • Proof of progress

    Showing a trajectory, not a promise

    Six months into the plan, the 30-day delta and the daily history show maturity moving from 1.4 to 2.6, the Detect function back above threshold, and forecast maturity at 3.1 if the pace holds. The board sees a verifiable trajectory, not a statement of intent.

What's included

Measurement & coverage

  • A-F grade and CMMI maturity 0 to 5
  • 31 frameworks assessable, plus your own
  • Framework assignment, scope and target per profile
  • Optional NIST CSF 2.0 reading (6 functions, 22 categories)
  • Assessed, mapped or unmapped coverage, never a false zero
  • Daily snapshots, 30-day delta, forecast maturity
  • One evidence register, reused by compliance

Gaps & remediation

  • Gaps per domain and per function
  • Quick wins isolated automatically
  • Compensating controls accepted and traced
  • Prioritized remediation plan
  • Assessment sessions with assignment, review and approval
  • Comparison across profiles and periods
  • Every gap becomes a dated action in the Action Center

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In posture, AI targets preparation and reading: proposing an assessment answer from evidence already filed, drafting the trend commentary, explaining a maturity gap in plain language. The A-F grade, the CMMI level and coverage stay computed by an explicit model, verifiable control by control.

Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Posture is not a silo. Every module leans on it.

Control maturity is the platform's reference data point. Without it, the other modules work in theory: they see exposures and threats, but not your real capacity to answer them.

  • Posture → Compliance

    A control assessed once feeds every framework that requires it. That is the engine behind "comply once, comply many": compliance inherits the posture work instead of redoing it.

  • Posture → Risk Engine

    Control maturity reduces residual risk. When no control is recorded on a sub-domain, an implicit defense credit is derived from posture, rather than leaving a hole in the register.

  • Posture → EASM and CTI

    A detected exposure does not carry the same severity depending on your ability to detect and respond. Posture weighs urgency: the same exposed service is not handled the same way whether your Detect function sits at 1 or at 4.

  • Posture → Action Center

    Every maturity gap becomes a prioritized action with an owner and a deadline, and the loop is verified: an action declared done only closes for good at the next assessment, otherwise it reopens.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.

Frequently asked questions

How is posture different from compliance?

Posture measures your operational maturity: can you do it, and how well. Compliance measures your alignment to a given framework: do you meet the requirement. Both rest on the same SCF control baseline, but they never merge into a single score, because they carry two different risks, one operational, one regulatory.

How long before we have a first number?

A baseline assessment on essential controls takes a few days. The evidence-based assessment takes about two weeks, and the comprehensive one four to six weeks, at the level of rigor an ISO 27001 or a SOC 2 Type II expects. You pick the depth; the grade is produced on the first pass.

What happens to a domain we have not assessed?

It is marked as not covered, not as a zero. That is an engine rule: an unknown domain must never look like a failing one, nor inflate an average. Actual coverage is displayed next to the grade.

Is the grade comparable from one period to the next?

Yes. Daily snapshots are produced by the same service that renders the screens, which guarantees a report and a screen cannot diverge. So you compare like with like, and the 30-day delta is computed on that basis.

Do we have to go through NIST CSF?

No. You assess against the framework you choose, and nothing forces you to look at the NIST CSF reading. It is available because the SCF baseline lets any assessment be projected onto the 6 functions, and because it is the most widely shared vocabulary in the boardroom. If your organization speaks ISO 27001, stay on ISO 27001.