Baseline Security Check

Know Your Security Baseline

Quick questions
About 2 to 3 minutes
Completely free
Based on NIST CSF

What this is

This is a short, plain-language check-in on your everyday security habits, not a technical test, and nothing on your systems is ever touched. It's free and takes about 2 to 3 minutes. You'll answer questions like whether you use multi-factor authentication, how you handle backups, and how prepared you'd be if something went wrong, then get an instant, personalized picture of where things stand. Every question is tied to a category from the NIST Cybersecurity Framework, a standard security professionals rely on, so the questions aren't random.

How it works

  1. 1
    Answer the questions. Yes, Partial, Not Sure, or No, based on what you already know about your organization. No technical background needed.
  2. 2
    Get an instant rating. Your overall result and a breakdown across 8 categories, shown as plain-language ratings, not a percentage or score.
  3. 3
    Unlock your full report, if you want it. Enter your name and email to see specific guidance for every answer, and keep a copy for your records.

What your ratings mean

Your overall result, and each of the 8 categories, lands in one of four bands below, described in plain language so they're easy to understand.

Deficient Core protections are missing or inconsistent in this area.
Developing Some protections are in place, with various gaps still open.
Partial A fairly consistent baseline posture, with real gaps below still worth closing.
Implemented A strong baseline posture in place.

Where your information goes

Your questionnaire answers aren't stored anywhere, unless you choose to keep the PDF report you can generate at the end. If you unlock your results, we do keep the contact information you provide (name, company, email, phone), but only for contact purposes. It's never sold or shared, and it stays within P.C.R.'s control. At no point does this tool connect to, scan, or access your systems, network, or accounts. Every answer comes from you, not a scan.

What this is not

  • Not a technical audit, scan, or penetration test of your systems
  • Not a certification, attestation, or compliance determination of any kind
  • Not a guarantee of security, and not proof that you are, or are not, fully secure
  • Not independently verified, every answer is self-reported, and results are only as accurate as those answers
  • Not a substitute for a defined, scoped security assessment performed by a professional
  • Ratings and severities reflect P.C.R.'s professional judgment, applied to self-reported answers only