The three assessments.
Each one runs in your browser, needs no sign-up, and gives you a result you can act on.
NHI Maturity Assessment
12 questions across discovery, authentication, lifecycle, and governance. Maps your programme to a 5-stage maturity model (Reactive → Optimised) and identifies the highest-leverage next step.
Risk self-auditOWASP NHI Top 10 Self-Audit
Score your controls against the ten risks defined in the OWASP Non-Human Identities Top 10 (2025). Pass / Partial / Fail for each, with a coverage percentage and a path to the gaps.
Scenario testingBreach Readiness Score
Seven real NHI-origin breaches, Salesloft, Snowflake, Shai-Hulud, Storm-0558, Okta, Codecov. For each, would your controls have changed the outcome? Get a readiness score and a prioritised gap list.
How the tools are used in practice
These are planning tools, not compliance artefacts. Security leaders use them to frame internal conversations, on the state of an NHI programme, on exposure to recent breaches, on where budget should go next quarter. They are deliberately short. Nothing in them requires a vendor conversation.
If you're running a board-level review, all three combine usefully: maturity → risk → recent-breach exposure gives you a coherent story in three slides. If you'd like the PDF version of any of them, that's what the email option provides.
Why there's no paywall, no sign-up to use them, no vendor push
These tools are free to use. The full written report for each is unlocked with a work email so we can send it to you, and the research is supported by our commercial sister sites and advisory work. No vendor pays for placement. More in the editorial policy.
Prefer a human read on your results?
Run any tool above, then book a free 20-minute call to talk through your score with the HumanAudit team.