Your stage
Placed on a five-level model from ad hoc to optimised, with what characterises the level above yours.
Per-area scores
Discovery, ownership, credential control and evidence, scored separately so you can see which one is holding the total down.
Three moves
The highest-leverage actions for your specific stage, not a generic maturity roadmap.
Before you start
12 questions, about 4 minutes. Everything runs in your browser. Nothing is transmitted, nothing is stored, and no email is requested at any point. Answer honestly rather than aspirationally, because the output is only as useful as the input and nobody else sees it.
How the maturity model works
The 5-stage model draws on CSA's state-of-NHI-security work, informal NIST CSF v2 alignment, and the practical experience of enterprise CISOs running NHI programmes. The stages are descriptive, not prescriptive:
- Stage 1, Reactive. No systematic NHI programme. NHIs are discovered when something breaks. Ownership is informal or absent.
- Stage 2, Ad-hoc. Some discovery has happened, typically a one-off inventory, but it isn't continuous. Basic hygiene exists in silos.
- Stage 3, Defined. Continuous inventory is in place. Ownership is assigned. Policies exist on paper. Posture is monitored but not fully remediated.
- Stage 4, Managed. Lifecycle is automated end-to-end for most NHIs. Credentials are short-lived where possible. Third-party integrations are governed.
- Stage 5, Optimised. Metrics drive improvement. AI-agent and workload-identity patterns are part of the programme, not separate. Board reporting is routine.
What the tool doesn't do
It doesn't recommend specific vendors. It doesn't capture the full richness of any real programme, twelve questions can't. It doesn't substitute for a serious internal assessment. What it does do is give you a defensible external framing and a sharper sense of which dimension is most worth attention next.
Related
For the full maturity model with KPIs and a 12-month roadmap, see NHI management. For the control-level audit, use the OWASP NHI Top 10 self-audit. For exposure to specific known breaches, try the breach readiness score.
Want a second read on your score?
The tools give you a number. A 20-minute call with HumanAudit will tell you which gap to close first, roughly what it costs, and what you can defer with a documented rationale.
What to do with your result
A score is only useful if it changes what you do next. These are the routes we would suggest depending on where you land.
| If your result shows | Do this next |
|---|---|
| Below level 2 | Inventory and ownership first. Tooling will surface problems you cannot yet act on. See the discovery methodology. |
| Level 2 to 3 | Credential lifetimes and review execution. The policy template is the fastest route. |
| Level 3 and above | Build versus buy becomes a real question. See the decision guide. |
Want a second read on your result?
Twenty minutes with HumanAudit, free and with no obligation. Bring the score and we will tell you which gaps actually matter for your estate and which are noise. If we are not the right answer we will say so on the call.