Skip to content
All services
DevSecOps & secure CI/CDAssess

DevSecOps gap check

In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.

When you need it

Security in your delivery process depends on who is working that week. Some repositories run scanners and others do not, nobody owns the exceptions, and when a customer asks how you build secure software, the answer is a promise rather than evidence.

What sets the quote

  • Sized from counts you already know: teams, engineers, CI platforms and active repositories.
  • One week: up to 5 teams or 50 engineers, one CI platform and 10 sampled repositories.
  • Two weeks: up to 15 teams or 150 engineers, up to 2 CI platforms and 20 sampled repositories.
  • Larger organisations, or more CI platforms, are quoted after the call.

What changes

  • You know the current and target maturity level for each OWASP SAMM practice, backed by evidence from your repositories and pipelines rather than interviews alone.
  • You can answer customer questions about secure development with a practice-by-practice mapping to NIST SSDF.
  • You know which gaps need tools and which need ownership, habits or time.
  • You have a 90-day plan ordered by risk and effort, ready for your backlog.

What you get

  • OWASP SAMM scorecard with the current and target level for each security practice
  • NIST SSDF (SP 800-218) mapping that shows which practices are in place, partly in place or missing
  • Gap list with evidence, a suggested owner and the effort for each gap
  • 90-day plan ordered by risk and effort
  • One-page summary for management
  • All gaps as a CSV file for your ticket system
  • A 90-minute readout with your engineering and security leads

The gap check shows where to start. When the biggest gaps sit in the pipelines, the usual next step is a pipeline security check or a secure CI/CD pipeline. When they sit in ownership and habits, it is the DevSecOps operating model.

Not included

  • Closing the gaps (quoted separately, often as a secure CI/CD pipeline or a DevSecOps operating model)
  • Penetration testing (we can refer you to a certified partner)
  • Application code review
  • Compliance certification or audit opinions

What we need from you

  • Read access to the sampled repositories and their pipelines, for example the Read role on GitHub, Reporter on GitLab or the Readers group in Azure DevOps.
  • A 45-minute screen-share with a CI platform admin to walk through the organisation settings that read-only roles cannot see.
  • 45-minute interviews with your engineering lead, your security owner and a sample of team leads: up to 5 in one week and up to 10 in two weeks.
  • Your secure development guidelines or policies, if you have them.

How it works

  1. Free 30-minute call, then a written fixed quote based on your team, engineer and repository counts.

  2. Interviews based on the OWASP SAMM assessment questions.

  3. Evidence checks in the sampled repositories and pipelines, then a score per practice and agreed target levels.

  4. Gap list, 90-day plan and a 90-minute readout.

At a glance

Duration
1–2 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess Popular

Pipeline security check

A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.

Duration:1 week
Build

Keyless pipelines and secrets cleanup

Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.

Duration:1–3 weeks
Build Popular

Secure CI/CD pipeline

A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.

Duration:2–5 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.