Score your AI security maturity in 5 minutes.
Eight questions on how your organization defends AI systems, agents, and data across identity, prompts, tools, memory, supply chain, models, outputs, and the AI development lifecycle. You get a radar view of where you stand, aligned to NIST CSF 2.0.
A self-assessment reflects what you report. The useful part is seeing which answers you could actually prove.
Where should we send your results?
We will email your PDF right away. Tell us if you would like us to follow up, no pressure.
By clicking “Start my Assessment”, you consent to the processing of your personal data in accordance with our Privacy Policy to deliver your assessment and contact you about it.
What this measures
How well you defend AI systems, agents, and data across the 8 Protect categories.
How it's scored
Each category is scored 1 (Partial) to 4 (Adaptive), shown as a radar.
Where it sits
Protect is 1 of 6 domains (Govern, Identify, Protect, Detect, Respond, Recover), aligned to NIST CSF 2.0.
The 8 Protect categories
- PR.1 · NHI & Access
- PR.2 · Prompt Security
- PR.3 · Tool Authorization
- PR.4 · Memory Integrity
- PR.5 · Supply Chain
- PR.6 · Model Robustness
- PR.7 · Output Guardrails
- PR.8 · Secure AI SDLC
Want the full framework? Read the ASMM overview →
Why this exists
Traditional security assumed predictable systems and human-driven actions. AI systems act autonomously, run on non-human identities, take real-world actions on untrusted input, and operate without human approval at each step. Yesterday's controls were not built for that.
What this measures
Move Fast. Build Agentic. Stay Secure.
Standards anchor
Built on NIST CSF 2.0 and aligned to the OWASP Top 10 for Agentic Applications. Also referenced: NIST AI RMF, CSA AICM, and the EU AI Act.
Who this is for
Built for CISOs and security leaders at organizations leveraging AI for production assets.
FAQ
+How is the ASMM different from other AI security frameworks?
The ASMM is designed to assess the organization's security program, for its ability to govern, protect, detect, respond to, and recover from risks across AI adoption, development, integration, and operation, including agentic AI systems that reason, act, and operate with autonomy. It also assesses the security program (policies, governance, processes), not the technical posture of individual systems.
+How is it different from NIST AI RMF or ISO 42001?
NIST AI RMF provides governance principles. ISO 42001 is a certifiable management system standard. The ASMM is an assessment tool. It gives you a number across 28 categories so you can track improvement over time. It helps organizations assess their maturity and alignment to these frameworks indicating where investment in additional capabilities may be required.
+Does it apply to all AI systems or only agentic ones?
It applies to AI systems in scope, then uses the Autonomy Test to determine which systems qualify as agentic for agentic-specific control depth. The framework is designed for assessing and improving the security maturity of organizations developing or operating agentic AI systems, that reason, plan, and act autonomously, with reduced or risk-based depth for lower-risk or human-assisted AI systems, as appropriate.
+How do I assess my organization's AI security posture?
Run the ASMM assessment across the six domains. Each of the 28 categories gets scored from 1 (Partial) to 4 (Adaptive). Your domain scores and overall score tell you where your security program is mature and where the gaps are. The result is a prioritized roadmap, not a pass/fail.
+Can I use this alongside NIST CSF 2.0?
Yes. The ASMM is aligned with the NIST CSF 2.0 structure. Same six functions (Govern, Identify, Protect, Detect, Respond, Recover). It complements NIST CSF 2.0 by applying its six-function structure to AI security maturity, including agentic AI-specific risks, rather than replacing it.
+We already use a vendor AI security tool. Does this replace it?
No. ASMM is an assessment framework, not a security tool. It tells you where your security program stands and what to prioritize. Your existing tools are how you execute on that. Most organizations find ASMM useful precisely because it gives them a vendor-neutral baseline before or during vendor evaluation.
+Doesn't NIST SSDF, OWASP SAMM, or the NIST AI RMF already cover this?
Partially, but each stops short of where agentic AI risk actually lives. SSDF and SAMM secure the humans building software. The NIST AI RMF governs AI as a system component. None of them address AI agents as autonomous actors or in systems that make runtime decisions, invoke tools, access data, and spawn sub-agents without human approval on every action. ASMM is built for that inversion. It inherits from CSF 2.0 and AI RMF for structural familiarity, then adds the six domains, four maturity tiers, and control evidence needed to assess and improve an organization's readiness to secure autonomous agent development specifically.
+Does this assessment cover AI governance?
This tool assesses the Protect domain only. Governance is a separate domain in the full six-domain model, not covered by these 8 questions.