Free AI security self-assessment

AI security self-assessment in five questions.

Free, from CWS. See where your organization stands, Crawl to Sprint, and the one move that takes you forward.

By CWS, named delivery OWASP, NIST AI RMF, ISO 42001 mapped Delivered by email or live
The Posture Quadrant
RUN Controls running ahead of the program SPRINT Program and controls in place and audited CRAWL No sanctioned AI and no policy WALK Policy and owner first, controls uneven PROGRAM · POLICY, OWNER, INVENTORY, VENDOR TERMS → CONTROLS IN OPERATION · PROMPT, MODEL, RUNTIME → EXAMPLE PLACEMENT · YOUR DOT IS DRAWN FROM YOUR ANSWERS YOU · Q 03
Figure 1. The Posture Quadrant. An example placement; yours is drawn from your answers.
Five
Questions
Four
Stages
A few
Minutes
Free
Always
Six scoring dimensions

What an AI security self-assessment measures

An AI security self-assessment reads your organization's AI security across six dimensions: governance, data, prompt, model, runtime, and vendor. Each dimension maps to a named framework, so every gap traces back to a source, not a private scoring model.

The governance dimension also asks what AI coding agents and assistants are running on staff machines, what files, applications, and credentials they can reach, and how MCP servers and Skills are vetted before install. In this market, governance means agent permissions and blast radius as much as it means policy.

Crawl, walk, run, sprint

The four AI security maturity stages

These are maturity stages, not a compliance checklist. The Cloud Security Alliance's AI Security Maturity Model, OWASP's AI Maturity Assessment, and the SANS AI security self-assessment go deeper into each one. The Posture Check is the three minute placement that tells you which of them to pick up next.

Bottom left

Crawl

No sanctioned AI and no policy.

Move to WalkName an accountable owner and write a one page AI policy.
Bottom right

Walk

Policy and owner first, controls uneven.

Move to RunInventory every AI deployment and start testing prompts against the OWASP LLM Top 10.
Top left

Run

Controls running ahead of the program.

Move to SprintCatch the program up: formal vendor terms, then bring the controls under one owner.
Top right

Sprint

Program and controls in place and audited.

Hold the lineQuarterly review against ISO 42001 and the frameworks that keep moving.
What you receive

You choose how your stage arrives.

Both paths give you the same result: your stage, the move to the next one, and the framework citations behind it.

By email

Your stage, from Crawl to Sprint, the one move that takes you to the next stage, and the framework citation behind every question you answered, written so you can forward it to your board.

In a live conversation

Twenty minutes with a CWS engineer who closes these gaps for a living, free. They walk through your stage, answer the question it raises, and tell you plainly whether a paid audit is worth booking yet.

Guides

Guides for the AI systems you already run

Most AI security gaps are specific to the system running them. These guides cover the systems we see most, the vendors worth shortlisting, and the industries where the stakes are highest, all mapped to the same six dimensions.

Vendor security guides

Directory

AI security vendor directory

60 vendors in 11 categories, from runtime guardrails to AI red teaming, organized so you can shortlist by what you actually need.

Browse the directory

Compare vendors

By industry

How it works

How the AI Posture Check works

01

Answer up to five questions

Each question is chosen from what you answered before. Pick the answer closest to your reality and don't overthink it. The check only works if you answer with what is true today.

02

Watch your position move

Each answer moves a dot on the Posture Quadrant: program across, controls up. Hover an answer before you pick it to see where it lands.

03

Choose how your stage is delivered

Your stage, where you are and what moves you to the next stage, is sent to your work email or talked through live with a CWS engineer. The stage itself never shows on screen.

After the check

When you have a specific AI deployment to secure.

Beyond a self-reported stage, the Standard AI Posture Audit goes further: a senior CWS engineer reviews your named AI deployments, including prompt-injection and jailbreak testing against OWASP LLM Top 10 cases, as a scoped engagement for a fixed fee agreed on a call.

Standard AI Posture Audit · 2 weeks

Senior-engineer paid review of your specific AI deployments.

Fixed-fee, scoped on call. When you have specific AI deployments live and need to demonstrate diligence to your board, regulator, or customers.

Technical assessment of your named AI deployments
Structured review of prompt-injection and jailbreak risk against your AI deployments using OWASP LLM Top 10 test cases. Adversarial testing depth scales with engagement tier.
OWASP LLM Top 10, NIST AI RMF, and ISO 42001 mapping
Remediation roadmap with effort estimates
Executive-ready report
For channel partners

Share the Posture Check as a conversation starter.

If you are a reseller, distributor, or technology vendor, share the AI Posture Check with your clients as an AI readiness and governance conversation starter. CWS delivers under its own name through your relationship as the partner of record, credited to you as the referring partner throughout.

Talk to us about partnering
Questions

Frequently asked questions.

What is the AI Posture Check?

A free adaptive self-assessment of up to five questions that reads your AI security across six dimensions: governance, data, prompt, model, runtime, and vendor. You get your stage (Crawl, Walk, Run or Sprint), what moves you to the next one, and the framework behind each answer, delivered by email or in a live conversation with a CWS engineer.

Is the AI Posture Check a maturity model?

It is a placement on four maturity stages, not a full maturity model. Deeper instruments exist: the Cloud Security Alliance's AI Security Maturity Model, OWASP's AI Maturity Assessment, and the SANS AI security self-assessment. The Posture Check tells you which of those is worth picking up next.

How long does the Posture Check take?

A few minutes for most people. Faster if you know your environment well.

Does it ask about AI coding agents?

Yes. The governance dimension asks what AI coding agents and assistants are running on staff machines, what files, applications, and credentials they can reach, and how MCP servers and Skills are vetted before install.

What happens after I finish the assessment?

You choose how your stage is delivered: emailed to you with what moves you to the next stage, or talked through live with a CWS engineer. The stage is not shown on screen. CWS does not contact you beyond the delivery you chose.

How is the Posture Check different from a paid audit?

The free check is self-reported. A paid Standard Audit is delivered by a senior CWS engineer reviewing your actual AI deployments, including adversarial testing. The free check is calibration; the paid audit is verification.

Which frameworks does the Posture Check map to?

OWASP LLM Top 10, NIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS. Each question you're asked cites the framework it maps to, so you can trace every gap back to its source.

Ready when you are

Ready to find out where you stand?

Free, a few minutes, and your stage arrives the way you choose: by email, or live with a CWS engineer.