Tools

What I use with my clients, open to everyone.

Cybersecurity and compliance self-assessments you can use right now. Free, no sign-up and no data left anywhere: everything runs in your browser.

From the community, for the community

Available

Pick your tool

Each one answers a question I get asked over and over. If something is missing, tell me and I will build it.

Available

ISO/IEC 42001 checklist: readiness to manage AI

Answer 24 questions on context, governance, risk, impact, data, lifecycle and improvement. Get an indicative score across eight areas, concrete priorities and a downloadable PDF report.

ISO 42001 AI governance Self-assessment PDF report
Open tool
Available

NIS2 checklist for companies in Spain

Does the NIS2 Directive apply to you, and how mature are you really? Check whether you are in scope under Annexes I and II, assess 16 controls mapped to Articles 20, 21 and 23, and download a PDF report with your prioritised gaps. It is built around the Spanish transposition context, so the scope test reasons about Spain.

NIS2 Compliance Self-assessment PDF report
Open tool
Available

Purview: Capabilities and licensing

Pick the Microsoft 365 plan you have and instantly see which Microsoft Purview capabilities it covers and which are missing. Nineteen capabilities, nine plans, and for anything missing it tells you which plan unlocks it.

Microsoft 365 Purview Licensing Self-assessment
Open tool
Available

Basic VRM Form: supplier security questionnaires

Tier the supplier, tick what they have access to and keep the questions that matter: mandatory ones, plus those triggered by criticality and applicability. Each carries its control in ISO 27001, NIST CSF 2.0, ENS, TISAX, GDPR, the AI Act and ISO 42001. You download a PDF with fillable fields for the supplier to answer.

Suppliers TPRM Supply chain Fillable PDF
Open tool
Downloadable · Excel

Third-party inventory template

The spreadsheet every supplier programme starts from: nineteen columns in the order of the method, dropdown lists, tiering colour-coded by criticality and an automatic counter per tier. No macros, no sign-up and nothing sent anywhere. This one is in English.

Inventory Tiering TPRM Excel
Download template
Coming soon

ISO 27001 self-assessment

The same approach applied to Annex A: where you stand today, what is missing to get certified and how much effort really sits behind each control.

ISO 27001 Annex A Certification
Coming soon

Incident cost calculator

To take the conversation that actually moves budgets to your board: what a day of downtime costs in your company, using your numbers rather than statistics from a foreign report.

Continuity Impact analysis Board
The deal

How these tools are built

"From the community, for the community" is not a nice slogan for asking you to hand over your email in exchange for a PDF. These are the rules I build them by, and you can verify every one of them.

No sign-up

No login form, no email wall, no "leave us your details to see your result". You come in and you use it.

No data sent

Everything is calculated in your browser. Neither your answers nor the report leave your device: there is no server to receive them.

No cookies, no tracking

No cookies, no analytics, no third-party resources. Fonts are served from my own domain.

Sources in plain sight

Every question cites the article it comes from, with a link to the official text. If something does not add up, you can go and check it.

Suggest a tool Read the blog