Not the assessment methodology - this page tracks the status of the website itself: what's shipped and working, what's actively being built, and what's planned next. Last updated September 24, 2026.
Fully functional in the live version of this site today.
Rebuilt on a data-driven decision graph - sequenced team-structure questions, containerization/virtualization as its own independent branch, per-framework question injection across all eight supported frameworks, and a session-wide de-dup engine so no branch ever asks the same thing twice.
A dedicated question track following EC-Council's Adopt/Defend/Govern framework - scoping how AI actually shows up in your environment (licensed platforms, embedded vendor features, custom RAG apps), over-permissioned-retrieval and AI-generated-code review questions where they apply, and defenses against AI-powered social engineering (deepfake/voice-impersonation-aware training, out-of-band verification) for every organization, regardless of whether it has adopted AI itself. Partially fulfills the Cyber Threat Intelligence item below - AI-specific threat coverage is now real, not just planned.
A live, opt-in second pass on your completed results: checks your named vendors/products against CISA's KEV catalog and NVD's CVE database for anything current a fixed rule set can't know by nature, plus a look for patterns this specific answer combination raises beyond it. Clearly labeled as AI-generated - the deterministic report above it is already complete either way.
A "why this matters, and what to do now" expander under each compounding-risk flag and low-scoring priority item, mapping to a real MITRE ATT&CK technique plus a compensating control computed from your own answers.
Cross-answer flagging for dangerous combinations, not just per-question scoring.
Illustrative guidance for named products, entered via dropdown + "Other" across every vendor field in the questionnaire.
A real, programmatically-built PDF of your results - selectable/searchable text, not a screenshot.
8 incident runbooks plus 16 OWASP/AI-mapped attack-type playbooks, each with MITRE ATT&CK/ATLAS references and equal-depth, actionable steps.
Real critical cybersecurity incidents, each tied back to a specific gap this tool is built to catch.
A 59-term glossary and a sourced references page.
A narrative, in-order on-ramp for starting cybersecurity from zero - distinct from the Glossary's alphabetical lookup.
Real named methodologies (STRIDE, PASTA, attack trees, DREAD) for reasoning through an attack before it happens, plus practical forensics basics - order of volatility, evidence preservation, when to call in outside help - for reconstructing what happened after one does.
Daily-refreshed threat-landscape feed pulled from CISA's KEV catalog, NVD, and security RSS feeds, updated automatically - not a static snapshot.
Confirmed actively-exploited CVEs from CISA KEV, VulnCheck KEV, and ENISA's EU Vulnerability Database, scored by real-world exploitation likelihood via FIRST.org's EPSS, refreshed daily.
Live site search across every page, a mobile hamburger menu, and a real toggle-style theme switch.
Every page has a real, shareable URL - back/forward, bookmarking, and opening links in a new tab all work as expected.
Original SVG illustrations across the site, a Maturity Model comparison table, framework stamps, and custom CSS animations on the Maturity Model and Exploits pages.
Live at simplifiedcs.net via Netlify, auto-deployed from GitHub on every update.
Being actively built right now.
In-progress answers are saved to your browser's own local storage as you go - close the tab, close the browser, even restart the device, and resuming picks up where you left off, as long as it's the same browser on the same device. This is what's actively being built and hardened right now.
The submission mechanism is built and wired to Netlify Forms, but Netlify Forms is not currently enabled for this site at the account level - confirmed directly, not assumed - so a real submission likely isn't being captured yet. Worth enabling and testing with a real submission before calling this shipped.
Not yet started - scoped and intended, not yet onboarded.
Replacing today's session-only History with real, persistent storage, so completed assessment results are still there - and comparable over time - the next time you visit.
A securely-generated link to pick up an in-progress assessment from any device, complementing the current same-device browser save above - a future, more advanced capability layered on top of it, not a replacement for it.
A conversational assistant to help visitors navigate the site, answer cybersecurity basics questions, and potentially help fill out the assessment conversationally.
Longer-form original writing - the reasoning behind specific tool and framework choices, and lessons drawn from real incidents - separate from the existing Trends & News feed, which curates external sources rather than publishing original posts.
A structured, sequenced path for building cybersecurity knowledge over time, distinct from the Starter Guide (a one-time on-ramp) and the Glossary (lookup as needed, not a course).
A page highlighting other work outside SimplifiedCS itself, for visitors arriving through a portfolio context rather than looking for the assessment tool specifically.
Deeper, structured threat-intelligence analysis - threat actor behavior, campaign tracking, industry-specific context - beyond what the curated Trends & News feed currently provides. The AI Readiness & Governance track above already covers the AI-specific slice of this (prompt injection, AI-powered social engineering); this item is the broader, non-AI-specific threat-intel capability still ahead.
Letting IT administrators test their own employees against realistic phishing and social-engineering scenarios, turning the concept the Starter Guide already introduces under phishing simulation into an actual feature.