Site Status

Roadmap

Not the assessment methodology - this page tracks the status of the website itself: what's shipped and working, what's actively being built, and what's planned next. Last updated September 24, 2026.

Shipped & accessible now

Fully functional in the live version of this site today.

Adaptive Assessment Engine

Rebuilt on a data-driven decision graph - sequenced team-structure questions, containerization/virtualization as its own independent branch, per-framework question injection across all eight supported frameworks, and a session-wide de-dup engine so no branch ever asks the same thing twice.

AI Readiness & Governance Track

A dedicated question track following EC-Council's Adopt/Defend/Govern framework - scoping how AI actually shows up in your environment (licensed platforms, embedded vendor features, custom RAG apps), over-permissioned-retrieval and AI-generated-code review questions where they apply, and defenses against AI-powered social engineering (deepfake/voice-impersonation-aware training, out-of-band verification) for every organization, regardless of whether it has adopted AI itself. Partially fulfills the Cyber Threat Intelligence item below - AI-specific threat coverage is now real, not just planned.

AI-Enhanced Insights

A live, opt-in second pass on your completed results: checks your named vendors/products against CISA's KEV catalog and NVD's CVE database for anything current a fixed rule set can't know by nature, plus a look for patterns this specific answer combination raises beyond it. Clearly labeled as AI-generated - the deterministic report above it is already complete either way.

MITRE ATT&CK Guidance Panel

A "why this matters, and what to do now" expander under each compounding-risk flag and low-scoring priority item, mapping to a real MITRE ATT&CK technique plus a compensating control computed from your own answers.

Compounding-Risk Detection

Cross-answer flagging for dangerous combinations, not just per-question scoring.

Vendor-Aware Mitigation Notes

Illustrative guidance for named products, entered via dropdown + "Other" across every vendor field in the questionnaire.

PDF Report Export

A real, programmatically-built PDF of your results - selectable/searchable text, not a screenshot.

Runbooks & Playbooks

8 incident runbooks plus 16 OWASP/AI-mapped attack-type playbooks, each with MITRE ATT&CK/ATLAS references and equal-depth, actionable steps.

Case Studies

Real critical cybersecurity incidents, each tied back to a specific gap this tool is built to catch.

Glossary & References

A 59-term glossary and a sourced references page.

Starter Guide

A narrative, in-order on-ramp for starting cybersecurity from zero - distinct from the Glossary's alphabetical lookup.

Threat Modeling & Forensics

Real named methodologies (STRIDE, PASTA, attack trees, DREAD) for reasoning through an attack before it happens, plus practical forensics basics - order of volatility, evidence preservation, when to call in outside help - for reconstructing what happened after one does.

Live Trends & News

Daily-refreshed threat-landscape feed pulled from CISA's KEV catalog, NVD, and security RSS feeds, updated automatically - not a static snapshot.

Exploits Page

Confirmed actively-exploited CVEs from CISA KEV, VulnCheck KEV, and ENISA's EU Vulnerability Database, scored by real-world exploitation likelihood via FIRST.org's EPSS, refreshed daily.

Header, Navigation & Site Search

Live site search across every page, a mobile hamburger menu, and a real toggle-style theme switch.

Real Client-Side Routing

Every page has a real, shareable URL - back/forward, bookmarking, and opening links in a new tab all work as expected.

Custom Visual System & Animations

Original SVG illustrations across the site, a Maturity Model comparison table, framework stamps, and custom CSS animations on the Maturity Model and Exploits pages.

Hosting & Domain

Live at simplifiedcs.net via Netlify, auto-deployed from GitHub on every update.

Work in progress

Being actively built right now.

In progress

Save & Resume (same browser)

In-progress answers are saved to your browser's own local storage as you go - close the tab, close the browser, even restart the device, and resuming picks up where you left off, as long as it's the same browser on the same device. This is what's actively being built and hardened right now.

In progress

Feedback Form

The submission mechanism is built and wired to Netlify Forms, but Netlify Forms is not currently enabled for this site at the account level - confirmed directly, not assumed - so a real submission likely isn't being captured yet. Worth enabling and testing with a real submission before calling this shipped.

Planned / ideation

Not yet started - scoped and intended, not yet onboarded.

Planned

Persistent History & Score Tracking

Replacing today's session-only History with real, persistent storage, so completed assessment results are still there - and comparable over time - the next time you visit.

Planned

Cross-Device Resume

A securely-generated link to pick up an in-progress assessment from any device, complementing the current same-device browser save above - a future, more advanced capability layered on top of it, not a replacement for it.

Planned

Chatbot Assistant

A conversational assistant to help visitors navigate the site, answer cybersecurity basics questions, and potentially help fill out the assessment conversationally.

Planned

Blog

Longer-form original writing - the reasoning behind specific tool and framework choices, and lessons drawn from real incidents - separate from the existing Trends & News feed, which curates external sources rather than publishing original posts.

Planned

Learning

A structured, sequenced path for building cybersecurity knowledge over time, distinct from the Starter Guide (a one-time on-ramp) and the Glossary (lookup as needed, not a course).

Planned

Personal Projects

A page highlighting other work outside SimplifiedCS itself, for visitors arriving through a portfolio context rather than looking for the assessment tool specifically.

Planned

Cyber Threat Intelligence

Deeper, structured threat-intelligence analysis - threat actor behavior, campaign tracking, industry-specific context - beyond what the curated Trends & News feed currently provides. The AI Readiness & Governance track above already covers the AI-specific slice of this (prompt injection, AI-powered social engineering); this item is the broader, non-AI-specific threat-intel capability still ahead.

Planned

Social Engineering Simulation Tools

Letting IT administrators test their own employees against realistic phishing and social-engineering scenarios, turning the concept the Starter Guide already introduces under phishing simulation into an actual feature.