Start with free coverage visualization, explore 970+ security tools, then run a framework assessment to get a UCPA-ranked implementation plan.
Free With a FrameworkMapper Account
Use these free tools to understand your current security posture before committing to an assessment.
Select the security tools your organization uses. The Aggregator maps them against CIS Safeguards and shows you an interactive heat map of your coverage.
Launch Aggregator →Browse 970+ security products filtered by cost, implementation group, industry vertical, and market analyst coverage (Gartner & Forrester). Find what fills your gaps.
Launch ToolMapper →Import encrypted assessment backup files to view your results anywhere — no account required. Share with your team or auditor.
View Reports →Paid Assessments
Choose a framework, answer rubric-based questions, get a scored result with a prioritized remediation roadmap, and export a professional PDF report.
Choose a framework
Select from CIS Controls, CMMC, NIST CSF, NIST 800-53, HIPAA, GovRAMP, CJIS, or the Texas Cybersecurity Framework.
Complete the rubric assessment questions
For each question, select the rubric level that best describes your current state.
Review your scored results
See where you stand with a detailed breakdown by control category.
Get a prioritized implementation roadmap
UCPA-ranked controls tell you exactly what to fix first, second, and third.
Export PDF + encrypted backup
Share a professional report with leadership, auditors, or clients.
Available Frameworks
CIS Controls
v8 · IG1 / IG2 / IG3
CMMC Level 1
17 practices
CMMC Level 2
110 practices
HIPAA
Security Rule
NIST CSF v2
6 functions
NIST 800-53
Rev 5
GovRAMP
State cloud authorization
NIST 800-171
110 requirements
Texas CSF
TX DIR framework
A Two-Algorithm Scoring Stack
Once you've taken an assessment, two algorithms run against your results. UCPA prioritizes which controls to implement. The Tool Trust Index scores which tools to actually procure. Both are deterministic, vertical-aware, and fully explainable.
A seven-factor weighted scoring model: threat exposure, dependency depth, effort-to-value ratio, blast radius, regulatory weight, coverage breadth, and your specific asset exposure. Each factor is tuned per vertical.
"Implement MFA on privileged accounts first — it scores 92 in your vertical."
Read UCPA deep diveFour additive trust signals (analyst placement, FedRAMP/GovRAMP, FIPS 140, CSA STAR) combined with a KEV-exposure multiplier. Vertical-aware signal defaults; no vendor self-attestation accepted.
"Of these four MFA tools, three are Trusted and one is on KEV with no patch — we don't recommend it."
Read TTI deep diveBuilt For You
Three audiences. One platform.
Assess your own security posture against multiple frameworks. Get a prioritized roadmap without an enterprise GRC budget.
Explore Free Tools →Deliver assessments at scale for your clients. Branded PDF reports, multi-framework support, and team collaboration.
Learn About Partnering →Get your tools mapped to compliance frameworks and listed in the ToolMapper catalog.
Coming SoonStart free with the Coverage Aggregator or jump straight to a framework assessment for a prioritized implementation roadmap.