← Dashboard
TechGuard Security Virtual CISO Platform

CMA Assessor Modules

Scope.Assess.Identify.Report.

These modules assess a business against a specific framework or regulation. Start with a Readiness Assessor to quickly gauge where an organization stands and whether a full review is warranted — then run the matching Full Assessor for a complete, evidence-based gap assessment and client-ready report. Results flow into the Cyber Maturity Advisor to build the overall risk picture.

Readiness Assessors
High-level assessments that quickly gauge a business’s readiness for a framework or regulation — and whether a full gap assessment is likely warranted.
Cybersecurity Risk Tolerance Assessor
Establish what an organization is actually willing to lose before assessing anything against a framework. Eighteen plain-language questions on money, downtime, oversight, and trust — no technical vocabulary — produce the acceptance thresholds that drive a risk register and POA&M, recovery time and recovery point anchors, a suggested insurance retention, and language for the minutes. Participants answer separately; the comparison view ranks where leadership disagrees.
Risk Governance · Fiduciary Decision Record · Multi-Respondent
AI Governance Readiness Assessment
Quickly determine how ready an organiation is to govern their AI security program and if a more in depth assessment is needed. Based on NIST RMF covering Govern, Map, Measure, and Manage functions for AI system risk and AI 600-1.
NIST AI RMF 2.0 + NIST AI 600-1
HIPAA compliance readiness assessment
Quickly determine how ready an organization is to comply with the HIPAA Security Rule and/or if a more in-depth assessment is needed. Includes administrative, physical, and technical requirements for healthcare organizations.
HIPAA · Security Rule
CMMC Level 1 Readiness Assessment
Quickly determine how ready an organization is to meet CMMC Level 1 and/or if a more in-depth assessment is needed. Covers the 15 basic safeguarding requirements of FAR 52.204-21 (the 17 CMMC Level 1 practices) for contractors that handle Federal Contract Information (FCI).
CMMC 2.0 Level 1 · FAR 52.204-21
CMMC Level 2 Readiness Assessment
Quickly determine how ready an organization is to meet CMMC Level 2 and/or if a more in-depth assessment is needed. Covers the 110 NIST SP 800-171 security requirements across 14 domains for contractors that handle Controlled Unclassified Information (CUI).
CMMC 2.0 Level 2 · NIST 800-171
Incident Response Readiness Assessment
Quickly determine how ready an entity is to respond to an information security incident. Covering plan documentation, roles, detection, containment, communication, and regulatory notification obligations.
IR · NIST 800-61 · SANS PICERL
Ohio HB 96 Readiness Assessment
Pre-engagement readiness check for Ohio political subdivisions against ORC §9.64 - statutory adoption, incident reporting (OCIC/AOS), ransom restriction, and the NIST CSF 2.0 / CIS Controls v8 IG2 program baseline.
ORC §9.64 · NIST CSF 2.0 · CIS v8 IG2
Full Assessors
Complete gap assessments against the full framework or regulation.
Full HIPAA Security Risk Assessment
Workbook-driven HIPAA Security Rule risk analysis under §164.308(a)(1)(ii)(A). Send the client the plain-language workbook, then upload the returned .xlsx to score all eight sections, build the risk register and POA&M, and generate executive, full, or custom reports. Section structure follows the HHS SRA Tool 3.6.1; DOL EBSA best practices are mapped throughout.
HIPAA §164.308 · HHS SRA Tool 3.6.1 · DOL EBSA · Risk Register · POA&M
Full AI Governance Gap Assessment
NIST AI RMF 1.0 gap assessment across Govern, Map, Measure, and Manage, plus the NIST AI 600-1 Generative AI risk profile.
NIST AI RMF 1.0 · NIST AI 600-1 · ISO 42001
NIST SP 800-171 Rev. 2 Full Gap Assessment
Assess for gaps in alignment with NIST 800-171 rev 2. For defense contractors and federal suppliers who handle controlled unclassified information.
NIST 800-171 Rev. 2 - CUI
GLBA-Aligned Security Program Full Gap Assesssent
CIS Controls v8 mapped to the NIST CSF 2.0 and the GLBA Safeguards Rule - coverage against current evidence for financial institutions and their service providers.
GLBA · NIST CSF 2.0 · CIS v8
HIPAA-Aligned Security Program Full Gap Assessment
One structured interview of 120 plain-English questions, assessed simultaneously against the HIPAA Security Rule, CIS Controls v8, NIST CSF 2.0, and the HHS Cybersecurity Performance Goals. Produces per-framework posture side by side, a coverage matrix naming every control no question reached, an auditor answer sheet tying each score to the exchange behind it, and a roadmap sequenced so one fix closes the most ground across all four frameworks at once.
HIPAA · CIS v8 IG1/IG2 · NIST CSF 2.0
Ohio HB 96 Aligned Security Program Full Gap Assessment
Upload the completed HB 96 Gap Assessment Workbook to produce a point-in-time gap assessment, an interactive check-listed remediation roadmap with owner/status tracking and a live completion score, an auto-generated risk register, and a client-ready report — mapped to ORC §9.64, CIS Controls v8, and NIST CSF 2.0.
ORC §9.64 · CIS v8 · NIST CSF 2.0 · Workbook-Driven