Infosec Standards now has a free, browser-only risk assessment tool

September 2, 2026

About: PCI DSS,HIPAA,SOC 2,CMMC

#site-updates

Most standards on this site ask for a documented risk assessment: HIPAA’s risk analysis, the risk assessment criteria in SOC 2, the Risk Assessment family in NIST SP 800-171 behind CMMC, and the organization-wide assessment PCI DSS assessors still expect alongside the newer targeted risk analyses. The first one is hard to do in a spreadsheet because the pieces are relational: assets, threat sources, threat events, vulnerabilities, and the same scenario repeated across many assets.

The new risk assessment tool walks a first-timer through that work in seven steps using NIST SP 800-30 vocabulary and five-level qualitative scales. It suggests common assets, threats, and scenarios so you are not starting from a blank page, scores likelihood and impact on a matrix you can adjust, and asks for a treatment decision on every risk above your acceptance threshold. The methodology page explains the method in plain language so an auditor can read it.

The risk assessment workspace on the review and export step. A sidebar lists the seven steps. The main pane shows a count of scenarios by risk level, a likelihood-and-impact heat map, and a register of scored scenarios with treatment decisions.
The review step: scenario counts, a heat map, and the register you take away.

What you leave with:

  • a JSON file you can reload to keep working or to start next year’s assessment from;
  • an Excel register with the scenarios, treatment plan, and methodology statement; and
  • a printable report with a heat map, register, and sign-off page.

Your assessment never leaves your browser. It is saved in the browser’s own storage and exported to files on your machine; there is no account and no upload. We count anonymous usage (which steps are reached, how many exports happen) and nothing else, as described on the privacy page.

If you would rather have practitioners do the assessment with you, the contact form reaches the Aeris Secure team.

#site-updates

← Back to news