Start here
Twelve questions. About four minutes. At the end you will know where the gaps in your security program are — which is a different thing from knowing how to close them, and a useful thing to know first.
Nothing you enter here is sent anywhere. This runs entirely in your browser. There is no form submission, no account, no cookie, no analytics on your answers, and no “enter your email to see your results.” When you close the tab your answers are gone. It would be a strange thing to write a book about protecting client data and then harvest yours in exchange for a quiz score.
Answer honestly, and answer from memory. If you have to go and look something up, the answer is “not sure” — that is a real finding, not a failure of the quiz. A plan nobody can recall under pressure is not doing its job on the day it matters.
Where you stand
Nothing came up. That is unusual, and worth two cautions. First, twelve questions cannot cover a rule with nine program elements — this check is a smoke test, not an audit. Second, a program that passes today goes stale on its own: the requirements move, the standards get withdrawn, and staff turn over.
What this check does not tell you. It shows you where the gaps are. It does not tell you what order to fix them in, what “good enough” looks like for a firm your size, which requirements you may be excepted from, or what evidence to keep so you can show the work later. Those are judgment calls, and they are what the book is for.
This is a self-assessment, not a compliance determination. No website can tell you whether you are compliant, and any that offers to is selling something.