Everything you need to know about RateYourCyber assessments. No technical expertise required.
A cybersecurity assessment evaluates how well your organisation protects its data, systems, and people from security threats. RateYourCyber assessments measure your current security posture across multiple domains, compare you to industry benchmarks, and identify specific gaps to address.
Unlike traditional assessments that require expensive consultants, RateYourCyber assessments are designed to be completed by business leaders themselves - no technical background needed.
Assessment times vary by type:
You can save progress and return later if needed.
No. RateYourCyber assessments use plain English and are designed for business leaders, not IT specialists. Each question includes simple explanations of what we're asking and why it matters.
If you understand how your business operates, you can complete these assessments yourself.
No. RateYourCyber assessments are specifically designed so you don't need external consultants or in-house security experts to complete them.
Traditional security assessments cost between £15,000 and £50,000+ and require weeks of consultant time. RateYourCyber delivers the same strategic insights at a fraction of the cost, completed in minutes rather than weeks.
Of course, if you have IT staff or security professionals, they may provide helpful input - but they're not required.
After completing an assessment, you receive:
RateYourCyber offers five comprehensive assessments covering all aspects of organisational security:
8 domains • ~45 minutes
8 domains • ~40 minutes
7 domains • ~35 minutes
8 domains • ~40 minutes
6 domains • ~30 minutes
Your score is out of 1,000 points and indicates your security maturity level:
RateYourCyber compares your scores against industry benchmarks for your sector. We maintain benchmark data for Technology, Finance, Healthcare, Retail, Manufacturing, Education, Aerospace, and Non-profit sectors.
Your results show whether you're above or below average for each domain, helping you understand where you stand relative to peers.
Your results highlight domains where you score below industry average - these are your priority areas. We also identify "quick wins" - improvements that are relatively easy to implement but have significant impact.
Focus on closing gaps in critical areas first, then work toward optimisation.
ISO 27001, SOC 2, GDPR, NIS2, DORA, the NCSC CAF, NIST CSF 2.0, CIS Controls v8.1, IEC 62443, HIPAA, CMMC 2.0, NCA ECC, SACS-002, SAMA CSF, LFPDPPP, ISO 42001, ISO 22301, ISO 9001, COBIT 2019, ITIL 4, ESG reporting and financial crime compliance. Frameworks are included from the Enterprise Single tier upwards.
No. Evidence is held once against what it is, and counts towards every framework that asks for it. An approved access control policy, a completed internal audit or a training record satisfies the relevant requirement in each framework at the same time. Where you attach a document to one specific requirement, it can also carry across to the equivalent requirement in another framework, and the platform records who says the two correspond, since that is what an auditor will ask.
Your existing evidence carries forward. Because evidence is held against what it is rather than against a particular framework, a newly added framework starts partly evidenced by the work you have already done, and the platform shows which requirements it cannot evidence from your data so you know what still needs supplying.
Yes. The free assessment gives you a genuine evaluation of your cybersecurity posture with real scores and recommendations. No credit card required, no hidden catches.
The paid plans add additional assessments, detailed reports, industry benchmarking, and ongoing features.
Absolutely. We recommend reassessing quarterly or after significant changes to your security posture. This lets you track progress and demonstrate improvement to stakeholders.
Yes. We practice what we preach. Your data is encrypted in transit and at rest, access is strictly controlled, and we never share individual assessment data with third parties.
Yes. RateYourCyber is fully GDPR compliant. We only collect data necessary to provide the service, you can export or delete your data at any time, and we maintain appropriate technical and organisational measures.
Your assessment results include specific recommendations for each domain. Start with areas where you score below industry average, focus on quick wins first, then work on more complex improvements.
Many improvements don't require significant investment - they're about implementing proper processes and documentation.
Yes. RateYourCyber generates board-ready reports that communicate security posture in business terms. You can export PDFs, share links, and present findings without needing to translate technical jargon.
We recommend quarterly assessments to track progress and catch emerging gaps. You should also reassess after:
No technical expertise required. Complete your assessment in minutes.