Rate your organisation's maturity against the standards that apply to you, see the gaps, and export something an auditor can read. One HTML file, no server, no accounts.
Answer once, satisfy several — frameworks overlap enormously, and the cross-map shows each control's equivalents already carrying their own maturity colour. You can see at a glance that you have effectively answered a NIST control while filling in ISO. The second and third frameworks cost a fraction of the first.
Eighteen catalogues, 1,621 subcontrols — cybersecurity, federal/defense, industry compliance, privacy, AI governance, incident response and security operations. Enable any combination per workspace; you are not carrying HIPAA around because it shipped in the box.
Scores that survive contact with an auditor — every control takes evidence, a remediation plan, a priority, a compensating-control flag and a timestamped activity log. Maturity you cannot evidence is maturity you are imagining.
Nothing is more than one click deep — a cell in the heatmap, a row in the gap analysis, a chip in the cross-map: all of them deep-link straight into that control with its drawer open. Maturity and priority edit inline from the pill, without opening anything.
Findings leave as work — export a .pumapack and open it in PumaRisk to become a risk register, or PumaTracker to become tasks. Each consumer filters for what it can act on, so the assessment turns into a plan instead of a PDF.
Trend, not snapshot — history snapshots keep the maturity curve, which is the thing a board actually asks for.
Parallel assessments — a workspace per business unit, audit cycle or customer, each with its own enabled frameworks, scores and history.
See the Method tab for how to run an assessment, and Keyboard for every shortcut.
Running a self-assessment
A maturity self-assessment gives you a baseline and a roadmap, not a grade. The number is not the point; the gap between where you are and where the risk says you need to be is.
1 · Enable only what applies — turn on the frameworks you are actually held to. Start with one. Breadth before depth wastes the overlap you are about to exploit.
2 · Score current state, not aspiration — rate what is true and repeatable today, not what a draft policy says or what you intend next quarter. An honest 2 is more useful than an aspirational 4, because you can only plan from the truth.
3 · Put the proof in as you go — fill the evidence field while you still remember what it was. A score with nothing behind it will not survive an audit, and it quietly misleads you in the meantime. The activity log timestamps the rest.
4 · Set targets by risk — not every control needs to be a 5. Decide the level each domain warrants and stop there. Chasing uniform top scores burns effort where it does not move the needle.
5 · Reuse the answer — when you add the second framework, work from the cross-map. A control whose equivalents are already coloured is one you have effectively answered; confirm it rather than re-deriving it.
6 · Turn every gap into an owned action — the Gap Analysis and Heatmap say where you fall short; the remediation plan and priority say what happens about it. Then hand the findings off — risk-worthy ones to PumaRisk, task-worthy ones to PumaTracker — so they land somewhere that chases them.
7 · Snapshot before you change anything — history is what lets you show a trend rather than assert one.
The maturity ladder traces back to CMMI. The frameworks set the bar: NIST CSF 2.0, SOC-CMM for security operations, and David Bianco's Hunting Maturity Model — all bundled here.
Where your assessments live
Every assessment, score, evidence note, and history snapshot is held in this browser's localStorage under the pumagrc2.* key prefix. Nothing is sent over the network. Closing the tab keeps your data; opening the file in a different browser, profile, or device shows no assessments.
Heads up. Clearing site data, using private/incognito mode, or losing the device erases everything. The browser is the database — back up regularly.
Backing up
Use the Export button (cloud icon, topbar) for a full .pumapack backup — every workspace, every score, every history snapshot. Open the same pack in any sibling PumaWorx app for cross-app interop. Right-click an assessment tab (or ☰ → Settings on narrow screens) to also export:
Full report (Markdown) — every control with its evidence, remediation plan, notes, activity log, and cross-mapping references. Pipe through pandoc for PDF/DOCX, drop in a repo for auditor handoff.
Full report (RTF) — same content, Word-compatible.
CSV — flat controls + scores; round-trips through spreadsheet workflows.
Excel workbook (.xlsx) — a live workbook: maturity/priority dropdowns, a maturity heatmap, and a formula-driven Summary sheet that recomputes as you edit. Edit it and it stays a working assessment, not a snapshot.
JSON (raw) — the active assessment payload, no envelope.
Cross-map matrix CSV — full NIST CSF × 15-framework table with confidence inline.
Print / Save as PDF — browser print dialog with the print stylesheet.
Clear all local data
This deletes every assessment, score, history snapshot, and preference under pumagrc2.* in this browser. It does not touch any .pumapack file you've exported.
Type DELETE EVERYTHING to confirm.
Keyboard shortcuts
?
Open this help modal
Esc
Close overlay / cancel selection
⌘K / Ctrl-K
Command palette
⌘S / Ctrl-S
Export current workspace as .pumapack
⌘O / Ctrl-O
Import a .pumapack file
J / K
Next / previous control
0–5
Set maturity on focused control
Enter
Open / activate focused item
About PumaGRC2
PumaGRC2 is a lightweight, portable, offline GRC maturity assessment tool that runs entirely in your browser. It ships eighteen complete control catalogs with gap analysis, cross-framework mapping, and history snapshots.
This tool is provided as-is, with no warranties or guarantees. It is not professional advice. By using it you accept full responsibility for any outcomes that result from your use.
About PumaWorx
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
Choose which frameworks appear in the sidebar and cross-map. Assessment data is preserved when a framework is hidden.
Start an assessment
Name your workspace and pick the frameworks you want to score. You can add or remove frameworks later via the gear menu.
Save snapshot
Capture the current assessment state for trend tracking.
This is not a web app
This is an offline single-HTML app. No data goes to or from the internet. There is no server, no account, no sync, and no telemetry.
Your assessments live in your web browser's localStorage — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
If you clear site data, use a private/incognito window, switch browsers, or lose this device, your assessments are gone. Back up regularly via the Export button in the topbar — produces .pumapack, CSV, or RTF.