Rate your organisation's maturity against the standards that apply to you, see the gaps, and export something an auditor can read. One HTML file, no server, no accounts.
.pumapack and open it in PumaRisk to become a risk register, or PumaTracker to become tasks. Each consumer filters for what it can act on, so the assessment turns into a plan instead of a PDF.See the Method tab for how to run an assessment, and Keyboard for every shortcut.
A maturity self-assessment gives you a baseline and a roadmap, not a grade. The number is not the point; the gap between where you are and where the risk says you need to be is.
The maturity ladder traces back to CMMI. The frameworks set the bar: NIST CSF 2.0, SOC-CMM for security operations, and David Bianco's Hunting Maturity Model — all bundled here.
Every assessment, score, evidence note, and history snapshot is held in this browser's sessionStorage under the pumagrc2.* key prefix. Nothing is sent over the network. Closing the tab keeps your data; opening the file in a different browser, profile, or device shows no assessments.
Heads up. Clearing site data, using private/incognito mode, or losing the device erases everything. The browser is the database — back up regularly.
Use the Export button (download icon, topbar) for a full .pumapack backup — every workspace, every score, every history snapshot. Open the same pack in any sibling PumaWorx app for cross-app interop. Right-click an assessment tab (or ☰ → Settings on narrow screens) to also export:
This deletes every assessment, score, history snapshot, and preference under pumagrc2.* in this browser. It does not touch any .pumapack file you've exported.
Type DELETE EVERYTHING to confirm.
.pumapack.pumapack filePumaGRC2 is a lightweight, portable, offline GRC maturity assessment tool that runs entirely in your browser. It ships eighteen complete control catalogs with gap analysis, cross-framework mapping, and history snapshots.
This tool is provided as-is, with no warranties or guarantees. It is not professional advice. By using it you accept full responsibility for any outcomes that result from your use.
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
Choose which frameworks appear in the sidebar and cross-map. Assessment data is preserved when a framework is hidden.
Name your workspace and pick the frameworks you want to score. You can add or remove frameworks later from the sidebar gear or by right-clicking the assessment tab.
Capture the current assessment state for trend tracking.
This is an offline single-HTML app. No data goes to or from the internet. There is no server, no account, no sync, and no telemetry.
Your assessments live in your web browser's sessionStorage — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
If you clear site data, use a private/incognito window, switch browsers, or lose this device, your assessments are gone. Back up regularly via the Export button in the topbar — it produces a .pumapack backup. CSV, RTF and other reports are on the assessment tab's right-click menu.
Press ? any time for help and keyboard shortcuts.