Platform maturity scorecard: where does your infrastructure stand?
Ten control areas. A radar chart. Your top three gaps. No account required.
For each area, drag the slider to reflect your current state across all active cloud providers.
Identity consistency
Any engineer can prove what they deployed and when, across all providers.
12345
AbsentNetwork clarity
Traffic paths between providers and to the internet are documented and enforced.
12345
AbsentIaC coverage
All production infrastructure is version-controlled and reproducible without manual steps.
12345
AbsentObservability
Every production service has a named owner, a log destination, and an alert path.
12345
AbsentCost visibility
You can attribute spend to a team or project within 24 hours, on any provider.
12345
AbsentSecurity baseline
Every host and service meets a written, automated baseline before it reaches production.
12345
AbsentSecret hygiene
No long-lived credentials exist in code, images, or config files.
12345
AbsentIncident readiness
Your team can respond to a production incident without needing the engineer who built it.
12345
AbsentCompliance posture
You can produce an audit trail for access and change events within 1 business day.
12345
AbsentDecommission discipline
Retired workloads and access are removed within a defined window, not left to drift.
12345
AbsentYour Scorecard
Overall maturity
| Control area | Score | Maturity level |
|---|---|---|
| Identity consistency | 1 | Absent |
| Network clarity | 1 | Absent |
| IaC coverage | 1 | Absent |
| Observability | 1 | Absent |
| Cost visibility | 1 | Absent |
| Security baseline | 1 | Absent |
| Secret hygiene | 1 | Absent |
| Incident readiness | 1 | Absent |
| Compliance posture | 1 | Absent |
| Decommission discipline | 1 | Absent |
Your top 3 priorities
What good looks like
- A central IdP federated to all active cloud providers.
- Every human access entry has a named owner and a review date.
- Service accounts use OIDC or provider-native workload identity. No long-lived keys.
- Deprovisioning a departing engineer takes under 10 minutes.
- Access reviews on a defined cadence (quarterly minimum for production).
- A network diagram exists, is version-controlled, and matches what is deployed.
- Egress from production goes through a controlled path, not directly from compute.
- Cross-environment traffic requires explicit configuration, not shared networking.
- Private endpoints are used for managed services in production.
- Security group and firewall rules have named owners and are reviewed on change.
- Zero production infrastructure was provisioned outside a tracked change.
- New environments can be stood up from code without asking the person who built production.
- State files are remote, locked, and access-controlled.
- Module interfaces are standardised across providers.
- CI runs terraform plan and requires approval before apply.
- Every service in production has a named on-call owner.
- Logs land in a queryable, retained store (not just the instance).
- At least one alert per service would wake someone up during an incident.
- You can answer "is this service healthy now?" without SSH-ing into the host.
- Log retention meets your compliance requirement (90 days minimum).
- Every resource has a team and environment tag, enforced at provisioning.
- A daily or weekly cost report broken down by team, not just by account.
- Budget alerts fire before overspend happens, not after the invoice arrives.
- Idle and untagged resources are reported with a named owner to chase.
- Commitment and reservation spend is reviewed against actual usage on a defined cadence.
- A written baseline exists: no root SSH, encrypted at rest, no public ports without justification.
- The baseline is tested automatically in CI, not checked manually before a release.
- CIS benchmark enabled on all active providers with findings reviewed weekly.
- No long-lived credentials exist in code repositories, CI secrets, or images.
- Vulnerability scanning runs on a schedule, not just at initial deployment.
- Secret scanning runs in CI and blocks merges on detected credentials.
- All application secrets are fetched at runtime from a managed secret store.
- No IAM access keys exist for human users. All human access uses federated identity.
- Service accounts use OIDC or workload identity. No manually-rotated keys.
- You can rotate any secret without redeploying an application or rebuilding an image.
- Every production service has a runbook written by someone other than the primary engineer.
- The on-call rotation includes at least two people per service.
- Runbooks are tested at least once per quarter.
- Alerts route to a single on-call platform, not individual inboxes.
- Post-incident reviews are written within 48 hours and stored in a searchable location.
- Management audit logs are enabled on all providers and retained for at least 1 year.
- Logs are stored in an account that production workloads cannot modify.
- You can answer who changed this resource and when in under 30 minutes.
- For regulated environments: audit logs feed a SIEM and are reviewed on a schedule.
- Compliance framework controls are mapped to implemented controls, not assumptions.
- Every environment stood up has a named owner and expected end date.
- Offboarded engineers have all cloud access removed within 24 hours.
- Unused resources are reported weekly.
- Old environments are not kept just in case. Data is backed up, then torn down.
- Decommission is a tracked work item, not an afterthought.
Get in touch
Send a note to start a conversation, or reach out directly by email.