Assess Your SDLC and Kubernetes Maturity Yourself — Offline, Audit-Ready, in Days
As a CISO in a regulated company, you know the question from every steering committee: How secure is our software supply chain really — and where does our Kubernetes environment stand? The honest answer is often: there is no shared, reliable picture. Development, the platform team, and security each hold partial knowledge, but no one has brought together the maturity across the entire software development lifecycle (SDLC) and the runtime environment.
This article shows how to close that gap — with a structured, offline-capable self-assessment aligned with the CIS Benchmarks and BSI IT-Grundschutz. ZERODOTFIVE's SDLC & Kubernetes Security Self-Check serves as the common thread — we use it to explain the method.
The problem: no reliable overall picture
Most security assessments fail not for lack of tools, but for lack of structure. There are scan results here, cluster configurations there, and a gut feeling in the leadership circle. What is missing is a shared scale that makes SDLC and Kubernetes comparable through one language.
Regulatory pressure makes this gap expensive. With the NIS2 transposition through the BSIG (§30), roughly 29,500 companies in Germany are directly obliged to implement risk management measures — including requirements for supply chain security, for secure development with vulnerability management, and for assessing the effectiveness of measures. It is precisely these three points that can be neither prioritized nor demonstrated without structured maturity transparency.
Why offline matters: data sovereignty as a compliance argument
A security assessment in which configuration details, cluster topologies, or vulnerability lists flow to an external service is often itself a risk in regulated contexts. That is why offline operation is not a technical detail but a matter of trust: the self-check runs entirely locally in the browser, with no backend and no telemetry. None of your answers leave the company.
For you as a CISO, this means you can run the check even with sensitive findings without first initiating a data processing agreement or a privacy review. The assessment takes place where the responsibility lies — in-house.
The maturity model: 64 controls, levels 0 to 4
The self-check consists of 64 weighted controls. You rate each control on a maturity scale from 0 to 4:
- 0 — not present
- 1 — ad hoc, irregular
- 2 — defined, but inconsistent
- 3 — standardized and practiced
- 4 — measured and continuously improved
The weighting is decisive: not every control carries the same weight. The risk contribution of a gap follows the formula (4 − maturity level) × weight. A critical control at maturity level 1 thus produces a significantly higher risk contribution than a secondary control at the same level. The result is not a mere percentage, but a list sorted by risk — the basis for prioritization instead of a scattergun approach.

The SDLC side: securing the supply chain
The SDLC side covers everything that happens between commit and deployment: source code management, dependencies, build integrity, secrets handling, and the inspection of container images.
A concrete example of a control is automated image scanning. Tools such as the freely available Trivy inspect container images for known vulnerabilities, misconfigurations, and exposed secrets — ideally as a mandatory step in the CI/CD pipeline, not as an occasional manual run. The maturity question here is not "Do we use a scanner?" but: Does the scan run on every build, does it block critical findings, and is the result documented in a traceable way? This distinction is exactly what separates maturity level 1 from level 3.
The Kubernetes side: policy enforcement instead of trust
On the runtime side, what matters is whether your cluster configuration follows recognized hardening guidelines — and whether deviations are technically prevented or merely noticed after the fact.
Here, policy enforcement is the key control. An admission controller such as Kyverno enforces policies before a resource even lands in the cluster — for example, prohibiting privileged containers or requiring resource limits. The fact that Kyverno reached CNCF "graduated" project status in March 2026 underscores the maturity of this approach. Again, maturity counts: are policies only recommended, warned about, or actually enforced? The self-check maps this gradation along the relevant CIS Benchmark topics.
Standards alignment: BSI IT-Grundschutz and CIS Benchmarks
The value of a self-check stands or falls with how well it connects to recognized standards. The controls dock onto two frameworks:
- CIS Kubernetes Benchmark — the de facto reference for hardening Kubernetes clusters, published by the Center for Internet Security.
- BSI IT-Grundschutz — in particular the modules APP.4.4 (Kubernetes) and SYS.1.6 (Container).
Beyond that, the controls reference the relevant obligations from NIS2/§30 BSIG as well as ISO 27001:2022. This lets you not only communicate a result internally, but map it directly against the requirements by which you are already measured.
From result to decision
At the end of the check stands an exportable report. It serves two purposes at once: it prioritizes by risk contribution — you immediately see which gaps offer the greatest leverage — and it documents the current state in an audit-ready manner. This turns a snapshot into a solid basis for decisions on budget, roadmap, and the obligation to provide evidence to regulators and auditors.
An honest classification is part of this: a self-check is a structured self-declaration, not an external audit. It replaces neither an independent review nor continuous monitoring — it gives you, in days rather than months, the shared picture on the basis of which you can commission both in a targeted way. And because it is a snapshot, the check only unfolds its value through repetition: as a recurring maturity measurement point over time.
Next step
Start the SDLC & Kubernetes Security Self-Check directly — offline, without registration, with your team in a workshop of just a few hours. If you then want to turn the result into a prioritized action plan, arrange an initial consultation or write to kontakt@zerodotfive.com.
offline · no registration · exportable report