# Gradum — Full Content for AI Retrieval > Concatenated, plaintext-friendly summary of every public page on https://gradum.io. Generated to help AI retrieval engines (ChatGPT search, Perplexity, Claude, Google AI Overviews, Apple Intelligence) ground their answers about Gradum. Operator: Siriustech SRL · Stejerisului 30H, 500122 Brașov, România · Trade Register no. J2025065962001 Founder: Harald Reisinger Contact: support@gradum.io · office@gradum.io B2B only. Service: https://app.gradum.io ---- ## / — The Smart Platform for Maturity Assessments Headline: The Smart Platform for Maturity Assessments. Subheadline: Ditch the complex spreadsheets. Gradum provides a modern, collaborative, AI-powered platform for running maturity assessments — pick a model, invite your team, get instant insights and presentation-ready reports. The Problem: Static spreadsheets, scattered comments, version conflicts, and weeks lost compiling results. Most maturity assessments today still happen in Excel templates that nobody owns and nobody trusts. The Solution: Gradum turns every assessment into a live, multi-user collaboration. Real-time editing, AI-driven recommendations, multi-language interface, and one-click export to a polished report. How it works (3 steps): 1. Choose Your Model — select from industry-vetted frameworks (SOC-CMM, NIST CSF, ESG/CSRD, DORA, EU AI Act, CIS Controls, and more). 2. Assess Collaboratively — invite users, assign tasks, complete in a multi-language interface, work with team or clients in perfect sync. 3. Gain AI-Powered Insights — instantly visualize results; built-in AI provides actionable recommendations and clear, boardroom-ready reports. Why maturity assessments matter: - Strategic Alignment of capabilities to business objectives. - Resource Optimization (invest where it moves the needle). - Stakeholder Confidence (transparent measurement). - Continuous Improvement (clear roadmap for growth). - Risk Reduction (find blind spots before they bite). - Competitive Advantage (outpace competitors on the processes that deliver value). For Model Creators: turn your framework into a marketplace product. Reach a global audience and earn a fixed fee per assessment. ---- ## /features — Powerful Features Designed for Clarity and Impact Toolkit: 4 categories — Collaboration & Workflow, Analysis & Intelligence, Reporting & Delivery, Platform & Ecosystem. Collaboration & Workflow: - Real-Time Multi-User Collaboration: see who's editing, leave comments, resolve disagreements, ship the assessment together. - Intuitive UI: built for non-experts. Anyone on the team can contribute without training. Analysis & Intelligence: - AI-Powered Recommendations: contextual suggestions ranked by impact, with the reasoning shown. - Dynamic Dashboards: drill from headline scores to specific dimensions and questions. Reporting & Delivery: - Professional Report Generation: one-click export to PDF/Word with brand-consistent layout. - Data Export: CSV / JSON / structured exports for integration with BI tools. Platform & Ecosystem: - Multi-Language Support: full UI and content in EN/DE/ES/FR/IT, with AI-translated model content where authors permit. - Maturity Model Marketplace: a growing library of industry-vetted models published by experts and consultancies. Coming soon: trend analytics over time, custom integrations, deeper AI explainability. ---- ## /maturity-models — The Right Framework for Every Ambition Browse industry-vetted maturity and capability models. Every model below can be run directly on Gradum — online, collaboratively, and in real time with your whole team, instead of a static spreadsheet or PDF. Each assessment includes AI-assisted recommendations ranked by impact (with the reasoning shown), dynamic dashboards that drill from headline scores down to individual questions, and one-click export to boardroom-ready reports (PDF/Word). Available in English, German, Spanish, French, and Italian. The library currently includes 28 models: - CBN RCSF Cybersecurity Compliance Maturity Assessment — This assessment helps Financial Institutions and FinTechs operating in Nigeria evaluate cybersecurity alignment with the Central Bank of Nigeria Risk-Based Cybersecurity Framework. - EU AI Act Maturity Model: A Strategic Roadmap to Trustworthy AI — The EU AI Act is no longer a distant possibility—it is an operational reality. The Gradum.io EU AI Act Maturity Model is the definitive framework for organizations to translate complex legal obligations into clear, measu… - Sales Excellence Quick Check — Multi-Domain Sales Maturity Assessment — A pragmatic, hyper-professional maturity assessment of the modern B2B Revenue Engine. - ESG EU CSRD Readiness Navigator: ESRS-Aligned Regulatory Maturity Model — Built for the EU Corporate Sustainability Reporting Directive, this maturity model operationalizes ESRS-aligned requirements across four pillars—Governance & Strategy, Double Materiality, ESRS Data Management & Reporting… - NIST CSF 2.0 Capability Maturity Model: Risk-Based Roadmap & Benchmark — This maturity model operationalizes NIST CSF 2.0 across six Functions—Govern, Identify, Protect, Detect, Respond, Recover—mapped to Categories and Subcategories as Domains → Aspects → Questions. - EU ESG CSDDD Due Diligence Maturity Model: From Policy to Proof — Anchored to EU CSDDD articles and built atop your Unified Core ESG Model, this maturity model assesses due-diligence capability across governance, salience and impact identification, prevention/mitigation, stakeholder en… - CAF 4.0 Model for Cyber Essentials and Cyber Essentials Plus — This model enables UK organisations to assess and evidence readiness for Cyber Essentials and Cyber Essentials Plus using the four Objectives and fourteen Principles of the Cyber Assessment Framework 4.0. - ISO/IEC 27701 & GDPR Privacy Maturity Model — A comprehensive, cross-industry maturity model designed to evaluate an organization's Privacy Information Management System (PIMS) against ISO/IEC 27701 and the EU General Data Protection Regulation (GDPR). - ESG General Maturity Model — Harmonized Baseline, Peer Benchmarking, Actionable Roadmap — Gradum.io’s ESG General Maturity Model unifies leading frameworks into a single, practitioner-grade baseline. - C2M2 MIL-Aligned Cyber Maturity Model for Energy & Critical Infrastructure — Built on the U.S. Department of Energy’s C2M2, this model structures cybersecurity capability across OT and IT for energy and other critical infrastructure operators. - IT Health Check — Pragmatic CIO Maturity Assessment — A pragmatic, business-aligned IT maturity assessment built for the Pragmatic Leader focused on value, stability, and speed. - ISO/IEC 27001 ISMS Maturity Model: From Compliance to Operational Excellence — Built on ISO/IEC 27001, this ISMS Maturity Model maps clauses 4–10 and Annex A (A.5–A.8) into three levels—Foundational, Managed, Optimized/Proactive—covering context, leadership, planning, operations, performance, and i… - ISO/IEC 42001 AI Management System Maturity Model — A cross-industry maturity model designed to help organizations assess and improve the effectiveness of their AI management system in alignment with ISO/IEC 42001. - Cloud Security Maturity Model (CSA CCM Aligned) — A cross-industry cloud security maturity model aligned to the Cloud Security Alliance Cloud Controls Matrix (CSA CCM). - NIST SP 800-171 / CMMC 2.0 Quick Check (US DIB) — A quick-check maturity assessment of NIST SP 800-171 Rev 2 implementation for the US Defense Industrial Base, aligned with CMMC 2.0 Levels 1, 2, and 3. - CIS Controls v8 Maturity Navigator (IG1–IG3 Operational Assessment) — Built on CIS Controls v8, this maturity model operationalizes the three Implementation Groups (IG1–IG3) into measurable safeguards, control owners, evidence expectations, and remediation workflows. - Cyber Essentials (UK) — Multi-Dimensional Maturity Assessment — A deep, multi-dimensional maturity assessment built on the UK Cyber Essentials 'Requirements for IT Infrastructure' v3.3 (April 2026, NCSC/IASME). - OWASP ASVS 5 Unified AppSec Maturity: From Baseline to Resilience — Built on OWASP ASVS 5, this unified model maps the 17 chapters to Domains→Aspects→Questions and inherits L1–L3 as capability outcomes. - GDPR Capability Maturity Model: From Baseline Compliance to Proactive Trust — Built from the GDPR’s 99 articles, this model translates legal obligations into a practical Domains→Aspects framework with three capability levels: Foundational, Managed, and Optimized. - DORA Resilience Navigator — Level 1–3 Capability Maturity Model — This DORA Maturity Model translates the EU’s Digital Operational Resilience Act into an actionable L1–L2–L3 capability roadmap across ICT risk, third-party risk, incident management, resilience testing, and information-s… - HIPAA Extensive — Covered Entities — An extensive HIPAA maturity assessment model for Covered Entities aligned to the currently in-force HIPAA Privacy, Security, and Breach Notification Rules. - HIPAA Extensive — Business Associates — An extensive HIPAA maturity assessment model for Business Associates aligned to the currently in-force HIPAA Privacy, Security, and Breach Notification Rules. - NIS2 Capability & Resilience Maturity Model (L1–L3) — The NIS2 Maturity Model translates EU legal obligations into an actionable capability roadmap across ten domains and twenty-four aspects. - NIST SP 800-53 Rev. 5 Security & Privacy Controls Navigator — A multi-dimensional maturity assessment of NIST Special Publication 800-53 Revision 5. - Cyber Security Health Check — The Gradum.io Cyber Security Health Check Model is the antidote to "Security Theater." In an era where organizations pass audits yet still get breached, this model digs deeper than standard compliance checklists. - SOC-CMM Basic — The SOC Capability Maturity Model (SOC-CMM), created by Rob van Os, is the global de facto standard for measuring and improving the maturity and capabilities of Security Operations Centers. - SOC Maturity Framework 360 (SOC360) — SOC Maturity Framework 360 (SOC360) is a multi-dimensional assessment for Security Operations Centers that fuses governance, people, process, technology, services, and a dedicated Risk Integration domain. - SOC-CMM Advanced — The SOC Capability Maturity Model (SOC-CMM), created by Rob van Os, is the global de facto standard for measuring and improving the maturity and capabilities of Security Operations Centers. Each model: domains and dimensions, evaluation factors, ideal-for guidance, AI-driven recommendations, multilingual content where authors opt in. ---- ## /for-creators — Monetize Your Maturity Model. Transform Your Framework. The old way (static document): limited reach, no revenue, manual scoring, hard to keep current. The Gradum way: convert your framework into an interactive tool, distribute on a global B2B platform, earn a fixed fee per assessment, focus on expertise — Gradum handles the technology. Process (4 steps): Upload your framework → Onboarding & co-design → We build it on Gradum → You earn revenue every time it is used. Benefits: - Monetize: fixed fee per assessment, predictable economics. - Reach: global audience of professionals already using Gradum. - Brand: positioned as expert author, with credit on every assessment. - Focus: stop maintaining Excel; spend time refining the framework. Partnership terms: ownership of the framework stays with the author; Gradum gets a license to host and operate; rights are fully reversible; compensation is transparent. Application: book a 30-minute introduction call (Calendly) or email sales@gradum.io. FAQ: covers IP, exclusivity, payouts, internationalisation, and timeline to launch. ---- ## /pricing — Choose the perfect plan for you Currency: USD or EUR (auto-detected by timezone, switchable). All CTAs go to https://app.gradum.io/sign-up. Two plan families: - Enterprise (one-time, per project): pay for a defined number of assessments, validity in months, results stored for a defined period. - Consultancy (subscription): recurring monthly/yearly access for ongoing work, unlimited within the plan's quotas. Each plan card discloses: assessments included, users included, storage period, AI recommendations on/off, validity period, tax behaviour (inclusive/exclusive). Custom plan: contact sales@gradum.io for tailored quotas, dedicated support, or private model deployments. FAQ: covers refunds, plan upgrades, currency switching, and tax handling for EU vs non-EU customers. ---- ## /support — Contact Support Book a 30-minute introduction or technical demo via Calendly inline widget on the page. For self-service answers (how-tos, FAQs, troubleshooting), see the public knowledge base at https://blog.gradum.io/support. ---- ## /terms — Terms & Conditions (effective 2025-10-01) B2B-only service terms operated by Siriustech SRL (Romanian Trade Register J2025065962001). Covers definitions, online checkout, authorised users, customer data ownership, IP licensing for contributor models, support obligations, term, suspension, indemnification, limitation of liability, governing law (Romanian), and dispute resolution. ---- ## /privacy — Privacy Policy (effective 2025-10-01) Controller: Siriustech SRL. We act as **controller** for website, account, billing, marketing, support, and usage data. We act as **processor** for customer data uploaded into the Service (governed by a separate DPA available on request). Personal data processed (controller context): account & profile, billing, service usage & logs, support content, marketing preferences. GDPR rights: access, rectification, erasure, restriction, portability, objection. Contact: office@gradum.io. ---- ## /imprint — Imprint / Legal Notice (EU E-Commerce Directive) Siriustech SRL · Stejerisului 30H, 500122 Brașov, România · Romanian Trade Register no. J2025065962001 · office@gradum.io · support@gradum.io. Legal form: Societate cu răspundere limitată (SRL). B2B only. ---- ## /copyright-policy — Copyright & Intellectual Property Policy (effective 2025-10-01) Contributors retain full IP ownership of submitted maturity models. Customers may use models for internal business purposes. Notice-and-takedown procedures consistent with U.S. DMCA and the EU Digital Services Act (DSA). IP notices: office@gradum.io. ---- ## /cookie-policy — Cookie Policy (effective 2025-10-01) Cookie categories: strictly necessary (always active), functional (with consent), analytics (with consent). Vendors: Supabase (auth & DB, strictly necessary), Stripe (payments, strictly necessary), sidebar preference (functional), Google Analytics 4 (analytics). Manage preferences via the cookie-settings link in the footer. We honour Global Privacy Control (GPC) signals. Consent stored in `gradum_cookie_consent` localStorage with a 6-month renewal window. ---- ## Brand & contact Brand: Gradum (a registered trade name of Siriustech SRL). Founder: Harald Reisinger. Logo: https://gradum.io/favicon/og-image.png (1200×630). Sitemap: https://gradum.io/sitemap.xml (all indexable URLs across en, de, es, fr, it). Robots: https://gradum.io/robots.txt (AI retrieval bots: allow).