New — Post-Incident
Breach Notification Timeline Generator — TX + Federal + All 50 States
How Many Hours Until Your First Notification Deadline?
Enter incident parameters and get a per-jurisdiction notification clock: DFARS 72-hour DoD report, SEC 8-K Item 1.05 (4 business days), HIPAA 60-day, TX SB 820, NYDFS, CCPA, and all 50 states — with countdowns, regulator contacts, and notification content checklists. Highest-conversion post-incident buyer state.
Generate My Timeline →
New
Cyber Insurance Premium Estimator — Marsh · Howden · Coalition 2025
How Much Are Your Control Gaps Inflating Your Premium?
Real-time premium estimate anchored to Marsh/Howden/Coalition 2025 benchmarks. 10-control checklist shows exactly which gaps inflate your rate (+18–32% each) or trigger denial. CoreRecon MSSP savings projection + carrier-question prep sheet — email-gated PDF. Highest-intent renewal moment in our market.
Estimate My Premium →
New
Vendor Risk Scorecard — CMMC · HIPAA · GLBA · CJIS · PCI DSS
How Exposed Is Your Third-Party Stack?
Score your vendor ecosystem against 5 compliance frameworks in 90 seconds. Get a 0–100 risk score, framework gap matrix (CMMC SCRM · HIPAA BA · GLBA · CJIS Appendix G · PCI DSS Req 12.8), top-5 remediation list, and email-gated PDF — the missing piece for every CMMC L2 and healthcare lead.
Score My Vendor Risk →
New
Phishing Resistance Score — Verizon DBIR · IBM CODB 2024 · CISA
How Exposed Is Your Organization to Phishing?
12 weighted controls. Live-updating 0–100 score with band labels. Top 3 weaknesses with fix rationale. IBM CODB breach cost exposure by industry. Email-gated 8-page remediation PDF. Universally urgent — every vertical is in scope.
Score My Phishing Risk →
New
SPRS Score Calculator — NIST 800-171 · DFARS 252.204-7012
Know Your SPRS Score Before DoD Does
Score all 110 NIST 800-171 controls. Get your official SPRS number (−203 to 110), control family heatmap, and prioritized remediation roadmap — free email-gated PDF. Required for every DFARS 252.204-7012 contract. Nov 2026 CMMC enforcement deadline.
Calculate My SPRS Score →
Start Here
Breach Cost Calculator — IBM 2024 · Verizon DBIR · FBI IC3
How Much Would a Breach Cost Your Organization?
Industry, endpoints, record count. Get your IBM 2024 breach cost range, TX penalty exposure (TDPSA/HIPAA/CMMC), 207-day dwell-time gap cost, and CoreRecon Fortress ROI — instantly. The number that makes $89/endpoint an easy yes.
Calculate My Risk →
Cyber Insurance Readiness Checker — New
Will Your Cyber Insurance Renew This Year?
38 carrier-aligned questions. See exactly where you'd fail Coalition, At-Bay, Travelers, Chubb, or Beazley before your broker does.
Check My Readiness →
HIPAA Readiness Quiz
Is Your Organization HIPAA Audit Ready?
18 questions across all HIPAA Security Rule standards. Find your OCR gaps before enforcement. TX HB 300 coverage included.
Take the Quiz →
CMMC Readiness Quiz
Are You CMMC Level 2 Ready?
14 questions across all CMMC L2 domains. Know your SPRS gaps before DoD enforcement begins November 2026.
Take the Quiz →
CJIS Readiness Quiz
Is Your Agency CJIS v6.0 Audit Ready?
13 questions across all CJIS policy areas. Find your gaps before FBI auditors arrive. Oct 2027 deadline.
Take the Quiz →
SOC Buildout Calculator
In-House SOC vs CoreRecon: Real Cost?
Staffing, tools, overhead — see the full in-house number vs CoreRecon Sentinel. Live model, shareable URL.
Run the Numbers →
New
Ransomware Tabletop Generator
Run a Board-Ready Tabletop Exercise
Custom 8-inject runbook in 2 minutes. Industry-specific scenario, comms templates, roles & responsibilities. Required by cyber insurers.
Generate My Runbook →
New
Compliance Regulation Finder
Which Regulations Apply to You?
7 questions. Ranked map of every federal and Texas regulation you're subject to — with deadlines, penalties, and the CoreRecon tier that covers each one.
Find My Regulations →
New
IR Plan Generator — NIST 800-61r3
Build Your Custom Incident Response Plan
8 inputs. A full 7-phase NIST IR plan with regulation-specific notification timelines, containment playbooks, and pre-populated contact trees — free, email-gated PDF.
Generate My IR Plan →
New
PCI DSS v4.0.1 Readiness Quiz
Are You PCI DSS v4.0.1 Ready?
16 questions across all 12 PCI Requirements. Know your QSA gaps before your next assessment. Final v4.0.1 enforcement landed March 31, 2025 — every CDE is in scope.
Take the Quiz →
New
CMMC POA&M Generator — DFARS 252.204-7020
Turn NIST 800-171 Gaps Into a DoD POA&M
Select gaps from all 110 controls. Auto-populate weakness descriptions, remediation steps, and target dates. Export PIEE-ready PDF + CSV — what your prime needs before CMMC certification.
Generate My POA&M →
New
CJIS Audit Readiness Checklist — v6.0
Turn CJIS Gaps Into an Auditor-Ready Checklist
Select gaps across all 13 CJIS v6.0 policy areas. Get plain-language requirements, remediation steps, evidence checklists, and target dates — what your IT director hands to the CSA before October 2027.
Build My Checklist →
New
vCISO ROI Calculator
Fractional vCISO vs. Full-Time CISO: Real 3-Year Cost
IBM CODB breach model + compliance penalty exposure + 3-year TCO chart. Know the math before your board asks the question.
Calculate vCISO ROI →
New
NIST CSF 2.0 Readiness Quiz
Where Do You Fall on the CSF 2.0 Maturity Scale?
23 questions. All 6 CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover. Tier 1–4 maturity score + downloadable gap report. Right for manufacturers, professional services, and anyone not under a single compliance regime.
Take the CSF 2.0 Quiz →
New
Texas TDPSA Readiness Quiz — Tex. Bus. & Com. Code Ch. 541 · SaaS · Fintech · Healthcare · Retail
Are You Texas TDPSA Ready?
21 questions across all major TDPSA obligations — consumer rights (access, correction, deletion, portability, opt-out), universal opt-out / GPC recognition, privacy notice, sensitive data consent, Data Protection Assessments, processor contracts, data minimization, reasonable security, appeal process, and AG enforcement readiness. Industry selector for SaaS/tech, fintech, healthcare, marketing, retail, accounting, and higher ed. Email-gated 30/60/90 remediation roadmap. AG civil penalties up to $7,500/violation.
Take the TDPSA Quiz →
FTC Safeguards Quiz →