Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Live, isolated infrastructure with customer-topology replication is materially stronger for skill transfer than a generic simulated UI with no real systems underneath.
Look for explicit ATT&CK mapping and a concrete content-refresh cadence; a static, unmapped library ages out of relevance quickly.
Objective, peer-benchmarked scoring is stronger evidence of real skill development than subjective, unbenchmarked facilitator grading.
Structured after-action reporting tied to concrete remediation steps is stronger than a bare pass/fail scorecard with no follow-through guidance.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Audience-tailored content is a real differentiator — probe for concrete evidence (sample materials, a customer reference) rather than accepting the claim at face value.
Demand a concrete participant-count ceiling and cost model; 'scales as needed' with no numbers is not a real answer for planning a large exercise.
Real LMS/HR integration with skills-gap reporting is stronger than a standalone completion certificate with no downstream visibility for leadership.
An explicit, working air-gapped/on-prem option matters for regulated or classified customers; a vague cloud-only answer is a real disqualifier for that segment.
Look for transparent, predictable pricing that accounts for a realistic recurring-exercise cadence, not just a one-time-event price that becomes expensive at real ongoing usage.
Real, recognized certification credit adds tangible career value for participants beyond the training itself — ask for a specific, named credentialing relationship, not a vague 'certificate of completion.'
OT-specific exercises require genuinely different technical content than generic IT scenarios — ask for evidence of real OT expertise behind that specific content, not a repurposed IT scenario relabeled.
Clarify this scope boundary explicitly — conflating training exercise data with real security-assessment findings could create confusion about what represents an actual organizational vulnerability versus a training scenario.
Automated ticket creation from after-action findings is materially more likely to result in real remediation than a standalone report that can be filed away and forgotten.
Trend-over-time readiness reporting is a distinct capability from a single exercise's scorecard — confirm this exists as a maintained, exportable report across multiple exercises.
A genuinely global organization needs real multi-language support, not just an English-only platform — ask for specific language coverage and how cross-language scoring consistency is maintained.
A concrete, recent example of fast content updates is more credible than a generic 'we stay current' claim — press for a specific instance and timeline.