Open kit · free to use

The VM Program Kit

A complete, risk-based vulnerability management program in ten editable files: the policy, the prioritization model, the runbook, the exception register and the reporting that goes with them. Free to use and adapt inside your organization.

Version 1.2 · October 2026 · CC BY-NC 4.0 with an internal-use grant · no sign-up

Download all ten files (427 KB zip) Read the method it implements

What's in it

TypeFileGet it
PDFStart here
What each file is, the order to adopt them, and what to customize before you deploy.
Download
134 KB
PPTXProgram overview deck
The whole program on 11 editable slides, with speaker notes. Rebrand it and present it to your leadership.
Download
285 KB
DOCXVM policy and standard
Scope, roles, asset tiering, the prioritization method, the deadline matrix, exceptions and governance.
Download
15 KB
XLSXPrioritization model
The engine. Paste a scanner export and map its columns once. It applies both stages of the method, assigns deadlines, tracks open and closed dates, and runs the dashboard. Wired for 2,000 findings.
Download
585 KB
DOCXTriage and remediation runbook
The operating procedure from intake through close, with escalation paths and a worked example.
Download
13 KB
XLSXException register
The risk-acceptance register the policy requires: approver set by priority, and an expiry that turns into a missed deadline.
Download
42 KB
DOCXScanner onboarding notes
Bringing a scanner into the program: required fields, authenticated coverage and tuning, with notes for Tenable, Qualys, Rapid7, Wiz and Snyk.
Download
15 KB
DOCXExecutive report template
The one-page leadership summary that answers whether you are exposed and whether it is improving.
Download
11 KB
XLSXFramework crosswalk
Every program element mapped to NIST CSF 2.0, PCI DSS v4, ISO 27001:2022 and SOC 2, with the evidence each produces.
Download
15 KB
DOCXMaturity model and 90-day roadmap
Six dimensions by five levels, scored like the free assessment, plus what to fix first at each level.
Download
16 KB

Start with the START-HERE guide and the overview deck. Then adopt the policy, wire up the prioritization model, and run the work through the runbook and the exception register. The files reference each other, so they work as one program.

What you can do with it

Use it at work: freeAny organization, any size, for-profit or not, may use and adapt the Kit to run its own security program. You don't need to ask, sign up or display credit on your internal documents.
Share it: free, with creditYou may share the Kit or your adapted version outside your organization for non-commercial purposes. Credit "FlintScope VM Program Kit by Nick Strupp, flintscope.com/kit, CC BY-NC 4.0" and say what you changed.
Use it for clients: licensedConsultants, vCISOs, MSPs and MSSPs who use the Kit in paid client work, and anyone who sells it or builds it into a product, need the commercial license below.

That is a summary. The license page has the terms, and a copy travels with the files as LICENSE.txt.

Commercial license

$399 per firm, one time. One firm, all of its people, unlimited clients. You may adapt the Kit and deliver the documents and workbooks to clients under your own name. Later versions are included, and the 30-day refund policy applies.

Email to buy a commercial license

Why it's free

This is the program I built and ran across more than 5,000 applications, written down. A prioritization method is only useful to the field if people can read it, check it and change it, so the method is published in full and the Kit that implements it is open. If you adopt it and change something, I'd like to hear what and why: support@flintscope.com.

Nick Strupp, CISSP. 15+ years in security. US Patent 11,106,801. The Kit is general information, not professional advice; see the disclaimer.