SSL Security Assessment Checklist Form
Use this form to systematically assess your organization's SSL/TLS security posture. Complete each item to identify strengths and areas for improvement.
Supported SSL/TLS Protocol Versions
*
Only TLS 1.2 and 1.3 enabled
TLS 1.0 or 1.1 still enabled
SSLv3 or older enabled
SSL/TLS Certificate Validity and Expiry
*
Valid and not expiring within 30 days
Valid but expiring within 30 days
Invalid or expired
Cipher Suite Strength
*
Only strong ciphers (AES-GCM, ChaCha20) enabled
Some weak ciphers (3DES, RC4) present
Export or insecure ciphers enabled
HTTP Strict Transport Security (HSTS) Enabled
*
HSTS enabled with long max-age and preload
HSTS enabled but not preloaded
HSTS not enabled
Forward Secrecy Support
*
All cipher suites support forward secrecy
Some cipher suites lack forward secrecy
No forward secrecy supported
Certificate Chain Completeness
*
Full chain (root and intermediates) provided
Intermediate certificates missing
Incomplete or broken chain
Certificate Revocation Status
*
OCSP Stapling or CRL available and valid
OCSP/CRL available but not valid
No revocation information available
Vulnerability to Known SSL/TLS Attacks
*
BEAST
POODLE
Heartbleed
FREAK
None of the above
Use of Deprecated Hash Algorithms
*
No deprecated algorithms (only SHA-256 or stronger)
SHA-1 present
MD5 or weaker present
General Comments or Observations
Submit Assessment
Should be Empty: