Three Levels, 130 More Labs and the Practical Exam — A Bakery, a Food Bank, a Drainage Board, an Insurance Group
On 20 September we added ten companies to the lab environments, and the set ran to thirteen organisations and 134 labs. Since then it has grown by twenty-two organisations and 130 labs, it has been sorted into three levels, and each level is now the standard of a practical examination. Two of those examinations are open now.
What a lab is has not changed. Each company is built whole: its policies name its systems, its registers list its suppliers, and its exports show who can still sign in. You get the evidence and the question the job actually asks, and most findings only exist in the gap between two documents. What changes from level to level is how much the lab tells you, and how much of an organisation you have to hold in your head at once.
Three levels
The levels are named after the practical exam each one prepares you for.
Level 1
Foundation
- 20 companies, all new
- One small organisation and one framework each
- 10 findings, two per lab, pointed out
- 6 short labs, about 4 hours
- Exam open now
Level 2
Practitioner
- The 13 companies you know
- One larger organisation each
- 24 findings, named in the final assessment
- 10 to 14 labs, about 10 hours
- Exam open now
Level 3
Advanced
- 2 groups, both new
- Three related companies in three countries each
- 24 findings, named nowhere
- 5 larger labs, about 14 hours
- Exam being built
The levels are measured, not guessed. A test measures every pack and holds it to its level's rules. A Foundation pack has no subtle tasks and one framework. A Practitioner pack has at least one subtle task and ends in an assessment of every finding. An Advanced pack is a group across at least two jurisdictions and names none of its findings anywhere. A pack placed on a level it does not fit fails. On the labs page each company now sits under its level, so you can see which ones are at the standard of the exam you are working towards.
Level 1 · Foundation — twenty small organisations
The Foundation companies are the new way in. Each has between 28 and 96 people, one framework, ten findings and 5,300 to 7,100 words of evidence: policies, registers, contracts, tickets and system exports. The first five labs each point you at two findings and tell you which documents to open. You answer exact questions from the evidence — a date, a count, which account, which statement describes the failure — map each finding to the framework, rate it with the company's own risk matrix, and write one of them up the way it would appear in a report. The sixth lab asks which three findings matter most, which to fix first, and for a short note to the people who decide.
Every framework the Practitioner labs assess at depth now has a Foundation company to start on. The first ten take a framework each; the second ten take eight of those frameworks to a different kind of organisation, and add the NCSC CAF and Australia's Privacy Act.
ISO/IEC 27001:2022. Brackenholt Architects, a Leeds practice of 31 whose drawings include the layouts of secure mental health wards, and whose Statement of Applicability relies on a multi-factor policy that has been in report-only mode since the day it was created. Quillhaven Translation in Ottawa, whose client files reach its freelancers through 1,207 SharePoint links that open for anyone who has them — one of which was posted on a public translators' forum.
SOC 2. Fernhook Software, a Denver company whose shift-scheduling product holds 210,000 hospitality workers' pay rates, and whose bucket of every customer's payroll exports has been open to anyone since a “temporary” migration in March. Owlcrest Education, a Madison education technology company holding 310,000 students' records, whose administrator access key has sat in a public repository since February and was used in July from an address that is not the company's.
NIST CSF 2.0. Sycamore Bend Community Food Bank in North Carolina, whose pantry check-in kiosks share one login, its password on a card in a desk drawer and unchanged since 2023. Sagebrook Water and Sewer District in Idaho, whose operators run every well and lift station from one HMI, reachable from the internet on the integrator's commissioning default password. Nineteen outside addresses connected to it in July.
PCI DSS v4.0.1. Tidemill Bakehouse, a Wellington bakery-café group whose catering team writes card numbers and security codes on paper order forms — 410 of them, none destroyed, in a binder in an office that is never locked. Thimbleberry Nursery, an online plant nursery in Oregon whose checkout page runs eleven scripts where its inventory lists six, and whose database still holds 2,314 full card numbers that its draft self-assessment says it does not store.
HIPAA. Mosswood Family Dental, three offices around Phoenix, where a hygienist who left in April signed in from outside the practice in May and opened fourteen patients' charts. Cypress Key Revenue Services, a Tampa medical billing company whose file transfer server lets anyone on the internet log in anonymously and read every client practice's patient statements.
GDPR. Clonmere Recruitment, a Cork agency whose shared CV mailbox has forwarded every message to a former consultant's personal webmail for 248 days since the consultant left, and whose new AI service reads every CV in the United States with no processor contract. Spaakwiel, a Utrecht e-bike subscription company whose bikes report their position every thirty seconds, day and night, and whose Ride Score has put 441 subscribers on a higher fee without an impact assessment.
NIS2. Dijlepost, a Leuven same-day courier that first reported a ransomware attack to Belgium's national cyber security centre fifty-seven and a half hours after it knew, with no early warning. Kuurapiste, a managed service provider in Oulu with a spreadsheet of 58 customers' administrator logins that every member of staff can read.
DORA. Amberfield Payments, a Vilnius e-money institution whose cloud owner account has no multi-factor authentication, and whose ledger backups can be deleted by anyone who administers production. Ventoluz Crowdfunding in Lisbon, where any signed-in investor can download any other investor's identity documents by changing a number in the address: found by the penetration test in February, still open at the retest in July.
NIST SP 800-171. Ashby Creek Harness, a Kansas maker of wire harnesses for a ground vehicle programme, facing a CMMC Level 2 assessment in December. Its System Security Plan records multi-factor authentication as implemented; neither the VPN nor Microsoft 365 asks for it.
APRA CPS 234. Tallis Health Fund, a not-for-profit health insurer in Newcastle, New South Wales, that told APRA about the ransomware at its claims processor seven days after it knew, against seventy-two hours.
NCSC CAF. Tollerdyke Internal Drainage Board, which keeps 31,000 hectares of Lincolnshire fen drained and runs its pumping stations from a SCADA server on Windows Server 2012 R2, out of support since 2023. Its telemetry supplier has always-on remote access to that server on one shared password, which the supplier has written to say may have leaked. In February's storm a pumping station lost contact, its pumps tripped, and nobody knew until two properties had flooded.
Privacy Act 1988. Bluegum Row Property Management, a Brisbane rental agency whose application form passes applicants to an energy reseller unless they untick a box ticked for them — 3,439 of 3,612 applicants from January to July — and which still holds 22,148 unsuccessful applications, identity documents and payslips included, going back to 2019.
Level 2 · Practitioner — the thirteen you know
Wattlebrook, Boxelder, Vlietstroom and the ten companies from the last post are all Level 2. Each is roughly ten hours and 13,000 to 22,000 words of evidence, with twenty-four findings and ten to fourteen labs that build from a first look to an independent assessment of every finding. That is half of a Level 2 exam, at the same standard.
Five of them now carry an Exam format tag. Kestrel Ridge, Marrowbay, Merridale, Thornbury Wells and Tregarrick end exactly the way an exam organisation does, with every finding mapped to a control and rated, field by field. The other eight end in an assessment that is mostly written, and are the gentler way in.
Level 3 · Advanced — a group, and nothing named
The Advanced labs are the first where nothing names the findings: you have to discover them. Each is a group of three companies in three countries, under three or four regimes at once, with 11,000 to 13,000 words of evidence that does not always agree with itself. There are five labs, fewer and larger, about fourteen hours in all, and deciding what is in scope is part of the answer.
Each of the first four labs takes one area of the evidence. You pick that area's findings out of a list salted with claims the evidence refutes, so ticking everything scores a quarter at most, and then write them into a findings register in your own words. A model classifies each row you write against a shuffled catalogue of the pack's real findings and plausible decoys; code, not the model, awards the points, and asserting a decoy costs marks. The fifth lab is the independent assessment: every finding in one register, then three papers for the boards and a regulator.
Aldermoor Group — an Australian travel insurer, the Irish insurer it bought in 2024, and the service company in Manila that runs IT, claims and round-the-clock emergency assistance for both. In May, ransomware at the service company took the assistance case system down for nineteen hours, and the three companies recorded the same night three different ways. Marked against CPS 234, the Privacy Act, DORA and the GDPR, it ends in a board paper, the answer to APRA's letter and a remediation roadmap against a budget.
Farrowdale Diagnostics Group — a reference laboratory in Minneapolis, the clinical genetics laboratory in Utrecht it bought in 2025, and the company in Pune that builds and runs both laboratories' systems. In May an extortion email to the Dutch laboratory's front desk quoted twenty patients' genetic results, and each company decided for itself what had happened. Marked against HIPAA, the GDPR and ISO/IEC 27001, it ends in a notification decision across three regimes, the answer to the Autoriteit Persoonsgegevens, and whether a research programme may go on.
The practical exam — two levels open
Every level is also an examination: timed, open book, on organisations you have never seen, and marked against their own evidence. Two are open now. None is a prerequisite for another, so sit whichever fits you.
Level 1 · Foundation. One small organisation, assessed against ISO/IEC 27001:2022 Annex A. Eight tasks, each telling you where to look: about six hours of work, and two days to do it in. There are twelve findings, pointed out task by task. You confirm them, map them and rate them with the organisation's own risk method, and finish by naming the three most serious in a note to its directors. Its bank of papers is full: four, each on a different organisation that appears nowhere else on the site.
Level 2 · Practitioner. Two organisations in different countries, against six frameworks. Twenty tasks, including a full independent assessment of each organisation: about twenty-two hours of work, and five days to do it in. There are forty-eight findings, with each task saying where to look, and you produce findings registers, board summaries, a corrected statement to a customer and a breach re-assessment. It has two papers so far, of the four its bank will hold.
Level 3 · Advanced is being built: a group of related companies across several jurisdictions, about thirty hours of work in seven days, findings you have to discover, and some evidence that conflicts. Its page shows the planned format, which may change before it opens. The two Advanced labs are built to that standard.
How a sitting works
The clock runs from the moment you press start. It does not pause, overnight included, but you can work in as many sessions as you like. Answers save as you go, and when the time runs out, whatever you have saved is submitted for you. Start when you have the days set aside.
Open book, no proctor, one honour code. Use any notes or references you like. No other person may help you, and you may not share the tasks, the evidence or your answers. You agree to that before the clock starts, and a certificate can be revoked for breaking it. The answer key has to be off: study with it, then switch it off to sit.
A paper at random, and a different one on a resit. Each sitting is one of the level's papers, chosen at random. The pass mark is 70 per cent. If you do not pass, you can sit again after seven days, on a paper you have not sat while there is one. Individual answers and feedback are never released, because the papers are reused.
Marked the way the labs are. Structured answers are marked automatically against a stored key. Written answers are marked against a rubric by AI. If one cannot be marked, marking keeps trying for up to a day, and after that a person reviews the sitting before any result is recorded.
Extra time, without the paperwork. If you have a disability, a long-term health condition or a learning difference that affects how quickly you read, write or type, you can declare 25, 50 or 100 per cent extra time. We do not ask what it is or for evidence, we store only the percentage, and it does not appear on your certificate.
A certificate anyone can check
A pass earns an exam certificate, kept apart from the completion certificates you get for finishing paths. It carries a credential ID and a QR code. Anyone with the code can check it at /verify, which shows the name on the certificate, the examination and its level, the date and whether it is valid — never your score. From the Exam Certificates page you can download it, add it to your LinkedIn profile with the form already filled in, or share the verification link, and you can switch public verification off whenever you like. A certificate stays valid after your membership ends. The levels, your exam certificates and the verification page all live under the new Exams menu.
Included with Pro
The practical exam comes with Pro, at $20 USD a month, with no separate exam fee: two sittings in any thirty days, across every level. A sitting counts from the moment you press start, whether or not you finish it, until thirty days later. Pro's three-day free trial includes it. Plus and free memberships do not.
The numbers
The twenty Foundation companies add 120 labs, 501 artefacts and 200 findings: about 77 hours of work and 3,571 points. The two Advanced groups add 10 labs, 112 artefacts and 48 findings: 28 hours and 894 points. Across all thirty-five organisations there are now 264 labs and roughly 240 hours of work.
The first lab of every company is still free
As before, the front door of every environment is free to work end to end, evidence and marking included. That is now thirty-six free labs across thirty-five organisations, including the first lab of all twenty Foundation companies and of both Advanced groups. The rest come with a paid membership, and paid labs are still listed with their brief so you can see what you would be working on.
If you are new to GRC work, start with the Foundation company that uses your framework, or the one you want to learn. If you have worked a few Practitioner companies, try an Advanced group. When you are ready, sit the exam.
Start at /lab-environments for how the labs work, go straight to /labs if you already have an account, or read each exam's rules at /practical-exam.
Four honest notes
Everything is invented. The companies, staff, customers, suppliers, systems, documents and regulator correspondence in the labs and the exam papers were written for the exercise, and names that resemble real ones are coincidence. None of it evidences any real organisation's controls — see the disclaimer. The framework texts in the dropdowns are paraphrased as a teaching aid, and clocks and deadlines are stated as facts of the scenario. Verify the current instrument before you rely on any of it at work.
The exam is not an accredited certification. It is a Do GRC credential from a timed, marked practical examination sat without proctoring, and the certificate says so on its face. It is not accredited by any standards body, certification body or regulator, and it is not a professional qualification or a licence. It records that you passed the examination at that level on the date shown.
Written answers are marked by an AI. In the labs and the exam alike, your written answer, the prompt and its rubric are sent to our AI provider; structured answers are marked against a stored key and never leave our database. You are writing about an invented organisation, so an answer should not contain anything about you or your employer. The AI transparency page and the privacy policy set out exactly what is sent and what is not.
Our analytics now include heatmaps and event tracking. They come from Cookiebot, which already runs our cookie banner. If you accept analytics cookies, it records where on each page people click, move the pointer and scroll, and counts actions such as clicking a button or submitting a form, so we can see which parts of a page get used and which get missed. If you decline, it counts your visit only in anonymised form, with no cookies. We have not switched on its session recordings, so it does not record your screen. You can change your choice at any time from the cookie policy, and the privacy policy sets out what is collected.