Skip to main content
⚖ NIST CSF 2.0

NIST CSF 2.0 Maturity Assessment

Assess your organization's cybersecurity maturity against the NIST Cybersecurity Framework 2.0. This self-assessment covers all 6 functions and approximately 106 subcategories, providing a structured maturity rating and prioritized improvement roadmap.

GV

Govern

Establish and communicate the organization's cybersecurity risk management strategy, policies, roles, and oversight. New in CSF 2.0 as a standalone function.

18 subcategories

ID

Identify

Develop understanding of the organization's cybersecurity risk to assets, systems, data, and capabilities.

16 subcategories

PR

Protect

Implement safeguards to ensure delivery of critical infrastructure services and manage cybersecurity risk.

26 subcategories

DE

Detect

Implement activities to identify the occurrence of a cybersecurity event in a timely manner.

13 subcategories

RS

Respond

Implement activities to take action regarding a detected cybersecurity incident.

16 subcategories

RC

Recover

Implement activities to restore capabilities or services that were impaired due to a cybersecurity incident.

10 subcategories

How the Assessment Works

  1. You'll answer questions across 6 functions, one at a time
  2. For each subcategory, rate your implementation: Yes (fully implemented), Partial (partially implemented), or No (not implemented)
  3. Your final score determines your maturity tier: Adaptive (75-100%), Repeatable (50-75%), Informed (25-50%), or Partial (0-25%)
  4. You'll receive a radar chart, per-function breakdown, and top 10 prioritized gaps with actionable recommendations