NIST CSF 2.0 Maturity Assessment
Assess your organization's cybersecurity maturity against the NIST Cybersecurity Framework 2.0. This self-assessment covers all 6 functions and approximately 106 subcategories, providing a structured maturity rating and prioritized improvement roadmap.
Govern
Establish and communicate the organization's cybersecurity risk management strategy, policies, roles, and oversight. New in CSF 2.0 as a standalone function.
18 subcategories
Identify
Develop understanding of the organization's cybersecurity risk to assets, systems, data, and capabilities.
16 subcategories
Protect
Implement safeguards to ensure delivery of critical infrastructure services and manage cybersecurity risk.
26 subcategories
Detect
Implement activities to identify the occurrence of a cybersecurity event in a timely manner.
13 subcategories
Respond
Implement activities to take action regarding a detected cybersecurity incident.
16 subcategories
Recover
Implement activities to restore capabilities or services that were impaired due to a cybersecurity incident.
10 subcategories
How the Assessment Works
- You'll answer questions across 6 functions, one at a time
- For each subcategory, rate your implementation: Yes (fully implemented), Partial (partially implemented), or No (not implemented)
- Your final score determines your maturity tier: Adaptive (75-100%), Repeatable (50-75%), Informed (25-50%), or Partial (0-25%)
- You'll receive a radar chart, per-function breakdown, and top 10 prioritized gaps with actionable recommendations