NIST Cybersecurity Framework 2.0

Measure Your Cybersecurity Posture Against CSF 2.0

Score all 106 subcategories across six core functions. Surface your highest-priority gaps. Track maturity improvement across assessments. Free to use — no account required.

Open Assessment Tool →
Six Functions. Complete Coverage.

Every corner of your cybersecurity program, scored.

NIST CSF 2.0 organizes cybersecurity activities into six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function contains categories and subcategories that map to specific outcomes.

The CSF 2.0 Assessment tool walks you through all 106 subcategories, scoring each on a 0–5 maturity scale. The result is a complete picture of where your program is strong, where gaps exist, and what to prioritize next.

GV ID PR DE RS RC 2.8 3.2 3.0 2.5 2.1 1.8
How It Works

From blank slate to scored assessment.

Four steps, built to be completed in a single session or across multiple visits. Export a JSON snapshot at the end to preserve your assessment.

01Configure Your Assessment

Set your organization name, assessment date, and target maturity levels. You can apply a single target score across all functions or set per-function targets to reflect where your program actually needs to be — not just a blanket aspirational level.

02Score All 106 Subcategories

Work through subcategories grouped by the six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each item receives a Current score (0–5) and an optional Target. Inline reference text from the CSF 2.0 publication provides context for each subcategory as you work.

03Review Gap Analysis & Priorities

The Summary tab aggregates scores into function-level maturity ratings and surfaces your highest-priority gaps. KPI cards show overall posture, total subcategories scored, gap count by threshold, and the number of high-priority items. A gap action plan groups remediation items by function and priority level.

04Track Progress Over Time PRO

Import previous assessment snapshots to the Trends tab and visualize maturity improvement over time. Compare function scores across assessments, see your overall trajectory, and identify where remediation efforts are — and aren't — moving the needle. Requires at least two saved snapshots.

Pro Features

Built for practitioners doing real engagements.

All scoring and gap analysis is free. Pro adds the file management, reporting, and trend tracking that serious work requires.

  • 📥
    Import Saved Snapshots

    Resume a previous assessment or load a historical snapshot. Import multiple files to populate the Trends view for comparative analysis.

  • 💾
    Save as JSON Snapshot

    Export a complete point-in-time assessment to a JSON file. Share with teammates, archive for compliance records, or reimport later to resume.

  • 📊
    Export to Excel

    Generate a formatted Excel workbook with all scores, gaps, and function summaries — ready for stakeholder review or leadership reporting.

  • 🖨️
    Print & PDF Report

    Produce a customizable, professionally formatted report with executive summary, function scores, and top remediation priorities. Always renders in light mode for clean printing.

  • 📈
    Trend Analysis

    Load 2+ snapshots to see maturity progression over time — line charts and delta indicators per function show exactly where the program is improving.

5.0 3.5 2.0 Q1 Q2 Q3 Q4 ↑ +0.8 Overall Score Protect (PR) CSF Trend Analysis · Pro Feature

Start your CSF 2.0 assessment — free.

No account required. Open the tool and start scoring in minutes. Export a JSON snapshot when you finish to preserve your work for next time.