A NIST CSF 2.0 self-assessment is one of the few GRC exercises you can actually do yourself, in an afternoon, without a consultant or a procurement cycle. The framework is not a control catalog you have to fully implement. It is a set of outcomes you rate against where you are and where you want to be. The hard part is not the rating. It is keeping the scope honest, scoring consistently, and turning the resulting gap list into something a budget owner will act on.
This is a practical, end-to-end walkthrough of how to do a CSF assessment: set scope, work through the six functions (including GOVERN, the function CSF 2.0 added), score the 106 subcategories against a tier-based rubric, read the gap analysis, and convert gaps into a plan. We will use the free, in-browser CSF 2.0 assessment tool as the working surface so you are not babysitting a spreadsheet, but the method works on paper too.
What CSF 2.0 actually is (and what changed from 1.1)
The NIST Cybersecurity Framework version 2.0 was published in February 2024 (NIST CSWP 29). Two changes matter for your self-assessment. First, the framework is now explicitly written for all organizations in any sector, not just critical infrastructure. Second, and more structurally, it added a sixth Function.
CSF 1.1 had five Functions: Identify, Protect, Detect, Respond, Recover. CSF 2.0 has six. The new one is GOVERN (GV), and NIST depicts it at the center of the others because it covers the decisions that make the rest meaningful: risk strategy, roles and authorities, policy, oversight, and supply chain risk management. The full Core is organized into 6 Functions, 22 Categories, and 106 Subcategories (down from 108 in 1.1). The Subcategory is the unit you score.
The six functions and what each one is asking
Read the Function names as questions about outcomes, not as a checklist of products you own. Here is the plain-language read on each.
| Function | ID | The question it answers | New in 2.0? |
|---|---|---|---|
| Govern | GV | Who owns cyber risk, what is our strategy and risk appetite, and how do we oversee it? | Yes |
| Identify | ID | What assets, data, suppliers, and risks do we actually have? | No |
| Protect | PR | What safeguards limit or contain the impact of an event? | No |
| Detect | DE | How do we find anomalies and incidents in time to act? | No |
| Respond | RS | What do we do once something is detected: contain, analyze, communicate? | No |
| Recover | RC | How do we restore operations and capabilities after an incident? | No |
GOVERN deserves extra attention because it is where most first-time self-assessments are weakest, and it is where 1.1-era assessors have no muscle memory. Its Categories cover Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities, and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV), and Cybersecurity Supply Chain Risk Management (GV.SC). If you cannot name who owns cyber risk or where your risk appetite is written down, GOVERN is going to light up red, and that is the assessment doing its job.
Step 1: Set the scope before you score anything
The single most common reason a CSF self-assessment is useless later is undefined scope. Before you rate a single subcategory, write down three things:
- The boundary. Whole enterprise, one business unit, one system, or one product line? CSF 2.0 lets you scope a Profile to whatever organizational unit makes sense. Pick one and name it.
- The point in time. A self-assessment is a snapshot. Date it. You want to re-run it later and compare, so the date is part of the data.
- Who is rating. One person rating everything gives you consistency but blind spots. A small group gives you coverage but rating drift. Either is fine if you pick a rubric and stick to it.
Step 2: Score each subcategory with a tier-based rubric
CSF 2.0 gives you the vocabulary for this directly. The framework defines four Implementation Tiers that describe how rigorous and consistent your cybersecurity risk governance and management practices are. In the framework, Tiers characterize an organization's practices overall rather than rating individual controls, but they translate cleanly into a per-subcategory scoring rubric, which is exactly what a gap analysis needs.
| Tier | Name | What it looks like at the subcategory level |
|---|---|---|
| 1 | Partial | Ad hoc, reactive, undocumented. It might happen, but nobody owns it and nothing is written down. |
| 2 | Risk Informed | Practices exist and are approved by management, but are not established as organization-wide policy or consistently applied across the scope. |
| 3 | Repeatable | Expressed as policy, applied consistently, and updated as policy or risk changes. This is a defensible target for most outcomes. |
| 4 | Adaptive | Continuously improved, informed by lessons learned and predictive indicators, integrated into enterprise risk decisions. |
For each of the 106 subcategories, you record two ratings: your Current state and your Target state. That pairing is the whole game. CSF 2.0 calls these the Current Profile and the Target Profile, and the distance between them is your gap. Do not set every Target to Tier 4. A realistic Target Profile sets higher targets where risk or a mandate is greater, and accepts lower tiers where a cost-benefit analysis does not justify the spend. An honest assessment has Targets at 2 and 3 in places.
The mock shows the mechanic. Each subcategory carries a short outcome statement, a Current rating, and a Target rating. Scoring all six functions is roughly 106 of these decisions. In the browser tool the per-function progress and the running gap update as you go, so you can stop and resume without losing your place.
Step 3: Read the gap analysis
Once Current and Target are set, the CSF gap analysis is just arithmetic: gap = Target minus Current, per subcategory, rolled up by Category and Function. But reading it well is a skill. Three things to look at, in order:
- Two-tier gaps first. A subcategory sitting at Current 1 against a Target 3 is a bigger signal than a 3-against-4. Sort by gap size, not by alphabetical ID.
- Function-level patterns. If GOVERN and RECOVER are mostly red while PROTECT is mostly green, you have a common profile: decent preventive controls, weak governance and resilience. That is a strategy finding, not a control finding, and it lands differently with leadership.
- Targets you set to Current. Subcategories where Target equals Current are not gaps. They are conscious acceptances. Keep them visible so nobody mistakes a deliberate Tier 2 for a thing you forgot.
The output you want is not "we scored 2.3 out of 4." Averages hide the subcategories that matter. The useful output is a ranked list of the largest gaps, grouped by Function, with the outcome statement attached so a reader who has never heard of GV.RR-02 understands what the gap is.
Step 4: Turn gaps into a plan
A gap list is not a plan. To make it actionable, each significant gap needs an owner, a rough effort estimate, and a target date. This is where a CSF assessment feeds directly into the rest of your GRC program. The largest gaps become entries in a remediation backlog, and the riskiest ones become formal items in a POA&M Tracker or risk register. CSF tells you what is weak; your POA&M tracks the commitment to fix it.
A workable sequence for converting the gap analysis into a plan:
- Filter to subcategories where the gap is 2 or more tiers. Those are your first wave.
- For each, write one sentence on the closing action and name an owner. "Document and approve the cybersecurity roles and responsibilities (GV.RR-02), owner: ISSM, target: Q3."
- Group by cost. Several governance gaps often close with one policy effort, not six separate projects. Bundle them.
- Re-baseline on a schedule. A CSF self-assessment is most valuable as a trend you track over time, not a one-off. Re-run it next quarter against the same scope and watch the gaps move.
Do it without a spreadsheet
You can run all of this in a spreadsheet. People do. But you will hand-key 106 outcome statements, fight with conditional formatting to make gaps visible, and recompute rollups by hand every time a rating changes. The free, browser-based CSF 2.0 self-assessment tool ships the full Core (all 6 functions, 22 categories, 106 subcategories) with the outcome statements already in place, scores Current and Target per subcategory, and computes the gap analysis and function rollups as you go. It runs entirely in your browser, no account, and your assessment data never leaves your device, which matters when you are rating your own control weaknesses.
It is genuinely free to use for the assessment itself. The Pro tier ($179/yr) adds the things you want once you commit to re-baselining: save, import, and export (JSON and CSV), print and PDF reports for leadership, a roll-up dashboard across tools, and trend tracking that compares snapshots over time so you can show movement quarter over quarter. If you are doing CSF once to scope a project, the free path is complete. If CSF becomes part of how you report posture, the trend view is the reason to upgrade.
This is also the most practical NIST CSF 2.0 assessment template you can use, because it is not a static document you have to interpret. The structure, the rubric, and the gap math are built in, and the output is the ranked, function-grouped gap list you need to brief a budget owner.
Frequently asked questions
Is a NIST CSF 2.0 self-assessment a certification with a pass/fail score?
No. CSF 2.0 is not a certification and there is no pass/fail score. Unlike CMMC or a FedRAMP authorization, no assessor signs off and no number gets reported to a government system of record. A CSF self-assessment is a management tool that tells you and your leadership where your cybersecurity outcomes stand and where to invest next, so treat it as a planning instrument, not an audit.
How many functions and subcategories are in NIST CSF 2.0?
CSF 2.0 has six Functions. It added GOVERN (GV) to the five from CSF 1.1 (Identify, Protect, Detect, Respond, Recover). The full Core is organized into 6 Functions, 22 Categories, and 106 Subcategories, down from 108 in 1.1. The Subcategory is the unit you score.
How do you score each subcategory in a CSF 2.0 self-assessment?
CSF 2.0 defines four Implementation Tiers (1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive) that translate into a per-subcategory rubric. For each of the 106 subcategories you record two ratings: your Current state and your Target state. The distance between them is your gap, computed as Target minus Current. A realistic Target Profile does not set every target to Tier 4; it sets higher targets where risk or a mandate is greater and accepts lower tiers where a cost-benefit analysis does not justify the spend.
Is the CSF 2.0 assessment tool free to use?
Yes. The browser-based CSF 2.0 assessment tool is genuinely free to use for the assessment itself. It ships the full Core (6 functions, 22 categories, 106 subcategories) with the outcome statements in place, scores Current and Target per subcategory, and computes the gap analysis as you go. It runs entirely in your browser with no account, and your assessment data never leaves your device. The Pro tier ($179/yr) adds save, import and export, print and PDF reports, a roll-up dashboard, and trend tracking across snapshots.
Related reading
- Tracking NIST CSF Maturity Over Time: The Benefits of a Trend, Not a Single Score
- NIST AI RMF Explained: A Practical Guide to the AI Risk Management Framework
- RMF Simplified: How the Seven Steps Bring Clarity to System Authorization
- the free NIST CSF 2.0 assessment tool
References
- NIST, "The NIST Cybersecurity Framework (CSF) 2.0," NIST CSWP 29, February 2024. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
- NIST, "NIST Releases Version 2.0 of Landmark Cybersecurity Framework," News Release, February 26, 2024. https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
- NIST, "NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using the CSF Tiers," NIST SP 1302. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1302.pdf
- NIST, "NIST Cybersecurity Framework 2.0: Resource & Overview Guide," NIST SP 1299. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1299.pdf
- NIST, "The NIST CSF 2.0 Core With Withdrawn CSF 1.1 Elements," March 2024 (Subcategory mapping, 106 vs 108). https://www.nist.gov/system/files/documents/2024/03/25/The_NIST_CSF_2-0_Core_With_Withdrawn_CSF_1-1_Elements.pdf