← All Insights
NIST CSF 2.0Self-AssessmentGap AnalysisFree Tools

How to Run a Free NIST CSF 2.0 Self-Assessment

9 min readMay 2026Risk Posture Insights

A NIST CSF 2.0 self-assessment is one of the few GRC exercises you can actually do yourself, in an afternoon, without a consultant or a procurement cycle. The framework is not a control catalog you have to fully implement. It is a set of outcomes you rate against where you are and where you want to be. The hard part is not the rating. It is keeping the scope honest, scoring consistently, and turning the resulting gap list into something a budget owner will act on.

This is a practical, end-to-end walkthrough of how to do a CSF assessment: set scope, work through the six functions (including GOVERN, the function CSF 2.0 added), score the 106 subcategories against a tier-based rubric, read the gap analysis, and convert gaps into a plan. We will use the free, in-browser CSF 2.0 assessment tool as the working surface so you are not babysitting a spreadsheet, but the method works on paper too.

What CSF 2.0 actually is (and what changed from 1.1)

The NIST Cybersecurity Framework version 2.0 was published in February 2024 (NIST CSWP 29). Two changes matter for your self-assessment. First, the framework is now explicitly written for all organizations in any sector, not just critical infrastructure. Second, and more structurally, it added a sixth Function.

CSF 1.1 had five Functions: Identify, Protect, Detect, Respond, Recover. CSF 2.0 has six. The new one is GOVERN (GV), and NIST depicts it at the center of the others because it covers the decisions that make the rest meaningful: risk strategy, roles and authorities, policy, oversight, and supply chain risk management. The full Core is organized into 6 Functions, 22 Categories, and 106 Subcategories (down from 108 in 1.1). The Subcategory is the unit you score.

Common misconception: CSF 2.0 is not a certification and there is no pass/fail score. Unlike CMMC or a FedRAMP authorization, no assessor signs off and no number gets reported to a government system of record. A CSF self-assessment is a management tool: it tells you and your leadership where your cybersecurity outcomes stand and where to invest next. Treat it as a planning instrument, not an audit.

The six functions and what each one is asking

Read the Function names as questions about outcomes, not as a checklist of products you own. Here is the plain-language read on each.

FunctionIDThe question it answersNew in 2.0?
GovernGVWho owns cyber risk, what is our strategy and risk appetite, and how do we oversee it?Yes
IdentifyIDWhat assets, data, suppliers, and risks do we actually have?No
ProtectPRWhat safeguards limit or contain the impact of an event?No
DetectDEHow do we find anomalies and incidents in time to act?No
RespondRSWhat do we do once something is detected: contain, analyze, communicate?No
RecoverRCHow do we restore operations and capabilities after an incident?No

GOVERN deserves extra attention because it is where most first-time self-assessments are weakest, and it is where 1.1-era assessors have no muscle memory. Its Categories cover Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities, and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV), and Cybersecurity Supply Chain Risk Management (GV.SC). If you cannot name who owns cyber risk or where your risk appetite is written down, GOVERN is going to light up red, and that is the assessment doing its job.

Step 1: Set the scope before you score anything

The single most common reason a CSF self-assessment is useless later is undefined scope. Before you rate a single subcategory, write down three things:

Tip: Scope to something you can defend in one sentence. "Production SaaS platform and the team that runs it, as of this quarter" beats "the company" because every subcategory rating now has a clear referent. If you run multiple systems, do separate scoped assessments rather than averaging them into mush.

Step 2: Score each subcategory with a tier-based rubric

CSF 2.0 gives you the vocabulary for this directly. The framework defines four Implementation Tiers that describe how rigorous and consistent your cybersecurity risk governance and management practices are. In the framework, Tiers characterize an organization's practices overall rather than rating individual controls, but they translate cleanly into a per-subcategory scoring rubric, which is exactly what a gap analysis needs.

TierNameWhat it looks like at the subcategory level
1PartialAd hoc, reactive, undocumented. It might happen, but nobody owns it and nothing is written down.
2Risk InformedPractices exist and are approved by management, but are not established as organization-wide policy or consistently applied across the scope.
3RepeatableExpressed as policy, applied consistently, and updated as policy or risk changes. This is a defensible target for most outcomes.
4AdaptiveContinuously improved, informed by lessons learned and predictive indicators, integrated into enterprise risk decisions.

For each of the 106 subcategories, you record two ratings: your Current state and your Target state. That pairing is the whole game. CSF 2.0 calls these the Current Profile and the Target Profile, and the distance between them is your gap. Do not set every Target to Tier 4. A realistic Target Profile sets higher targets where risk or a mandate is greater, and accepts lower tiers where a cost-benefit analysis does not justify the spend. An honest assessment has Targets at 2 and 3 in places.

riskposture.tools/app/csf · CSF 2.0 Self-Assessment
GOVERN (GV) · Roles, Responsibilities & Authorities3 of 4 scored
GV.RR-01 Leadership accountable for cyber riskCurrent 2 → Target 3
GV.RR-02 Roles & responsibilities establishedCurrent 1 → Target 3
GV.RR-03 Adequate resources allocatedCurrent 3 → Target 3
Largest gap in this category: GV.RR-02 (Current 1 → Target 3). 2-tier gap.

The mock shows the mechanic. Each subcategory carries a short outcome statement, a Current rating, and a Target rating. Scoring all six functions is roughly 106 of these decisions. In the browser tool the per-function progress and the running gap update as you go, so you can stop and resume without losing your place.

Step 3: Read the gap analysis

Once Current and Target are set, the CSF gap analysis is just arithmetic: gap = Target minus Current, per subcategory, rolled up by Category and Function. But reading it well is a skill. Three things to look at, in order:

The output you want is not "we scored 2.3 out of 4." Averages hide the subcategories that matter. The useful output is a ranked list of the largest gaps, grouped by Function, with the outcome statement attached so a reader who has never heard of GV.RR-02 understands what the gap is.

Step 4: Turn gaps into a plan

A gap list is not a plan. To make it actionable, each significant gap needs an owner, a rough effort estimate, and a target date. This is where a CSF assessment feeds directly into the rest of your GRC program. The largest gaps become entries in a remediation backlog, and the riskiest ones become formal items in a POA&M Tracker or risk register. CSF tells you what is weak; your POA&M tracks the commitment to fix it.

A workable sequence for converting the gap analysis into a plan:

Tip: Save your first assessment as the baseline before you touch anything. The story leadership responds to is not "here is our score," it is "here is what closed since last quarter and here is what is still open." That requires two dated snapshots, so capture the first one cleanly.

Do it without a spreadsheet

You can run all of this in a spreadsheet. People do. But you will hand-key 106 outcome statements, fight with conditional formatting to make gaps visible, and recompute rollups by hand every time a rating changes. The free, browser-based CSF 2.0 self-assessment tool ships the full Core (all 6 functions, 22 categories, 106 subcategories) with the outcome statements already in place, scores Current and Target per subcategory, and computes the gap analysis and function rollups as you go. It runs entirely in your browser, no account, and your assessment data never leaves your device, which matters when you are rating your own control weaknesses.

It is genuinely free to use for the assessment itself. The Pro tier ($179/yr) adds the things you want once you commit to re-baselining: save, import, and export (JSON and CSV), print and PDF reports for leadership, a roll-up dashboard across tools, and trend tracking that compares snapshots over time so you can show movement quarter over quarter. If you are doing CSF once to scope a project, the free path is complete. If CSF becomes part of how you report posture, the trend view is the reason to upgrade.

This is also the most practical NIST CSF 2.0 assessment template you can use, because it is not a static document you have to interpret. The structure, the rubric, and the gap math are built in, and the output is the ranked, function-grouped gap list you need to brief a budget owner.

Frequently asked questions

Is a NIST CSF 2.0 self-assessment a certification with a pass/fail score?

No. CSF 2.0 is not a certification and there is no pass/fail score. Unlike CMMC or a FedRAMP authorization, no assessor signs off and no number gets reported to a government system of record. A CSF self-assessment is a management tool that tells you and your leadership where your cybersecurity outcomes stand and where to invest next, so treat it as a planning instrument, not an audit.

How many functions and subcategories are in NIST CSF 2.0?

CSF 2.0 has six Functions. It added GOVERN (GV) to the five from CSF 1.1 (Identify, Protect, Detect, Respond, Recover). The full Core is organized into 6 Functions, 22 Categories, and 106 Subcategories, down from 108 in 1.1. The Subcategory is the unit you score.

How do you score each subcategory in a CSF 2.0 self-assessment?

CSF 2.0 defines four Implementation Tiers (1 Partial, 2 Risk Informed, 3 Repeatable, 4 Adaptive) that translate into a per-subcategory rubric. For each of the 106 subcategories you record two ratings: your Current state and your Target state. The distance between them is your gap, computed as Target minus Current. A realistic Target Profile does not set every target to Tier 4; it sets higher targets where risk or a mandate is greater and accepts lower tiers where a cost-benefit analysis does not justify the spend.

Is the CSF 2.0 assessment tool free to use?

Yes. The browser-based CSF 2.0 assessment tool is genuinely free to use for the assessment itself. It ships the full Core (6 functions, 22 categories, 106 subcategories) with the outcome statements in place, scores Current and Target per subcategory, and computes the gap analysis as you go. It runs entirely in your browser with no account, and your assessment data never leaves your device. The Pro tier ($179/yr) adds save, import and export, print and PDF reports, a roll-up dashboard, and trend tracking across snapshots.

Related reading

References
  1. NIST, "The NIST Cybersecurity Framework (CSF) 2.0," NIST CSWP 29, February 2024. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
  2. NIST, "NIST Releases Version 2.0 of Landmark Cybersecurity Framework," News Release, February 26, 2024. https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
  3. NIST, "NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using the CSF Tiers," NIST SP 1302. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1302.pdf
  4. NIST, "NIST Cybersecurity Framework 2.0: Resource & Overview Guide," NIST SP 1299. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1299.pdf
  5. NIST, "The NIST CSF 2.0 Core With Withdrawn CSF 1.1 Elements," March 2024 (Subcategory mapping, 106 vs 108). https://www.nist.gov/system/files/documents/2024/03/25/The_NIST_CSF_2-0_Core_With_Withdrawn_CSF_1-1_Elements.pdf

Run your CSF 2.0 self-assessment now

Score all 106 subcategories against Current and Target tiers, see your gap analysis roll up by function in real time, and keep every rating on your own device. No account, no upload, free to use.