Start Free, Score Yourself in 15 Minutes

NIST CSF 2.0 Maturity Assessment

Measure your cybersecurity maturity against the framework a board, an insurer, or a customer is most likely to ask about. Three ways to do it, depending on whether you need a number for yourself or evidence someone else will accept.

Take the Free Self-Assessment

What a Cybersecurity Maturity Assessment Measures

The Cybersecurity Framework is the most common way an outside party asks how mature your security actually is, because the answer does not depend on your industry or your tooling.

A NIST cybersecurity framework assessment answers that question in a way an outsider can check. Version 2.0, published in February 2024, restructured the framework around six functions rather than the five most people still quote, across 22 categories and 106 CSF 2.0 subcategories:

We score your current maturity and the target your business case actually needs, which is rarely the highest one, and write the distance between them up as a sequenced plan. That distance is the CSF 2.0 gap analysis, and it is the part you can act on. The framework is voluntary, so the value is not a certificate; it is a common vocabulary you can hand to a board or a customer that maps cleanly onto the HIPAA, ISO 27001, and PCI DSS work you may already be doing.

Pick the One That Matches Who Is Asking

The difference between these is not depth for its own sake. It is who stands behind the answer, and whether anyone independent has looked at your evidence. Start with the free NIST CSF self assessment and move up only when someone else needs convincing.

Tier 1

Free Self-Assessment

For your own planning

Score your organization against all 22 CSF 2.0 categories on a four-point scale, current state against the target you need. Around 15 minutes.

  • 22 categories, scored by you
  • Maturity radar and category heatmap
  • Gap list ordered by what to fix first
  • Printable report you can take to a meeting
  • Runs entirely in your browser; your answers are never transmitted
You get

An indicative score and a prioritized gap list.

Tier 3

Full Audit Engagement

For a regulator, or anywhere your word is not enough

Our auditors do the work. We test your controls independently rather than reviewing what you selected, and the opinion at the end is ours, not yours.

  • Controls tested independently by a certified auditor
  • Evidence gathered by us, not submitted by you
  • Fieldwork, interviews, and technical validation
  • Auditor Opinion Letter and Secure Seal
  • Three months of post-audit support included
You get

An independent opinion a third party will accept at face value.

Where tier 2 stops, and why. A reviewed assessment is built on evidence you selected and submitted. Our auditors examine it and tell you where it falls short, which is a genuinely useful answer and the right one for most internal and commercial purposes. It is not independent testing, so it does not end in an Auditor Opinion Letter. Only the full engagement does, because only there have we gathered and tested the evidence ourselves. Any firm willing to issue you an opinion on evidence it did not test is selling you something it should not.

NIST CSF 2.0 Questions We Get Asked

Common questions about cybersecurity maturity assessment against the NIST Cybersecurity Framework.

It measures how mature your cybersecurity program is against the NIST Cybersecurity Framework 2.0, across its six functions: Govern, Identify, Protect, Detect, Respond, and Recover. You get a score for where you are now, a target for where your business case says you need to be, and the gap between them written up as a sequenced plan. The framework is voluntary, so the value is not a certificate; it is a common vocabulary a board, an insurer, or a customer already understands.

Version 2.0, published in February 2024, added a sixth function, Govern, which covers who owns cybersecurity risk, how it is escalated, what the board sees, and how supply chain expectations are set. It is the function most organizations score worst on. CSF 2.0 also broadened the framework beyond critical infrastructure to organizations of any size and sector, and reorganized the categories and subcategories, retiring several that existed in 1.1.

Six functions, 22 categories, and 106 subcategories. Our free self assessment scores the 22 categories, which is enough to see the shape of your gaps in about 15 minutes. The reviewed assessment and the full audit both work at the level of all 106 CSF 2.0 subcategories, because that is where evidence actually attaches.

Yes, and it does not ask for anything until you have finished. It runs entirely in your browser, so your answers are never transmitted to us or to anyone else. You score 22 categories, see a maturity radar, a category heatmap, and a gap list ordered by what to fix first, and you can print the report or save it to a file to continue on another computer.

In a reviewed assessment you score all 106 subcategories and submit your own evidence, and our auditors examine it and either accept each item or return it asking for more. In a full audit our auditors gather and test the evidence themselves. That difference decides the deliverable: a reviewed assessment ends in a findings report and a remediation roadmap, and a full audit ends in an Auditor Opinion Letter.

Because an opinion has to rest on evidence the auditor gathered and tested. A reviewed assessment rests on evidence you selected and submitted, which is genuinely useful and is the right level for most internal and commercial purposes, but it is not independent testing. Issuing an opinion on untested evidence would misrepresent what was done.

Yes. CSF 2.0 maps onto the control work those frameworks already require, so a cybersecurity framework audit usually reuses evidence you have gathered for them rather than duplicating it. It is common to run a CSF assessment as the umbrella view and keep the specific compliance audits underneath it.

The free self assessment takes about 15 minutes. A reviewed assessment depends on how quickly evidence is submitted, since the 106 subcategories are worked through over days or weeks with a review loop on each. A full audit engagement is scoped to your environment; we will give you a timeline with the quote.

If You Want a Security Audit, You Need a Certified Auditor

Unlike a security consultant, Altius IT is certified as a Certified Information Systems Auditor to perform a security audit of your environment and issue reports and recommendations to secure your systems. Altius IT has been featured in 40+ publications and nationwide media outlets.

Fortify Your Information Systems

Strengthen your applications and network infrastructure against evolving threats.

Comply with Regulatory Requirements

Meet HIPAA, GDPR, NIST, ISO, PCI-DSS, SOX, and other compliance standards.

Protect Your Valuable Assets

Safeguard sensitive data, intellectual property, and customer information.

3 Months Free Post-Audit Support

Every engagement includes follow-up support to ensure vulnerabilities are properly mitigated.

30+
Years of Experience
50
Point Security Process
40+
Media Publications
1000+
Audits Completed
Why you need a certified auditor

Success Stories & Resources

See how we have helped organizations ensure their systems are secure, meet security best practice requirements, and achieve compliance.

Other Services