Measure your cybersecurity maturity against the framework a board, an insurer, or a customer is most likely to ask about. Three ways to do it, depending on whether you need a number for yourself or evidence someone else will accept.
Take the Free Self-AssessmentThe Cybersecurity Framework is the most common way an outside party asks how mature your security actually is, because the answer does not depend on your industry or your tooling.
A NIST cybersecurity framework assessment answers that question in a way an outsider can check. Version 2.0, published in February 2024, restructured the framework around six functions rather than the five most people still quote, across 22 categories and 106 CSF 2.0 subcategories:
We score your current maturity and the target your business case actually needs, which is rarely the highest one, and write the distance between them up as a sequenced plan. That distance is the CSF 2.0 gap analysis, and it is the part you can act on. The framework is voluntary, so the value is not a certificate; it is a common vocabulary you can hand to a board or a customer that maps cleanly onto the HIPAA, ISO 27001, and PCI DSS work you may already be doing.
The difference between these is not depth for its own sake. It is who stands behind the answer, and whether anyone independent has looked at your evidence. Start with the free NIST CSF self assessment and move up only when someone else needs convincing.
For your own planning
Score your organization against all 22 CSF 2.0 categories on a four-point scale, current state against the target you need. Around 15 minutes.
An indicative score and a prioritized gap list.
For a board, an insurer, or a customer questionnaire
You score all 106 subcategories and submit your evidence through our client portal. Our auditors review every item and either accept it or send it back with a comment explaining what is missing.
A findings report and remediation roadmap, reviewed by a certified auditor.
For a regulator, or anywhere your word is not enough
Our auditors do the work. We test your controls independently rather than reviewing what you selected, and the opinion at the end is ours, not yours.
An independent opinion a third party will accept at face value.
Where tier 2 stops, and why. A reviewed assessment is built on evidence you selected and submitted. Our auditors examine it and tell you where it falls short, which is a genuinely useful answer and the right one for most internal and commercial purposes. It is not independent testing, so it does not end in an Auditor Opinion Letter. Only the full engagement does, because only there have we gathered and tested the evidence ourselves. Any firm willing to issue you an opinion on evidence it did not test is selling you something it should not.
Common questions about cybersecurity maturity assessment against the NIST Cybersecurity Framework.
It measures how mature your cybersecurity program is against the NIST Cybersecurity Framework 2.0, across its six functions: Govern, Identify, Protect, Detect, Respond, and Recover. You get a score for where you are now, a target for where your business case says you need to be, and the gap between them written up as a sequenced plan. The framework is voluntary, so the value is not a certificate; it is a common vocabulary a board, an insurer, or a customer already understands.
Version 2.0, published in February 2024, added a sixth function, Govern, which covers who owns cybersecurity risk, how it is escalated, what the board sees, and how supply chain expectations are set. It is the function most organizations score worst on. CSF 2.0 also broadened the framework beyond critical infrastructure to organizations of any size and sector, and reorganized the categories and subcategories, retiring several that existed in 1.1.
Six functions, 22 categories, and 106 subcategories. Our free self assessment scores the 22 categories, which is enough to see the shape of your gaps in about 15 minutes. The reviewed assessment and the full audit both work at the level of all 106 CSF 2.0 subcategories, because that is where evidence actually attaches.
Yes, and it does not ask for anything until you have finished. It runs entirely in your browser, so your answers are never transmitted to us or to anyone else. You score 22 categories, see a maturity radar, a category heatmap, and a gap list ordered by what to fix first, and you can print the report or save it to a file to continue on another computer.
In a reviewed assessment you score all 106 subcategories and submit your own evidence, and our auditors examine it and either accept each item or return it asking for more. In a full audit our auditors gather and test the evidence themselves. That difference decides the deliverable: a reviewed assessment ends in a findings report and a remediation roadmap, and a full audit ends in an Auditor Opinion Letter.
Because an opinion has to rest on evidence the auditor gathered and tested. A reviewed assessment rests on evidence you selected and submitted, which is genuinely useful and is the right level for most internal and commercial purposes, but it is not independent testing. Issuing an opinion on untested evidence would misrepresent what was done.
Yes. CSF 2.0 maps onto the control work those frameworks already require, so a cybersecurity framework audit usually reuses evidence you have gathered for them rather than duplicating it. It is common to run a CSF assessment as the umbrella view and keep the specific compliance audits underneath it.
The free self assessment takes about 15 minutes. A reviewed assessment depends on how quickly evidence is submitted, since the 106 subcategories are worked through over days or weeks with a review loop on each. A full audit engagement is scoped to your environment; we will give you a timeline with the quote.
Unlike a security consultant, Altius IT is certified as a Certified Information Systems Auditor to perform a security audit of your environment and issue reports and recommendations to secure your systems. Altius IT has been featured in 40+ publications and nationwide media outlets.
Strengthen your applications and network infrastructure against evolving threats.
Meet HIPAA, GDPR, NIST, ISO, PCI-DSS, SOX, and other compliance standards.
Safeguard sensitive data, intellectual property, and customer information.
Every engagement includes follow-up support to ensure vulnerabilities are properly mitigated.