A readiness assessment across all six Functions (Govern, Identify, Protect, Detect, Respond, Recover), a controls matrix covering every one of the 106 Subcategories, Current/Target Profile and Implementation Tier guides, and a prioritized roadmap. The clearest way to see where you stand and what to do next.
Score your readiness across the six Functions, set Current and Target Profiles for all 106 Subcategories, and work the roadmap to your target Tier. Instant download — no subscription.
For teams getting their first clear read on cyber posture.
For teams actively driving their CSF program forward.
The full program — all 106 Subcategories, Profiles, and Tiers.
Redirecting to secure checkout…
The free NIST CSF 2.0 readiness assessment scores you across the six Functions and shows your biggest gaps. The toolkit is how you close them — and the controls tracker turns it into your Current and Target Profiles across all 106 Subcategories.
No. The Cybersecurity Framework is a voluntary framework, not a certification or an audit. This toolkit produces a self-assessed readiness picture, your Current and Target Profiles, and a prioritized roadmap — so you can measure and improve your posture and speak about it credibly to customers, insurers, and your board.
CSF 2.0 — the current version, released in 2024. It adds the sixth Govern function and covers all 22 Categories and 106 Subcategories. That is what new adopters use today.
CSF is a risk-based framework and a common language for cybersecurity outcomes, not an audited certification. Many organizations use it to organize their whole program and map it to ISO 27001, SOC 2, and regulations. If you need a certificate or an attestation report, pair CSF with our ISO 27001 or SOC 2 toolkits.
No. You set a Target Profile based on your risk, obligations, and resources, then prioritize the gaps that matter most. The Controls Matrix lets you mark Current and Target state for each Subcategory so you can focus effort where it counts.
A Profile describes which outcomes you achieve — your Current Profile (where you are) versus your Target Profile (where you need to be). Implementation Tiers (1–4) describe how rigorous and adaptive your risk practices are. The toolkit includes dedicated guides for both.
Yes. Our vCISO team can run the assessment, build your Current and Target Profiles, and drive the roadmap to your target Tier. Start with the free assessment, or book a consultation.
If you'd rather we assess, build your Current and Target Profiles, and drive the roadmap to your target Tier, that's what our vCISO engagements are for. Tell us where you are and we'll recommend the right scope.