Skip to main content
TOOLS

NIST CSF 2.0 Readiness Check

Ten operating questions across the six functions — Govern, Identify, Protect, Detect, Respond, Recover. Answer honestly; your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

NIST CSF 2.0 is a voluntary framework — no law, and no official certification scheme attaches to it. It organizes security outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover. The check scores one operating question per core category.

0/10
  1. 1.Govern: does the enterprise risk strategy explicitly include cybersecurity, with roles, responsibilities and authority assigned?

    GV.RM, GV.RR — risk strategy, roles and authority

  2. 2.Policy: is cybersecurity policy established, communicated and enforced — including its performance being overseen?

    GV.PO, GV.OV — policy and oversight

  3. 3.Supply chain: are suppliers and their dependencies part of the risk program — assessed before and during the relationship?

    GV.SC — cybersecurity supply chain risk management

  4. 4.Identify: is there an inventory of hardware, software, data and the systems that support the mission — with owners assigned?

    ID.AM — asset management

  5. 5.Risk: are cybersecurity risks identified, analysed and prioritized — with improvement actions tracked to closure?

    ID.RA, ID.IM — risk assessment and improvement

  6. 6.Protect — identity and data: are identities authenticated (MFA where it matters), access kept least-privilege, and data protected at rest and in transit?

    PR.AA, PR.DS — identity, access and data security

  7. 7.Protect — people: does the workforce get role-appropriate security awareness and training?

    PR.AT — awareness and training

  8. 8.Protect — platforms: are systems managed and hardened through their lifecycle, and is the infrastructure resilient enough to degrade safely?

    PR.PS, PR.IR — platform security and infrastructure resilience

  9. 9.Detect: is the environment continuously monitored for anomalies — and are adverse events analysed and declared incidents on a defined basis?

    DE.CM, DE.AE — continuous monitoring and analysis

  10. 10.Respond and recover: is there a practised incident process that mitigates and communicates — and a recovery plan executed to restore normal operations?

    RS.MA, RS.MI, RC.RP — incident management, mitigation, recovery

0%

NIST CSF 2.0 readiness

Answer to score

What the score means

80–100% · Low risk

Outcomes exist and can mostly be shown. Next step: continuous evidence — the CSF is an operating model, not an annual snapshot.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with the Govern function — strategy, roles, policy — then the asset inventory. The NIST CSF framework page maps both to operating controls.

The NIST CSF framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

What is new in NIST CSF 2.0?
The Govern function. CSF 1.1 had five functions; CSF 2.0 (February 2024) adds governance — strategy, roles, policy, oversight and supply-chain risk — as the function everything else reports into. The check scores it in the first three questions.
Can you be certified in NIST CSF?
No — the framework has no official certification scheme. Organizations profile themselves against it (Current Profile vs Target Profile) and may map to certifiable schemes like ISO 27001 or audited regimes like CMMC. The check scores the outcomes those profiles describe.
Is NIST CSF only for US organizations?
It is US-published but used worldwide — it is a vocabulary for security outcomes, and buyers in regulated markets increasingly recognize it. EU organizations typically run it alongside NIS2 or ISO 27001 rather than instead of them.
Is the score an official NIST assessment?
No — NIST does not assess anyone. It is an indicative maturity score from ten questions mapped to the framework's categories; it tells you where the outcomes are missing, not that any authority has judged you.