← GRC Hub

📊 NIST CSF 2.0 Self-Assessment

Rate your organisation against all six CSF 2.0 Functions at Category level. 22 categories, 0–4 maturity scale. Stored only in your browser.

CSF 2.0 (NIST CSWP 29, February 2024) · NIST source ↗ · methodology

GV Govern

Cybersecurity strategy, expectations and policy established and overseen.

Function mean: 0.0 / 4
GV.OC · Organizational Context

Mission, stakeholders, dependencies, legal and regulatory requirements understood and informing cybersecurity risk management.

GV.RM · Risk Management Strategy

Priorities, constraints, risk tolerance, and assumptions established and used to support operational risk decisions.

GV.RR · Roles, Responsibilities, and Authorities

Cybersecurity roles, responsibilities, and authorities established and communicated to foster accountability and performance.

GV.PO · Policy

Organizational cybersecurity policy established, communicated, and enforced.

GV.OV · Oversight

Results of organization-wide cybersecurity risk management activities and performance used to inform, improve, and adjust strategy.

GV.SC · Cybersecurity Supply Chain Risk Management

Supply chain risk management processes identified, established, managed, monitored, and improved.

ID Identify

Current cybersecurity risks to the organization understood.

Function mean: 0.0 / 4
ID.AM · Asset Management

Assets that enable the organization to achieve business purposes identified and managed consistent with their relative importance to organizational objectives and the risk strategy.

ID.RA · Risk Assessment

Cybersecurity risk to the organization, assets, and individuals understood by the organization.

ID.IM · Improvement

Improvements to organizational cybersecurity risk management processes, procedures, and activities identified across all CSF Functions.

PR Protect

Safeguards to manage cybersecurity risks used.

Function mean: 0.0 / 4
PR.AA · Identity Management, Authentication, and Access Control

Access to physical and logical assets limited to authorized users, services, and hardware and managed commensurate with risk.

PR.AT · Awareness and Training

Personnel provided with cybersecurity awareness and training so they can perform their cybersecurity-related tasks.

PR.DS · Data Security

Data managed consistent with the organization's risk strategy to protect confidentiality, integrity, and availability.

PR.PS · Platform Security

Hardware, software, and services of physical and virtual platforms managed consistent with the organization's risk strategy.

PR.IR · Technology Infrastructure Resilience

Security architectures managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience.

DE Detect

Possible cybersecurity attacks and compromises found and analyzed.

Function mean: 0.0 / 4
DE.CM · Continuous Monitoring

Assets monitored to find anomalies, indicators of compromise, and other potentially adverse events.

DE.AE · Adverse Event Analysis

Anomalies, indicators of compromise, and other potentially adverse events analyzed to characterize the events and detect cybersecurity incidents.

RS Respond

Actions regarding a detected cybersecurity incident taken.

Function mean: 0.0 / 4
RS.MA · Incident Management

Responses to detected cybersecurity incidents managed.

RS.AN · Incident Analysis

Investigations conducted to ensure effective response and support forensics and recovery activities.

RS.CO · Incident Response Reporting and Communication

Response activities coordinated with internal and external stakeholders as required by laws, regulations, or policies.

RS.MI · Incident Mitigation

Activities performed to prevent expansion of an event and mitigate its effects.

RC Recover

Assets and operations affected by a cybersecurity incident restored.

Function mean: 0.0 / 4
RC.RP · Incident Recovery Plan Execution

Restoration activities performed to ensure operational availability of systems and services affected by cybersecurity incidents.

RC.CO · Incident Recovery Communication

Restoration activities coordinated with internal and external parties.

Informational only — not legal advice. Maturity scores reflect editorial paraphrases of NIST CSF 2.0 Implementation Tier descriptions. Verify against the published NIST CSWP 29 before relying on this output. No data leaves your browser.