CSF 2.0 gave governance its own function, and that is where most programmes turn out to be thinnest. Thirty-one of the 106 subcategories now sit under Govern, ten of them on supply chain alone, and they are the ones nobody was scored against under version 1.1.

This assessment scores all 106 subcategories across the six functions, so you can show a board where the programme actually stands rather than where the tooling says it does. It is free, it saves as you go, and you can stop and come back to it.

What this is

A Current Profile, in CSF terms. You score each outcome as it stands today; the gap to where you want to be is your Target Profile, and the distance between them is the action plan. We have the background reading elsewhere — the framework explained, the new Govern function, the implementation tiers, maturity levels and what changed from 1.1. Come here when you want a score.

What it covers

FunctionCategoriesSubcategories
GOVERN — context, risk strategy, roles, policy, oversight, supply chain631
IDENTIFY — asset management, risk assessment, improvement321
PROTECT — access control, training, data, platform, infrastructure resilience522
DETECT — continuous monitoring, adverse event analysis211
RESPOND — incident management, analysis, reporting, mitigation413
RECOVER — recovery plan execution, recovery communication28

Why Govern changes the picture

Under CSF 1.1, governance was scattered through Identify and easy to answer generically. CSF 2.0 pulled it out and made it a peer of the other five, then expanded supply chain risk management from one category to ten subcategories inside it.

The practical effect is that organisations who scored well on 1.1 often score noticeably worse on 2.0 — not because anything got worse, but because the questions about risk appetite, oversight, supplier tiering and post-relationship data return were never asked before. Expect Govern to be your weakest function on the first run.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicableA justified exclusion, removed from the score

CSF is outcome-based rather than prescriptive, so there is no single right implementation. The scale measures whether the outcome is achieved and whether you could show it.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every subcategory with your status and notes, the score broken down by function and category, a prioritised gap list, and the documents from the NIST CSF Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 45 minutes. Govern and Identify take the longest because they ask organisational questions rather than technical ones, and those often need someone else in the room.

What to do with your score

Below 40% — start in Govern. Context, risk strategy and roles are cheap to establish and everything downstream leans on them.

40–70% — the usual shape, and usually uneven: strong in Protect, weak in Govern and Recover. Work the weakest function rather than the lowest single score.

Above 70% — build a Target Profile, set tiers, and use the gap between Current and Target as the roadmap. That is what CSF is designed for.

Frequently asked questions

Is this assessment really free?

Yes. All 106 subcategories, your function breakdown and your overall score cost nothing. The $39 report is optional.

Is CSF 2.0 a certification?

No. There is no certification against CSF, and anyone offering one is selling something else. It is a voluntary framework for describing and improving cybersecurity posture.

Does it cover CSF 1.1?

No — it scores 2.0, published February 2024. If you have a 1.1 profile, expect the Govern subcategories to be new to you.

Does it set implementation tiers?

Not directly. Tiers describe the rigour of your risk governance and are applied to a Profile. This gives you the Profile; the tier is a judgement you make on top of it.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.