NIST CSF 2.0 Readiness Check
Ten operating questions across the six functions — Govern, Identify, Protect, Detect, Respond, Recover. Answer honestly; your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
NIST CSF 2.0 is a voluntary framework — no law, and no official certification scheme attaches to it. It organizes security outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover. The check scores one operating question per core category.
1.Govern: does the enterprise risk strategy explicitly include cybersecurity, with roles, responsibilities and authority assigned?
GV.RM, GV.RR — risk strategy, roles and authority
2.Policy: is cybersecurity policy established, communicated and enforced — including its performance being overseen?
GV.PO, GV.OV — policy and oversight
3.Supply chain: are suppliers and their dependencies part of the risk program — assessed before and during the relationship?
GV.SC — cybersecurity supply chain risk management
4.Identify: is there an inventory of hardware, software, data and the systems that support the mission — with owners assigned?
ID.AM — asset management
5.Risk: are cybersecurity risks identified, analysed and prioritized — with improvement actions tracked to closure?
ID.RA, ID.IM — risk assessment and improvement
6.Protect — identity and data: are identities authenticated (MFA where it matters), access kept least-privilege, and data protected at rest and in transit?
PR.AA, PR.DS — identity, access and data security
7.Protect — people: does the workforce get role-appropriate security awareness and training?
PR.AT — awareness and training
8.Protect — platforms: are systems managed and hardened through their lifecycle, and is the infrastructure resilient enough to degrade safely?
PR.PS, PR.IR — platform security and infrastructure resilience
9.Detect: is the environment continuously monitored for anomalies — and are adverse events analysed and declared incidents on a defined basis?
DE.CM, DE.AE — continuous monitoring and analysis
10.Respond and recover: is there a practised incident process that mitigates and communicates — and a recovery plan executed to restore normal operations?
RS.MA, RS.MI, RC.RP — incident management, mitigation, recovery
NIST CSF 2.0 readiness
Answer to scoreWhat the score means
80–100% · Low risk
Outcomes exist and can mostly be shown. Next step: continuous evidence — the CSF is an operating model, not an annual snapshot.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with the Govern function — strategy, roles, policy — then the asset inventory. The NIST CSF framework page maps both to operating controls.
The NIST CSF frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.