Nobody enforces NIST CSF against you, which is why the shape of the programme is yours to decide. The method is a profile: rate where each outcome stands today, set the level you are prepared to fund, and treat the distance between the two as the roadmap. Two decisions come before any scoring: what each maturity rating means, agreed across the team, and which target you can defend. Start with Govern, because ownership and review decisions make the other five functions coherent. Once the first profile exists, the question becomes how to keep it alive, and that is where tooling earns or fails its place.
2 pages on NIST CSF 2.0, in the order the work happens. Jump to the stage you are at, or read straight through.
Score all six functions against an agreed rating scale, set a target you can fund, and read the gap column as your priority list.
Judge platforms on maturity scoring, Govern coverage and Current versus Target profiles, not on whether NIST CSF appears in a logo list.
The free compliance check runs the NIST CSF 2.0 gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users