Gap analysis · NIST Cybersecurity Framework 2.0
Where are our gaps?
Answer 106 questions about how your organisation actually works, and see which parts of NIST Cybersecurity Framework 2.0 you would struggle to evidence. Every question explains itself as it is asked.
The baseline is every CSF 2.0 Core outcome that applies to you. This asks whether each one is achieved, on your own account, and reports the ones you said were not. That baseline is not a Target Profile. NIST's own method is to set a Target Profile from your mission, your obligations, the threats you face and your risk appetite — and a considered Target Profile may deliberately leave some outcomes partly achieved and push others further than the Core describes. Nobody has done that for you here. This tells you where you stand against the Core; it does not tell you where you ought to stand.
- About 65 minutes.
- No account, and no email needed to see your result.
- Nothing leaves your browser unless you ask for the full report.
First, a few things about you
Loading the questions…