Calculator overview
Inputs and outputs
This summary comes from the calculator's published input and output contract.
Inputs
- Assessment Questions
-
Default 23 rows
About this input
One row per self-assessment question grouped under the Govern, Identify, Protect, Detect, Respond and Recover functions: enter a maturity score and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the wording of the NIST Cybersecurity Framework, so a score is not evidence of conformance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.
Column Range or allowed values Category Not declared Question Not declared Weight At least 0 Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified Applicability Applicable, Not applicable
Outputs
- Share Not Applicable
-
Unit %
About this output
The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.
- Second Priority
-
Unit question
About this output
The in-scope question with the second largest weighted gap to a full score.
- Questions Not Applicable
-
Unit count
About this output
The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.
- Share Of The Total Gap In The Top Three
-
Unit %
About this output
The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the improvement is.
- Total Weight In Scope
-
Unit weight
About this output
The sum of the weights of the questions in scope, as a weight total. It is the denominator the readiness score is measured against.
- Top Priority
-
Unit question
About this output
The in-scope question contributing the largest weighted gap to a full score, the single item worth the most improvement.
- Third Priority
-
Unit question
About this output
The in-scope question with the third largest weighted gap to a full score.
- Questions In Scope
-
Unit count
About this output
The number of questions marked applicable and therefore included in the readiness score.
- Lowest Scoring Category
-
Unit category
About this output
The function with the weakest weighted score, the natural place to focus first.
- Highest Scoring Category
-
Unit category
About this output
The function, Govern, Identify, Protect, Detect, Respond or Recover, with the strongest weighted score.
- Category Scores
-
No unit declared
About this output
One row per function: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.
- Model Status
-
No unit declared
About this output
The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.
- Points Available To Gain
-
Unit points
About this output
The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.
- Overall Score
-
Unit %
About this output
The weighted maturity score across the questions in scope, in percent, combining each answer with its weight. It reflects self-reported maturity, not an assessed result.
- Overall Band
-
Unit band
About this output
The maturity band, from Not established to Optimised, read from the overall score. The band is a summary of your answers, not a certification.
What it is
This is a cybersecurity readiness self-assessment. You score 23 questions about your organisation's security practices, each on a scale from zero to five, and it returns a weighted readiness score as a percentage, a band, a score for each of six security functions, and a ranked list of the gaps worth closing first.
What it is not. The 23 questions were written for this workbook. They are not the NIST Cybersecurity Framework's own control wording, they do not cover the framework exhaustively, and completing this assessment tells you nothing about conformance to it. The questions are grouped under the six function names the framework uses because that grouping is publicly documented and widely understood, and those names are referenced as a factual matter only. The weights, the rating scale and the band boundaries are all editable and carry no official standing. A score from this page is not a certification, an audit result, or evidence of compliance with any framework, standard or regulation.
What it is good for is an honest first picture of where a small or mid-sized organisation stands, and a defensible order of work. The weighted gap list is the most useful output: it tells you what to fix first rather than only what is broken.
Methodology
Purpose and model boundary
This model scores self-reported cybersecurity practice maturity across twenty-three original questions grouped under the six NIST Cybersecurity Framework 2.0 function names: Govern, Identify, Protect, Detect, Respond and Recover. It returns function scores, an overall maturity score and band, and a weighted list of improvement priorities.
The function names provide a familiar organizing structure only. The workbook does not reproduce the CSF Core, assess CSF outcomes or subcategories, create a Current or Target Profile, assign a CSF Tier, or determine conformance. Its questions and scoring scheme are original.
Inputs and units
Each fixed question row includes:
| Field | Meaning and restriction |
|---|---|
| Function and question | Locked workbook text. Questions are not CSF wording. |
Weight, w_i |
Nonnegative integer expressing importance within the function. |
Score, s_i |
Required choice mapped to 0 through 5, from Not in place to Fully in place and verified. |
Applicability, a_i |
Required choice mapped to 1 for Applicable or 0 for Not applicable. |
The published model uses fixed function weights: Govern 15, Identify 15, Protect 25, Detect 15, Respond 15 and Recover 15. Maturity bands start at 0% Not established, 25% Initial, 45% Developing, 65% Managed and 85% Optimised. These weights and bands are not CSF concepts or official thresholds.
Governing relationships
For function c and maximum score s_max = 5:
FunctionScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))
Not-applicable questions are excluded from both sums. A function with no applicable questions is reported as not assessed and excluded from the overall function-weight denominator.
With fixed function weight W_c:
OverallScore = sum over assessed c (W_c × FunctionScore_c) / sum over assessed c W_c
The workbook selects the highest maturity-band threshold reached by 100 × OverallScore.
For improvement ranking:
Gap_i = w_i × (s_max - s_i) × a_i
Points_Available_To_Gain = sum(Gap_i)
Only positive applicable gaps receive a priority rank. A small row-index term makes tied gaps unique. The top-three gap share is the sum of gaps ranked 1 through 3 divided by the total gap, returning zero when there is no gap.
Calculation sequence
- Validate all 23 score labels, applicability labels and weights.
- Translate categorical entries into numeric score and applicability flags.
- Calculate weighted score and weighted gap for each applicable question.
- Calculate a score and maturity band for every assessed CSF function.
- Combine assessed functions with the six fixed function weights.
- Rank positive question gaps and return the top three priorities.
- Calculate scope counts, category extrema, total gap and top-three share.
- Evaluate
Model_Statususing the exact precedence below.
Outputs and interpretation
Overall_Score is a custom weighted maturity summary. Overall_Band describes that custom score and is not a CSF Implementation Tier. The category table and chart show within-function question scores, not the completeness of a CSF Profile or coverage of CSF outcomes.
Points_Available_To_Gain is a raw weight-times-shortfall total, not a percentage-point difference. Priorities rank weighted gaps, and the highest and lowest function outputs consider only functions with at least one applicable question.
Validation and status logic
The workbook evaluates status in this order:
| Condition | Returned status |
|---|---|
| Fewer than all 23 score entries match the six-item score list | NOT VALID: a score entry is blank or not one of the listed options |
| Fewer than all 23 applicability entries match the scope list | NOT VALID: an applicability entry is blank or not one of the listed options |
| Any weight is not numeric | NOT VALID: a weight is not a number |
| Any weight is blank | NOT VALID: a weight is blank |
| Any weight is negative | NOT VALID: a weight is negative |
| No question is Applicable | NOT VALID: every question is marked not applicable, so there is nothing to score |
| Total weight across Applicable questions is zero | NOT VALID: the total weight in scope is zero, so there is nothing to score |
| More than 25% of questions are Not applicable | CHECK: more than a quarter of questions are marked not applicable; confirm that is right |
| Overall score is below 45% | CHECK: the overall score is below the Developing band; treat the priority list as a work plan |
| None of the preceding conditions applies | OK |
Validation and denominator failures take precedence. A high exclusion share takes precedence over the low-score warning.
Assumptions and limitations
- The results depend on self-reported answers and do not verify documents, technical configurations, control operation or risk outcomes.
- The custom questions do not cover the complete CSF 2.0 Core and have no one-to-one mapping to its categories, subcategories or Informative References.
- The model does not establish organizational scope, mission objectives, risk appetite, Current or Target Profiles, community profiles, implementation examples or Tiers.
- Function weights, question weights, rating scale and maturity bands are illustrative and have no NIST standing.
- Not applicable removes a question from the arithmetic. The calculator cannot decide whether an exclusion is justified for the organization's scope and risk context.
- Averages can hide a severe weakness in one control or asset. Use the question-level gaps with evidence and risk analysis rather than treating the headline as a security conclusion.
- The model does not estimate threat likelihood, business impact, control effectiveness or residual risk and should not replace a formal assessment.
Restrictions and non-computing states
The grid has exactly twenty-three rows and its function/question text is locked. Every weight, score and applicability cell is required, including a valid score label on rows marked Not applicable. The page refuses negative weights, unlisted choices, blanks and incorrect grid shape before workbook execution. The workbook requires at least one Applicable question and positive total in-scope weight.
Errors and warnings
A rejected entry means the submitted questionnaire did not satisfy the published input rules. Workbook NOT VALID means there is no meaningful denominator or an entry is malformed. Workbook CHECK retains the calculated custom score but asks the reader to confirm exclusions or use a below-Developing result as a work plan. Network and calculation-service failures are service conditions, not cybersecurity findings.
References
The workbook reproduces no text, control wording, question set or scoring scheme from any framework, standard or regulation. The six function names are publicly documented terminology and are referenced here as a factual matter. The sources below identify that terminology; they are not sources for the questions or the scoring, which were written for this workbook.
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper 29, February 2024. https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final (the source of the six function names used as categories: Govern, Identify, Protect, Detect, Respond and Recover)
- National Institute of Standards and Technology. The CSF 1.1 Five Functions. https://www.nist.gov/cyberframework/csf-11-five-functions (the earlier five-function structure, before Govern was added in version 2.0)
- Wikipedia. NIST Cybersecurity Framework. https://en.wikipedia.org/wiki/NIST_Cybersecurity_Framework
Framework and standard names are trademarks of their respective owners, and none of those owners endorses this workbook or the questions in it. Completing this assessment does not constitute or evidence compliance.
Additional source notes migrated from Methodology
The organizing function names come from the NIST Cybersecurity Framework 2.0, NIST CSWP 29. NIST's CSF Profiles guidance describes a use of the framework that this calculator does not implement. Neither source defines or endorses the workbook's questions, weights, bands or overall score.
Frequently asked questions
Does a good score here mean we are NIST CSF compliant?
Why are there six functions when the framework I know has five?
What does marking a question Not applicable actually do?
Why is a question I scored 3 ranked above one I scored 0?
When should I score a control 5 rather than 4?
Can I change the weights and the bands?
Why does my overall score not equal the average of the function scores?
What does the band tell me?
Found a problem, or have an idea?
Tell us if a result looks wrong, a label is unclear, or something is missing. We read every message.
LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.