risk-compliance · assessments · cybersecurity

NIST CSF Readiness Assessment

Scores cybersecurity readiness across the six NIST Cybersecurity Framework functions, Govern, Identify, Protect, Detect, Respond and Recover, from a weighted questionnaire. Use it for a self-assessment of security posture; the questions are original and a score is not evidence of compliance.

Last updated
Assessment Journey

Calculator overview

Inputs and outputs

This summary comes from the calculator's published input and output contract.

Inputs

Assessment Questions
About this input

One row per self-assessment question grouped under the Govern, Identify, Protect, Detect, Respond and Recover functions: enter a maturity score and a scope flag, and edit the weight if needed. The questions are written for this tool and are not the wording of the NIST Cybersecurity Framework, so a score is not evidence of conformance. A question marked not applicable is removed from both the numerator and the denominator, so it does not penalise the score. Every question needs a score and an applicability flag from the dropdowns; an entry that is blank or not on the list makes the tool refuse to score rather than guess.

Default 23 rows
ColumnRange or allowed values
Category Not declared
Question Not declared
Weight At least 0
Score 0 - Not in place, 1 - Ad hoc, 2 - Partially in place, 3 - Largely in place, 4 - Fully in place, 5 - Fully in place and verified
Applicability Applicable, Not applicable

Outputs

Share Not Applicable
About this output

The questions marked not applicable as a percent of all questions, a check on how much of the set was excluded.

Unit %
Second Priority
About this output

The in-scope question with the second largest weighted gap to a full score.

Unit question
Questions Not Applicable
About this output

The number of questions marked not applicable. These are removed from both the numerator and the denominator, so they neither help nor penalise the score.

Unit count
Share Of The Total Gap In The Top Three
About this output

The combined weighted gap of the top three priorities as a percent of the whole gap to a full score, showing how concentrated the improvement is.

Unit %
Total Weight In Scope
About this output

The sum of the weights of the questions in scope, as a weight total. It is the denominator the readiness score is measured against.

Unit weight
Top Priority
About this output

The in-scope question contributing the largest weighted gap to a full score, the single item worth the most improvement.

Unit question
Third Priority
About this output

The in-scope question with the third largest weighted gap to a full score.

Unit question
Questions In Scope
About this output

The number of questions marked applicable and therefore included in the readiness score.

Unit count
Lowest Scoring Category
About this output

The function with the weakest weighted score, the natural place to focus first.

Unit category
Highest Scoring Category
About this output

The function, Govern, Identify, Protect, Detect, Respond or Recover, with the strongest weighted score.

Unit category
Category Scores
About this output

One row per function: its weighted score in percent and its share of the total weight, so you can see where the overall figure comes from.

No unit declared
Model Status
About this output

The overall check on your entries, shown above the results. It reads OK when the inputs are usable, NOT VALID with a reason when an entry makes the model meaningless, or CHECK with a reason when a result is valid but worth a second look. Read it before you trust the numbers below.

No unit declared
Points Available To Gain
About this output

The total weighted gap to a full score: the sum over the questions in scope of weight times score shortfall. It is measured in raw weight-times-score points on your own weight scale, not in percentage points, so re-weighting changes it even when the answers do not.

Unit points
Overall Score
About this output

The weighted maturity score across the questions in scope, in percent, combining each answer with its weight. It reflects self-reported maturity, not an assessed result.

Unit %
Overall Band
About this output

The maturity band, from Not established to Optimised, read from the overall score. The band is a summary of your answers, not a certification.

Unit band

What it is

This is a cybersecurity readiness self-assessment. You score 23 questions about your organisation's security practices, each on a scale from zero to five, and it returns a weighted readiness score as a percentage, a band, a score for each of six security functions, and a ranked list of the gaps worth closing first.

What it is not. The 23 questions were written for this workbook. They are not the NIST Cybersecurity Framework's own control wording, they do not cover the framework exhaustively, and completing this assessment tells you nothing about conformance to it. The questions are grouped under the six function names the framework uses because that grouping is publicly documented and widely understood, and those names are referenced as a factual matter only. The weights, the rating scale and the band boundaries are all editable and carry no official standing. A score from this page is not a certification, an audit result, or evidence of compliance with any framework, standard or regulation.

What it is good for is an honest first picture of where a small or mid-sized organisation stands, and a defensible order of work. The weighted gap list is the most useful output: it tells you what to fix first rather than only what is broken.

Methodology

Purpose and model boundary

This model scores self-reported cybersecurity practice maturity across twenty-three original questions grouped under the six NIST Cybersecurity Framework 2.0 function names: Govern, Identify, Protect, Detect, Respond and Recover. It returns function scores, an overall maturity score and band, and a weighted list of improvement priorities.

The function names provide a familiar organizing structure only. The workbook does not reproduce the CSF Core, assess CSF outcomes or subcategories, create a Current or Target Profile, assign a CSF Tier, or determine conformance. Its questions and scoring scheme are original.

Inputs and units

Each fixed question row includes:

Field Meaning and restriction
Function and question Locked workbook text. Questions are not CSF wording.
Weight, w_i Nonnegative integer expressing importance within the function.
Score, s_i Required choice mapped to 0 through 5, from Not in place to Fully in place and verified.
Applicability, a_i Required choice mapped to 1 for Applicable or 0 for Not applicable.

The published model uses fixed function weights: Govern 15, Identify 15, Protect 25, Detect 15, Respond 15 and Recover 15. Maturity bands start at 0% Not established, 25% Initial, 45% Developing, 65% Managed and 85% Optimised. These weights and bands are not CSF concepts or official thresholds.

Governing relationships

For function c and maximum score s_max = 5:

FunctionScore_c = sum over i in c (w_i × s_i × a_i) / (s_max × sum over i in c (w_i × a_i))

Not-applicable questions are excluded from both sums. A function with no applicable questions is reported as not assessed and excluded from the overall function-weight denominator.

With fixed function weight W_c:

OverallScore = sum over assessed c (W_c × FunctionScore_c) / sum over assessed c W_c

The workbook selects the highest maturity-band threshold reached by 100 × OverallScore.

For improvement ranking:

Gap_i = w_i × (s_max - s_i) × a_i

Points_Available_To_Gain = sum(Gap_i)

Only positive applicable gaps receive a priority rank. A small row-index term makes tied gaps unique. The top-three gap share is the sum of gaps ranked 1 through 3 divided by the total gap, returning zero when there is no gap.

Calculation sequence

  1. Validate all 23 score labels, applicability labels and weights.
  2. Translate categorical entries into numeric score and applicability flags.
  3. Calculate weighted score and weighted gap for each applicable question.
  4. Calculate a score and maturity band for every assessed CSF function.
  5. Combine assessed functions with the six fixed function weights.
  6. Rank positive question gaps and return the top three priorities.
  7. Calculate scope counts, category extrema, total gap and top-three share.
  8. Evaluate Model_Status using the exact precedence below.

Outputs and interpretation

Overall_Score is a custom weighted maturity summary. Overall_Band describes that custom score and is not a CSF Implementation Tier. The category table and chart show within-function question scores, not the completeness of a CSF Profile or coverage of CSF outcomes.

Points_Available_To_Gain is a raw weight-times-shortfall total, not a percentage-point difference. Priorities rank weighted gaps, and the highest and lowest function outputs consider only functions with at least one applicable question.

Validation and status logic

The workbook evaluates status in this order:

Condition Returned status
Fewer than all 23 score entries match the six-item score list NOT VALID: a score entry is blank or not one of the listed options
Fewer than all 23 applicability entries match the scope list NOT VALID: an applicability entry is blank or not one of the listed options
Any weight is not numeric NOT VALID: a weight is not a number
Any weight is blank NOT VALID: a weight is blank
Any weight is negative NOT VALID: a weight is negative
No question is Applicable NOT VALID: every question is marked not applicable, so there is nothing to score
Total weight across Applicable questions is zero NOT VALID: the total weight in scope is zero, so there is nothing to score
More than 25% of questions are Not applicable CHECK: more than a quarter of questions are marked not applicable; confirm that is right
Overall score is below 45% CHECK: the overall score is below the Developing band; treat the priority list as a work plan
None of the preceding conditions applies OK

Validation and denominator failures take precedence. A high exclusion share takes precedence over the low-score warning.

Assumptions and limitations

  • The results depend on self-reported answers and do not verify documents, technical configurations, control operation or risk outcomes.
  • The custom questions do not cover the complete CSF 2.0 Core and have no one-to-one mapping to its categories, subcategories or Informative References.
  • The model does not establish organizational scope, mission objectives, risk appetite, Current or Target Profiles, community profiles, implementation examples or Tiers.
  • Function weights, question weights, rating scale and maturity bands are illustrative and have no NIST standing.
  • Not applicable removes a question from the arithmetic. The calculator cannot decide whether an exclusion is justified for the organization's scope and risk context.
  • Averages can hide a severe weakness in one control or asset. Use the question-level gaps with evidence and risk analysis rather than treating the headline as a security conclusion.
  • The model does not estimate threat likelihood, business impact, control effectiveness or residual risk and should not replace a formal assessment.

Restrictions and non-computing states

The grid has exactly twenty-three rows and its function/question text is locked. Every weight, score and applicability cell is required, including a valid score label on rows marked Not applicable. The page refuses negative weights, unlisted choices, blanks and incorrect grid shape before workbook execution. The workbook requires at least one Applicable question and positive total in-scope weight.

Errors and warnings

A rejected entry means the submitted questionnaire did not satisfy the published input rules. Workbook NOT VALID means there is no meaningful denominator or an entry is malformed. Workbook CHECK retains the calculated custom score but asks the reader to confirm exclusions or use a below-Developing result as a work plan. Network and calculation-service failures are service conditions, not cybersecurity findings.

References

The workbook reproduces no text, control wording, question set or scoring scheme from any framework, standard or regulation. The six function names are publicly documented terminology and are referenced here as a factual matter. The sources below identify that terminology; they are not sources for the questions or the scoring, which were written for this workbook.

Framework and standard names are trademarks of their respective owners, and none of those owners endorses this workbook or the questions in it. Completing this assessment does not constitute or evidence compliance.

Additional source notes migrated from Methodology

The organizing function names come from the NIST Cybersecurity Framework 2.0, NIST CSWP 29. NIST's CSF Profiles guidance describes a use of the framework that this calculator does not implement. Neither source defines or endorses the workbook's questions, weights, bands or overall score.

Frequently asked questions

Does a good score here mean we are NIST CSF compliant?
No. The 23 questions were written for this workbook. They are not the framework's control wording, they do not cover it exhaustively, and the scoring scheme is this workbook's own. The result is a self-assessment of your own answers. It is not a certification, an audit result, or evidence of compliance with any framework, standard or regulation.
Why are there six functions when the framework I know has five?
Govern was added as a sixth function in version 2.0 of the NIST Cybersecurity Framework, published in February 2024. Version 1.1 had five: Identify, Protect, Detect, Respond and Recover. This assessment groups its questions under the six-function structure, with Govern carrying a weight of 15.
What does marking a question Not applicable actually do?
It removes the question from both the numerator and the denominator, so it neither helps nor penalises your score. It is not scored as zero, because that would punish you for something that does not apply to you. The effect is large: the workbook notes it moves the result by roughly eighteen percentage points on a representative set, so set the flag honestly. The page reports how many questions you excluded and what share of the total that is.
Why is a question I scored 3 ranked above one I scored 0?
Because priorities are ranked by weight times the shortfall from the maximum, not by the raw score. A heavily weighted question scoring 3 leaves a larger weighted gap than a lightly weighted question scoring 0. That is usually the right order for deciding what to fix first, since it points at the work with the most value rather than at the lowest number.
When should I score a control 5 rather than 4?
Score 5 only when the control is verified, meaning someone checks that it works and not merely that it exists. The scale reserves its top value for verification because a control nobody checks tends to decay. A policy that exists on paper but is not followed is not in place at all.
Can I change the weights and the bands?
Yes. The rating scale, the band boundaries, the per-question weights and the per-function weights are all on the workbook's Data sheet and are all editable. None of them has official standing. If you adjust them to your context, record what you changed, because the score is only comparable against itself under the same settings.
Why does my overall score not equal the average of the function scores?
Because both levels are weighted. Each function score is a weighted average of its own questions, and the overall score is a weighted average of the function scores using the function weights, where Protect carries 25 and the other five carry 15 each. Functions with no questions in scope read not assessed and are left out of the average rather than counted as zero.
What does the band tell me?
It is a plain-language label read off an editable table: Not established from 0 percent, Initial from 25, Developing from 45, Managed from 65 and Optimised from 85. It summarises your own answers and nothing more. The band boundaries carry no official standing and can be changed on the Data sheet.
This page is provided by LogicCommons for informational purposes only. Results are analysis outputs computed from the inputs you supply and are not engineering advice, a design, or a substitute for review by a licensed professional under the codes adopted where the work is built. Verify all inputs and results independently.

LogicCommons is in beta. If a result, label, or reference looks wrong, tell us here; we read every message.