NIST CSF 2.0 Readiness Scorecard

Assess your organization’s cybersecurity maturity against NIST CSF 2.0 with 24 questions across all six Functions. Produce a score out of 72 with a per-Function breakdown — so you know exactly where your program stands and where to focus first.

What’s Inside

  • 24 Plain-Language Questions Across All Six Functions: Govern (5), Identify (4), Protect (5), Detect (3), Respond (4), and Recover (3). Each question describes a concrete organizational capability — no prior framework experience required to answer.
  • 0–3 Maturity Scale: Rate each capability as Not Started (0), Informal (1), Defined (2), or Managed (3). The scale measures current state, not aspirational targets, so your results reflect where your program actually stands today.
  • Per-Function Scoring with Interpretation Bands: A scoring table tallies results by Function and overall (max 72), with four readiness levels — Early Stage, Developing, Established, and Advanced — so you can communicate posture to leadership in a single number and pinpoint which Functions need attention.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo