NIST CSF 2.0 Self-Assessment Questionnaire

Assess your organization against all 106 NIST CSF 2.0 Subcategories with plain-language questions, implementation tiers, and evidence fields — designed to be distributed across business units and teams — for a complete picture of what you’ve done, what’s in progress, and what’s missing.

What’s Inside

  • 106 Questions Across All Six Functions: One plain-language question per CSF 2.0 Subcategory — Govern (31), Identify (21), Protect (22), Detect (11), Respond (13), and Recover. Each question includes the official NIST requirement text and implementation examples so you know exactly what “good” looks like.
  • Five-Tier Scoring with Weighted Priorities: Rate each Subcategory from Not Started (0) through Partial, Risk Informed, Repeatable, to Adaptive (1.0). Adjustable weight columns let you prioritize Subcategories that matter most to your organization. The Scorecard sheet auto-calculates results by Function and Category as you go.
  • Evidence and Notes Per Subcategory: A dedicated column for documenting the policies, procedures, tools, and artifacts that support each rating. When the assessment is complete, the evidence column gives you a documented record of what supports each rating.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Book a Demo