Free NIST Cybersecurity Framework (CSF) 2.0 Self-Check:
Are You Actually Aligned?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive NIST CSF 2.0 self-check below to get a real answer the next time a board member, an insurer, or a customer asks if you’re aligned to the framework.
Answer 6 quick questions, one for each of the six CSF 2.0 functions, and get your result in about 2 minutes: your risk level and the specific gaps to close first.
No sign-up to see your result.
What the NIST Cybersecurity Framework 2.0 Actually Covers
(the short version)
NIST released CSF 2.0 on February 26, 2024, and the biggest change from the original 2014 framework is a sixth function: Govern, sitting alongside the original five (Identify, Protect, Detect, Respond, Recover). Together the six functions break down into 22 categories and 106 subcategories, but almost nobody needs to work through all 106 line by line to get useful direction.
Unlike HIPAA or PCI DSS, CSF isn’t a law or a certification; it’s a common language and a structure for organizing a cybersecurity program, which is exactly why “are you aligned to NIST CSF” is such a hard question to answer off the cuff. It’s also why insurers, boards, and larger customers increasingly use it as a shared checklist, even for companies with no legal requirement to follow it.
The self-check below walks the six functions in order
The NIST CSF 2.0 Self-Check, Function by Function
Work through each function below. Anything you can’t confirm is a gap, if you can’t prove it to yourself, you won’t be able to prove it to a board, an insurer, or a customer either.
- 1. Govern:
✓ One specific person is formally accountable for cyber risk, with real authority to act and spend on what they find (not a title nobody has actually assigned).
✓ Cyber risk shows up in real business decisions, budget, vendor selection, new tools, not just an IT conversation that never reaches leadership.
✓ Someone can explain your cyber risk posture to a non-technical board member or owner in plain language, on request, without a scramble. - 2. Identify:
✓ A current, accurate inventory of your critical systems: servers, cloud apps, and devices.
✓ A written record of where sensitive data actually lives: customer records, financial data, employee data, across every system that touches it, not just the obvious one.
✓ A basic understanding of which vendors can reach that data, and what happens if one of them has a bad day. - 3. Protect:
✓ Multi-factor authentication required on the systems that matter most: email, financial systems, and anywhere customer or employee data is stored.
✓ That same data encrypted, at rest and in transit, not just on the “important” server.
✓ Unique logins for every user, no shared accounts, with access removed the same day someone changes roles or leaves. - 4. Detect:
✓ Active monitoring on the systems that matter most, not just logging that nobody looks at.
✓ A real person assigned to actually review what monitoring flags, on a regular schedule.
✓ A realistic sense of how fast you’d actually notice an intrusion in progress, versus finding out from a ransom note or a customer. - 5. Respond:
✓ A written incident response plan naming who does what: who can shut down a system, who calls your insurer, who calls a lawyer, who talks to customers.
✓ That plan actually walked through at least once, a tabletop exercise or a real incident, not just filed away.
✓ Clarity on your notification obligations if the incident involves other people’s data. - 6. Recover:
✓ Backups that someone has actually tested by restoring real data, on a real schedule, not just a job that shows “success” overnight.
✓ A documented sense of how long a real recovery would take, and whether that’s fast enough for your business to survive it.
✓ A short after-action habit: when something does go wrong, the fix gets fed back into Identify and Protect instead of being forgotten once the fire’s out.
How to read your gaps?
- 0 – 1 Gap (No Critical Gaps)
Strong Shape
- 2 – 5 Gaps (1 Critical Gap Max)
Real, findable holes that would read as an incomplete program to a board or an insurer
- 5+ Gaps (or 2+ Critical Gaps)
You’d likely come up short if asked to show alignment today, and depending on what you flagged, you’re carrying real breach or recovery risk right now.
NIST CSF 2.0 Self-Check FAQ
No. It’s a voluntary framework, not a law, and there’s no certification an organization (or an IT company) can hold that means “NIST CSF certified.” What you can do is align your program to it and be able to demonstrate that alignment, which is the gap this self-check and the fuller assessment behind it are built to close.
The biggest change is a sixth function, Govern, added specifically to address the “who owns this, and does leadership actually see it” gap that the original five functions (Identify, Protect, Detect, Respond, Recover) didn’t fully cover. CSF 2.0 also broadened its intended audience beyond critical infrastructure to organizations of any size or sector.
Because it’s become the common language insurers, boards, and larger customers reach for when they need a structured way to ask “is this a real program, or a patchwork of tools?” Even if you have no legal obligation to follow CSF, being able to answer in its terms is often the fastest way to satisfy that question.
No, and it says so above the tool: this is a streamlined, 6-question version, one question per function, built for a fast Low / Moderate / High read. A full maturity assessment scores your program against all 106 subcategories on a 0-4 scale and produces a function-by-function radar chart. That fuller version is a planned upgrade to this tool; this self-check is an honest, useful first read in the meantime, not a substitute for the complete one.
CSF is a general-purpose organizing structure, not a sector-specific rulebook. If you’re in healthcare, payments, or a government/defense supply chain, you likely have a sector-specific standard (HIPAA, PCI DSS, NIST 800-53 and its relatives) that’s the one you’re actually held to; CSF’s six functions still work as a useful, plain-language way to organize and explain that same program to people outside IT.
For most organizations it’s the same two things: name one accountable owner (Govern) and turn on MFA plus encryption everywhere your important data lives (Protect). Those two moves address the most common findings and are usually the fastest to put in place.
Yes. An untested plan is a document, not a capability, and the gap usually only shows up on the day it matters: wrong contact info, nobody sure who’s allowed to shut a system down.
Ready to close your gaps?
If your result flagged gaps in Govern, Protect, Detect, or Recover, most of that is IT and cybersecurity work an experienced partner handles day to day, not a policy-writing exercise.
LeadingIT helps Chicagoland organizations build the accountability, controls, monitoring, and tested recovery a real NIST CSF-aligned program requires, and put it in terms you can actually explain to a board or an insurer. We deliver this FOR clients; there’s no NIST CSF “certification” an IT company can hold, and we don’t claim one.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver managed cybersecurity services.