Free NIST CSF 2.0 Cybersecurity Self-Assessment

Get an evidence-based view of your cybersecurity maturity in about 20 minutes. 106 questions, mapped to all 6 NIST CSF 2.0 functions, with an instant maturity score and a sharable report.

What You Get

  • 106 questions across all 6 NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover)
  • Roughly 20 minutes to complete — designed for IT and security leaders
  • Free maturity score and high-level findings immediately after submission
  • Optional full PDF report with prioritized recommendations and remediation guidance
  • Benchmarking against industry peers and NIST CSF 2.0 target profiles

How It Works

Start in seconds

No credit card. Just an email to save your progress and deliver your report.

Answer 106 questions

Guided assessment across all 6 NIST CSF 2.0 functions, with plain-language prompts.

Get your report

Instant maturity score and a sharable, evidence-backed report you can use with your board, investors, or auditors.

Why NIST CSF 2.0

NIST Cybersecurity Framework 2.0 is the most widely adopted cybersecurity framework in the world, used by Fortune 500 enterprises, federal agencies, and PE-backed portfolio companies. Version 2.0 adds the Govern function, making it the most complete and board-relevant framework available today.

Because Diligenze uses the same NIST CSF 2.0 framework inside buy-side and sell-side technology due diligence engagements, your self-assessment results are directly comparable to what investors and acquirers would see.

Frequently Asked Questions

How long does the NIST self-assessment take?
Most people complete the 106-question assessment in around 20 minutes. Your progress is saved as you go, so you can pause and resume.
Is it really free?
Yes — you can take the full assessment and view your maturity score and high-level findings at no cost. A paid tier unlocks the full PDF report with detailed recommendations and benchmarking.
Which NIST framework version is used?
The assessment is built on NIST Cybersecurity Framework (CSF) 2.0, including the new Govern function alongside Identify, Protect, Detect, Respond, and Recover.
Who should take this assessment?
It is designed for CIOs, CISOs, IT leaders, MSP/MSSP customers, M&A diligence teams, and portfolio company executives who need a credible cybersecurity maturity baseline aligned to NIST CSF 2.0.
How is my data handled?
Your responses are stored securely in our backend and used only to generate your report. We do not sell or share your data, and you can request deletion at any time.
Can I use this for M&A or portfolio diligence?
Yes. The assessment is the same NIST CSF 2.0 framework Diligenze uses inside buy-side and sell-side technology due diligence engagements, so results are directly comparable.

Ready to see your cybersecurity maturity score?

Free, no credit card. About 20 minutes.