Build a NIST CSF 2.0 Current-vs-Target Profile.
Rate every one of the 22 NIST Cybersecurity Framework 2.0 categories on a plain 1–4 implementation level, set where you want each to be, and the workbook surfaces the largest gaps in one sorted table you can export. It runs entirely in your browser.
Self-diagnostic workbook — this is not a DSE assessment, an audit, or an implementation tier certification. CSF 2.0 is a voluntary framework. The Functions and categories are NIST's; the 1–4 levels are our plain self-diagnostic scale — not NIST's Implementation Tiers, which characterize organization-wide risk governance rather than per-category scores. The gap is simply your target minus your current level.
Rate current, set target, read the gap.
For each category pick a Current level and a Target level. The gap column updates live. Score honestly — the value is the ordered list of where target exceeds today, not a single headline number.
Gap table — largest gap first
| CSF 2.0 category | Current | Target | Gap | Notes |
|---|
Turn the biggest gaps into a sequenced roadmap.
Bring your completed profile to a free 30-minute Cyber Risk Check. We talk through the largest gaps, the evidence you already have, and the next three moves — and scope a fixed-fee assessment only if it helps.
What this is and is not. This is a voluntary, point-in-time self-diagnostic workbook. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it does not rate or certify a CSF 2.0 Implementation Tier — the 1–4 levels here are a self-diagnostic scale, not NIST Tiers. Use it to focus a conversation, not to claim a posture.
Primary source, verified.