§ Cybersecurity proof & diagnostic assets·free · browser-local

Build a NIST CSF 2.0 Current-vs-Target Profile.

Rate every one of the 22 NIST Cybersecurity Framework 2.0 categories on a plain 1–4 implementation level, set where you want each to be, and the workbook surfaces the largest gaps in one sorted table you can export. It runs entirely in your browser.

Self-diagnostic workbook — this is not a DSE assessment, an audit, or an implementation tier certification. CSF 2.0 is a voluntary framework. The Functions and categories are NIST's; the 1–4 levels are our plain self-diagnostic scale — not NIST's Implementation Tiers, which characterize organization-wide risk governance rather than per-category scores. The gap is simply your target minus your current level.

About this asset

Audience
Security and risk owners planning a NIST CSF 2.0 improvement roadmap for a 50–500-person organization.
Owner service
Cybersecurity Risk Assessment & Roadmap
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The six Functions and their 22 categories are taken from NIST CSWP 29 (The NIST Cybersecurity Framework 2.0). Each category is rated on a plain 1–4 implementation level (not performed → optimized). These levels are DSE's self-diagnostic scale, not the CSF 2.0 Implementation Tiers, which NIST applies to organization-wide risk governance rather than individual categories. Gaps are plain target-minus-current arithmetic; no proprietary scoring is applied.
Limitations
Point-in-time, self-diagnostic workbook you complete yourself. It is not a DSE assessment, an audit, an attestation, or legal advice, and it produces no compliance result, tier rating, or certification.
Verification
The primary-source citation below was checked against the csrc.nist.gov landing page for NIST CSWP 29. Function and category names are cited to that source; the 1–4 levels are DSE's own self-diagnostic scale and are labeled as such. DSE added no requirement the source does not contain.
The workbook

Rate current, set target, read the gap.

For each category pick a Current level and a Target level. The gap column updates live. Score honestly — the value is the ordered list of where target exceeds today, not a single headline number.

CSF 2.0 category Current level Target level Gap Notes

Turn the biggest gaps into a sequenced roadmap.

Bring your completed profile to a free 30-minute Cyber Risk Check. We talk through the largest gaps, the evidence you already have, and the next three moves — and scope a fixed-fee assessment only if it helps.

What this is and is not. This is a voluntary, point-in-time self-diagnostic workbook. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it does not rate or certify a CSF 2.0 Implementation Tier — the 1–4 levels here are a self-diagnostic scale, not NIST Tiers. Use it to focus a conversation, not to claim a posture.

Primary source, verified.