Cyber Security Maturity Check
Twenty-four yes/no questions across the six NIST Cybersecurity Framework functions — Govern, Identify, Protect, Detect, Respond, Recover — to map your organisation's cyber security maturity end to end.
- 24 questions
- ± 10 minutes
Frequently asked questions
What is the NIST Cybersecurity Framework (CSF)?
A cyber security framework from NIST (United States) that organises security practice into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is framework-agnostic, so it can be used alongside other standards such as ISO 27001.
What is the difference between this and the ISO 27001 Readiness Check?
This questionnaire assesses general security practice maturity across the six NIST CSF functions as an initial picture. The ISO 27001 Readiness Check is more detailed and structured for organisations already targeting certification.
I'm just starting and don't know where to begin — is this questionnaire right for me?
Yes, it is the right starting point. The result points you to the area to strengthen first, whether that is governance, technical controls, or testing readiness.
Can the result be used for a report to management?
The result is an initial, self-assessed picture. For a formal report to management or the board, we recommend a structured maturity assessment by a consultant.
How long does it take?
About 10 minutes for 24 questions covering all six NIST Cybersecurity Framework functions.
Discuss your cyber security maturity roadmap
We help build a cyber security maturity improvement roadmap across all six NIST CSF functions, from quick wins to long-term programmes.