Cyber Security Maturity Check

Twenty-four yes/no questions across the six NIST Cybersecurity Framework functions — Govern, Identify, Protect, Detect, Respond, Recover — to map your organisation's cyber security maturity end to end.

  • 24 questions
  • ± 10 minutes
  1. 1Details
  2. 2
  3. 3
Before you start

Before you start

Four short fields so we can send you the result and follow up if you wish.

The result summary is sent to this address.

By continuing you agree that these details are used to send your result and to follow up, per our Privacy Policy.

24 questions · ± 10 minutes

Frequently asked questions

What is the NIST Cybersecurity Framework (CSF)?

A cyber security framework from NIST (United States) that organises security practice into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is framework-agnostic, so it can be used alongside other standards such as ISO 27001.

What is the difference between this and the ISO 27001 Readiness Check?

This questionnaire assesses general security practice maturity across the six NIST CSF functions as an initial picture. The ISO 27001 Readiness Check is more detailed and structured for organisations already targeting certification.

I'm just starting and don't know where to begin — is this questionnaire right for me?

Yes, it is the right starting point. The result points you to the area to strengthen first, whether that is governance, technical controls, or testing readiness.

Can the result be used for a report to management?

The result is an initial, self-assessed picture. For a formal report to management or the board, we recommend a structured maturity assessment by a consultant.

How long does it take?

About 10 minutes for 24 questions covering all six NIST Cybersecurity Framework functions.

Discuss your cyber security maturity roadmap

We help build a cyber security maturity improvement roadmap across all six NIST CSF functions, from quick wins to long-term programmes.