Skip to content

Assess and Comply

NIST CSF 2.0 Assessment

Scores your maturity across all six CSF 2.0 functions, tracks every gap to an owner, and produces the report your board asked for.

Audience
Compliance and CISO
Headline
Overall maturity score
Framework
NIST CSF 2.0
Output
Score, gaps, evidence

What it does

Inside NIST CSF 2.0

Maturity assessment across the six CSF functions with gap tracking and executive reporting.

Six-function scoring

Govern, Identify, Protect, Detect, Respond, and Recover, each scored with the controls behind the number.

Control-level assessment

Every control carries a status, an assessor, and the evidence supporting its score.

Gap tracking

Each gap has a priority, an owner, and a state, so the list is worked rather than admired.

Evidence collection

Evidence is gathered from your connected tools and mapped to the control it satisfies.

Automated control signals

Controls that can be checked from telemetry are checked from telemetry, not asked about in a questionnaire.

Executive reporting

A report that reads for a board: where you are, where the risk sits, and what closing it takes.

How it works

See, decide, act.

Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.

  1. See

    Your controls and your telemetry

    The assessment scope is set, then evidence is collected from documents and from your connected tools.

    • Uploaded policies and procedures
    • Entra ID and Defender configuration
    • Sentinel coverage
    • Asset inventory
  2. Decide

    Scored control by control

    Each control is scored against CSF 2.0, and the scores roll up per function into an overall maturity number.

    • Compliant, partially compliant, or non-compliant
    • Function-level rollup
    • Overall maturity score with a band
  3. Act

    Gaps with owners

    Every non-compliant control becomes a tracked gap with a priority and an owner, and the whole assessment exports as evidence.

    • Prioritised gap register
    • Owner assignment and status
    • Board-ready report export
1 / 3

Governance

How NIST CSF 2.0 is governed

What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.

What it does on its own

Collects evidence from connected tools, scores the controls that can be scored from telemetry, and maintains the gap register.

What always waits for a person

Every control score is confirmable by your assessor, and a score change is attributed to whoever made it.

What it records

Every score with its evidence, every change with its author, and every export with what it contained.

CIS Controls v8 Assessment

Assess and Comply · v2.0

Safeguard-level assessment against CIS Controls v8 with implementation-group scoping.


  • Safeguards in scope
  • Controls covered
  • Open gaps

Book a demo

See NIST CSF 2.0 on your own data.