NIST Cybersecurity Framework

NIST CSF assessment that measures your security program’s maturity

We score your program across the six functions of NIST CSF 2.0, compare where you are with where you need to be and give you a prioritized roadmap. It is the same NIST-based approach we use with California cities through CJPIA.

  • All six CSF 2.0 functions, including Govern
  • Current and target profiles with a gap roadmap
  • Maturity assessments for 30+ California cities
City skyline with a network overlay

30+ California cities assessed

Cybersecurity assessment provider for California JPIA

Repeat assessments

Progress measured against the same baseline over time

Top virtual CISO services company

Recognized by Cyber Security Review

Maps to other frameworks

Findings aligned to SOC 2, ISO 27001, HIPAA and CMMC

Team reviewing findings around a conference table

NIST CSF 2.0

A common language for cybersecurity maturity

The NIST Cybersecurity Framework is a voluntary framework for managing cybersecurity risk, used by organizations of every size and sector. Version 2.0, published in 2024, extended its scope beyond critical infrastructure and added a sixth function, Govern, which covers strategy, roles, policy, risk management and supply chain oversight.

A NIST CSF 2.0 assessment tells leadership how mature the program is in terms they can follow. It also gives you a baseline that maps to most other frameworks, which makes it a practical first step when no specific regulation applies yet.

What we assess

Cybersecurity maturity assessment across all six functions

Tiers and profiles

Current profile, target profile and the gap between them

CSF 2.0 uses organizational profiles to describe outcomes. Your current profile shows what you achieve today. Your target profile shows what you need, based on your risk, obligations and resources. The gap between them becomes your roadmap.

The framework’s tiers, from Partial to Risk Informed, Repeatable and Adaptive, describe how rigorous your risk governance and management practices are. We score each area consistently so you can track security program maturity from one assessment to the next.

CSF 2.0 tiers

How rigor is described

Tiers help you set expectations for the program as a whole.

  • Tier 1: Partial
  • Tier 2: Risk Informed
  • Tier 3: Repeatable
  • Tier 4: Adaptive

How it works

How a NIST CSF gap assessment works

1

Scope

We agree on the organization, systems and stakeholders in scope and set the target profile with leadership.

2

Interview and review

Remote and onsite working sessions with IT and business owners, plus review of policies and configurations.

3

Score

Each CSF category is scored for maturity, and optional vulnerability scans add technical evidence.

4

Roadmap

You receive the current and target profiles, the gaps and a prioritized roadmap, and we present it to leadership.

Government building at sunset

Public agencies

Maturity assessments for California cities through CJPIA

The California Joint Powers Insurance Authority chose Triden as its cybersecurity assessment provider. Through a master services agreement, member cities and agencies can engage us for cybersecurity maturity assessments and internal and external vulnerability scans. We have assessed more than 30 California cities and municipalities.

Members can also use the agreement for penetration testing, repeat assessments, incident response tabletop exercises and implementation of improvements. Repeat assessments measure each agency against its earlier baseline, so councils and managers can see progress.

  • Cybersecurity maturity assessments
  • Internal and external vulnerability scans
  • Penetration testing and repeat assessments
  • Incident response tabletop exercises

Deliverables

What you receive

  • Maturity score for every CSF 2.0 category
  • Current and target organizational profiles
  • Gap analysis with risk themes
  • Prioritized roadmap with quick wins
  • Executive summary and leadership presentation
  • Baseline for repeat assessments

FAQ

NIST CSF assessment questions

It’s a review of your cybersecurity program against the NIST Cybersecurity Framework. We score maturity across the Govern, Identify, Protect, Detect, Respond and Recover functions and show where to improve first.

CSF 2.0 added the Govern function, broadened the framework’s intended audience to organizations of all sizes and sectors, and gave more attention to supply chain risk. It also added implementation examples and quick start guides.

For most private organizations, no. The framework is voluntary. Many regulators, insurers, customers and public agencies expect programs to align with it, and it maps to frameworks that are mandatory.

Many organizations repeat it every year or two, or after major changes. Repeat assessments against the same baseline show leadership what has improved.

Cost depends on your size, the number of locations and systems, whether vulnerability scans are included and whether you need a one-time assessment or a repeat program. We scope it on a short call and give you a fixed price.

A NIST-based maturity assessment is where every vCISO engagement starts. You can also order it on its own and use the roadmap with your own team.

Request the assessment

Find out how mature your security program is

Tell us about your organization and an advisor will reply by email to scope your NIST CSF 2.0 assessment.

  • Scoping call with a Triden advisor
  • A fixed price and timeline before work begins

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message