Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

How to Run a NIST CSF 2.0 Self-Assessment for Your Business

CybersecurityManaged IT
Last updated: September 4, 2026

A NIST CSF 2.0 self-assessment scores your business against six Functions, Govern, Identify, Protect, Detect, Respond, and Recover, then documents the gap between what you actually do today and what you should be doing.

Nobody grades it. There is no auditor, no certificate, no minimum score to hit. NIST publishes the whole framework as voluntary guidance and gives the worksheets away, which is the part most owners never find out about until somebody points at the download link.

You have probably run into CSF sideways. An insurance renewal questionnaire asks whether you follow a recognized security framework. A bigger client sends over a vendor security review. A contract mentions it in a clause nobody in the room actually wrote. So you open the real document, find six Functions fanning out into 22 categories of outcomes, and quietly close the tab.

Fair reaction. The framework was not written with a 14-person insurance agency in Nanuet in mind. But the assessment underneath it scales down much further than people expect, and NIST published a small business version aimed specifically at companies with modest cybersecurity plans or none at all. What follows is the DIY route, start to finish, run entirely on files NIST gives away. Where it stops being a DIY job we will say so, because that line is real and pretending otherwise helps nobody.

What a CSF Self-Assessment Actually Is

A NIST CSF 2.0 self-assessment is a structured review where you rate how well your business achieves each cybersecurity outcome in the framework, record that as a Current Profile, describe where you want to be as a Target Profile, and write down every difference between the two. NIST calls that last list a gap analysis.

It is not a certification. Nothing gets filed with anyone. Version 2.0 landed on February 26, 2024 as NIST CSWP 29, replacing the 2018 edition, and the headline change was a brand-new sixth Function called Govern that sits in the middle of the other five and informs all of them.

Govern is the one small businesses skip. It is also the one that insurance questionnaires and vendor reviews keep asking about, because it covers the boring written things. Who is accountable. What the policy says. Whether anyone reviews it. If your answer to all three is a shrug, that is a finding, and it is a cheap one to fix compared with anything on the technical side.

FunctionWhat NIST says it coversThe question you are really answering
Govern (GV)Cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitoredWho decides, who is accountable, and is any of it written down?
Identify (ID)The organization’s current cybersecurity risks are understoodDo we know what we own, and what losing it would cost?
Protect (PR)Safeguards to manage the organization’s cybersecurity risks are usedWhat is actually standing in an attacker’s way right now?
Detect (DE)Possible cybersecurity attacks and compromises are found and analyzedWould we notice? How fast?
Respond (RS)Actions regarding a detected cybersecurity incident are takenDoes anyone know what to do in the first hour?
Recover (RC)Assets and operations affected by a cybersecurity incident are restoredCan we get back to work, and have we ever tested that?

What You Need Before You Start

Three files and a couple of hours. That is genuinely the whole shopping list, and every one of the files is free.

  • The NIST Small Business Quick-Start Guide, published as NIST SP 1300. Nine pages. It sorts the framework into Understand, Assess, Prioritize, and Communicate actions for each Function, which is far more usable than the parent document.
  • NIST’s CSF 2.0 Organizational Profile template, a spreadsheet built to hold your Current and Target Profiles side by side so the gaps show up in the same row.
  • The full framework PDF, for when you need the exact wording of an outcome. You will not read all 32 pages. Keep it open anyway.

Then the people. Bring whoever signs the contracts and whoever knows the passwords. At a lot of companies with 5 to 60 employees that turns out to be the same person, and noticing that is itself one of the more useful findings you will get out of the whole exercise.

Leave your IT vendor out of the first pass. Not because they would lie to you. Because you want the version of reality that lives in the business, not the version that lives in a ticketing system, and those two drift apart in ways nobody notices until they are compared side by side.

Step 1. Scope It Before You Score Anything

NIST’s first instruction is to document the high-level facts and assumptions the Profile rests on. In plain terms, decide what you are assessing.

You can have as many Profiles as you want, each scoped differently. A whole company. One department. One system. NIST’s own example scopes a Profile to an organization’s financial systems, or narrower still, to countering ransomware threats against those financial systems specifically.

For a first pass, scope it to the whole business and write two sentences at the top of the spreadsheet saying so. Something like this. “This Profile covers all company systems, staff, and data as of August 2026, including remote workers and the Microsoft 365 tenant. It excludes the warehouse camera system, which runs on its own network.” Boring, but it stops the argument three weeks later about whether the cameras counted.

Step 2. Gather What You Already Have

More exists than you think. NIST lists organizational policies, risk priorities, business impact analysis registers, the security requirements you are already subject to, the tools and procedures in place, and who holds which work role.

Translated for a company your size, go find the employee handbook section about acceptable use, the cyber insurance application you filled in last renewal, your Microsoft 365 admin settings, the managed services agreement with whoever supports your network, and any client contract with a security clause in it. That insurance application is the sleeper. You already answered a long list of security questions under penalty of being denied a claim, and those answers amount to a rough Current Profile that somebody else made you write.

Pull it up. Read what you claimed. Then check whether it is still true, because the gap between the two is usually the most honest thing you will produce all day.

Step 3. Write the Current Profile

Now the actual work. Go Function by Function through the Quick-Start Guide’s Actions to Consider and, for each one, record what your business does today and how well it does it.

The temptation is to score yourself with numbers. Resist it for now. NIST asks you to characterize how, or to what extent, each outcome is being achieved, and a sentence beats a number here because a sentence carries the caveat. “Yes, we require MFA” and “Yes, we require MFA except on the two shared mailboxes and the accounting login, which the bookkeeper says breaks her workflow” land on the same score and describe completely different risks.

Some of NIST’s small business prompts are unusually concrete, and they make good starting rows. Understand what information employees should have access to, and restrict sensitive data to only the people who need it for their jobs. Prioritize MFA on every account that offers it. Change default manufacturer passwords. Patch and update on a schedule, with automatic updates on where you can. Back up regularly and test the backups. Turn on full-disk encryption for laptops and tablets.

On password managers, which NIST recommends alongside MFA, BitWarden is our recommended system. Pick one and standardize. Running two password managers is worse than running none, because now nobody knows where anything lives.

Be honest in this column even where honesty is unflattering. A Current Profile that flatters you produces an action plan that fixes nothing, and you are the only person who will ever read it.

Step 4. Set a Target and Find the Gaps

The Target Profile is where you want to be, not where a Fortune 500 wants to be. NIST is explicit that the framework is not one size fits all, and it tells you to consider anticipated changes when you set the target, things like new requirements, new technology you are about to adopt, and where the threat picture is heading.

Practical version. Look at what is already coming at you. A client contract renewing in six months with a security addendum. An insurance renewal. A planned move into Azure. Those set your target far better than an abstract ideal does. NIST also publishes Community Profiles, baselines built for a particular sector or threat type, and you are allowed to lift one wholesale as your starting target instead of inventing one.

Then the gap analysis, which is just reading your own spreadsheet across the row. Current says one thing. Target says another. The difference is a gap. Write each one down. Do not fix anything yet, and do not let the conversation drift into vendor selection, because a room that starts shopping stops assessing.

Step 5. Turn Gaps Into an Action Plan With Dates

NIST wants a prioritized action plan out of this, and it names the formats it has in mind, a risk register, a risk detail report, or a plan of action and milestones. Any of them work. A spreadsheet with four columns works.

What matters is that every gap gets an owner, a date, and a rough cost. All three. Gaps without owners are wishes. The prioritization rule that holds up best for a small business is to sort by what an attacker would reach first and what would hurt worst, then do the free things immediately, since a surprising share of what turns up in a first pass costs nothing but an afternoon of somebody’s attention.

Then repeat the whole thing. NIST’s framing is continuous improvement, and it says outright that an organization can repeat these steps as often as needed. Annually is a reasonable cadence for most small businesses. Sooner if you acquire something, open a location, or change the way people work.

Where Small Businesses Usually Land on the Tiers

CSF 2.0 includes four Implementation Tiers you can use to characterize how rigorous your risk management practices are. NIST names them Partial, Risk Informed, Repeatable, and Adaptive, running Tier 1 through Tier 4. They are not a maturity grade, and NIST never tells you which one you ought to be.

Most first-time assessments land in Tier 1. NIST describes Tier 1 as applying the risk strategy in an ad hoc manner, prioritizing on an ad hoc basis rather than by objectives or threat environment, implementing risk management on an irregular case-by-case basis, and being generally unaware of the cybersecurity risks that come with suppliers and the products and services the business uses. Read that back slowly. It describes a lot of otherwise well-run companies. Profitable ones, too.

Tier 2, Risk Informed, is the realistic target for a first year. Management has approved the risk practices even if they are not company-wide policy yet, prioritization is actually informed by business requirements, and cybersecurity information gets shared internally, informally. That is a reachable jump. Tier 3 needs written policy and repeatability, which is a different order of effort.

One caution. Tiers describe your practices, not your tools. Buying software does not move you up a Tier. Writing down who is responsible for that software, and reviewing it on a schedule, does.

Where the DIY Version Runs Out

The self-assessment itself is genuinely DIY. Three of the gaps it tends to expose usually are not.

Detect is the first. NIST’s small business guidance says to prioritize engaging a service provider to monitor computers and networks for suspicious activity if you do not have the resources to do it internally, which is NIST quietly acknowledging that continuous monitoring is not something a 20-person company pulls off with existing staff. Somebody has to be watching the alerts. That is the gap VJNetworks built its managed detection and response service to close.

Recover is the second, and the failure is almost always the same. Backups exist. Nobody has restored from them. NIST asks you to assess the integrity of backed-up data before using it for restoration, which is a polite way of saying an untested backup is a hypothesis. Testing restores is the entire job of backup and disaster recovery, and it is tedious enough that it does not survive being somebody’s side task.

Govern is the third and the least obvious. Writing policy is not hard. Owning it is. That is the role a virtual CISO fills for companies too small to employ a security executive but large enough to be asked for one by a client or an insurer.

None of that changes the value of doing the assessment yourself first. Walk into any provider conversation, ours included, holding a gap list you wrote yourself, and you are negotiating from a completely different position than someone who arrived cold. If you would rather have the whole thing run for you and handed over as a report, that is what a security risk and vulnerability assessment is, and it goes deeper than a self-scored spreadsheet can. VJNetworks has been doing this for businesses across Rockland, Westchester, and Bergen for over 20 years. The pattern rarely changes. The gaps that hurt are almost never the exotic ones. They are the unowned ones.

Worth separating two different exercises here, since people run them together. Scoring your own security posture against CSF is one thing. Grading the company you pay to handle it is another, and we wrote a separate self-test for whether your IT provider is proactive or reactive. Run both. They answer different questions, and a good result on one tells you nothing about the other.

Common Questions

Can a small business really run this without hiring anyone?
Yes, for the first pass. NIST wrote SP 1300 specifically for small and medium businesses with modest cybersecurity plans or none at all, and the templates are free. Where outside help earns its keep is fixing what the assessment turns up, not producing the assessment.
Realistically, how much time does a first pass eat?
Two to four hours for a company under 60 employees, if the right people are in the room and nobody starts shopping for software mid-meeting. Gathering documents beforehand is what actually determines the length. Walk in with the insurance application and last year’s contracts and it goes fast.
Does anyone actually require CSF, or is it optional?
Optional by law, increasingly not optional in practice. CSF 2.0 is voluntary guidance and no statute makes a private small business adopt it. What changed is the paperwork around you, since insurers, enterprise clients, and prime contractors now ask which framework you follow, and CSF is the most common acceptable answer.
We filled out a cyber insurance questionnaire already. Is that the same thing?
Close cousin, not the same. An insurance questionnaire asks about a fixed list of controls the carrier cares about, mostly under Protect. A CSF self-assessment covers all six Functions, including Govern and Recover, which insurance forms barely touch. The questionnaire is a great head start on your Current Profile though. See how those answers connect to the controls carriers keep asking about.
This versus the assessment an IT company sells, where is the line?
Depth and verification, mainly. A self-assessment records what you believe to be true. A paid assessment tests it, scanning for vulnerabilities, checking configurations against what policy claims, and reviewing evidence rather than recollection. Both are useful. Doing the free one first makes the paid one cheaper and sharper.
Which Function should we fix first if we can only fix one?
Govern, nine times out of ten. It is the cheapest to improve and it changes every other Function’s outcome, because assigning ownership and writing down a review schedule is what stops the technical fixes from decaying six months after somebody installs them. Tools without owners drift. Every time.
Ran the assessment and did not like the gap list?

Bring us what you found. We will walk your Current Profile with you and tell you which gaps actually matter for a business your size, at no cost and with no obligation.

Review My Gap List →

Or call (845) 440-5000