
In 7 days you know where to start.
Gap analysis vs. NIST CSF executed in 7 business days. You walk out with an executive report, a score benchmarked against your industry, and a 90-day plan.
Concrete deliverables.
- 01Executive report (PDF, 18-24 pages) with score by NIST CSF function
- 02Technical detail (PDF, 40-60 pages) with assessed sub-functions
- 03Executive presentation (slide deck, 14 slides)
- 0490-day remediation plan (PDF, 8-12 pages)
- 0530-min workshop with your technical leadership
Timeline.
- Day 1Kickoff (2h)
Scope alignment, focal points appointed, scheduling.
- Days 2-4Interviews + evidence
6-10 interviews with IT, Security, Compliance and Operations.
- Day 5Analysis + scoring
Assessment against NIST CSF, scoring per sub-function.
- Day 7Report + walkthrough (30 min)
Full delivery + executive walkthrough.
Maturity Thermometer.
3 minutes. 12 questions. Partial score based on NIST CSF v2.0 so you arrive at the Assessment with context.
Where your operation stands today.
The 12 questions cover the 6 framework functions: Govern, Identify, Protect, Detect, Respond and Recover. Each answer uses the CMMI scale (Ad-hoc → Optimized) to differentiate companies at distinct maturity stages.
Your answers stay in your browser (sessionStorage) and disappear when you close the tab. Nothing is sent until you submit the form.
…
…
Score per NIST CSF function
…
The full 7-day Assessment quantifies these fronts against your sector benchmark and delivers an executive remediation plan. We carry your partial result into the conversation.
Partial result · does not replace formal assessment · contains approximations.
Request now.
Frequently asked.
Quote sent by email after a qualification call. Range depends on environment size.
For gap analysis vs. framework and risk prioritization, yes. Not a deep audit: entry point, not destination.
Yes. The executive report is designed to support presentation to auditor, regulator and board.