Most NIST CSF assessments end as a spreadsheet of scores that nobody reopens. The gaps are known, the actions have no owners, and next year’s assessment starts again from a blank sheet.
The NIST Cybersecurity Framework 2.0 describes 106 cybersecurity outcomes and leaves each organisation to decide which ones matter and how well it meets them. This free NIST CSF checklist runs that assessment for security leads, IT managers and risk teams. It follows NIST’s five-step process for Organizational Profiles: scope the Profile, score a Current Profile Function by Function, set a Target Profile with executive sign-off, analyse the gaps and track a prioritised action plan to closure. Answers on the first task switch on the reassessment, Tiers and Community Profile steps only where they apply. The result is a dated Current and Target Profile, an action plan with owners and deadlines, and the evidence behind every score.
CSF 2.0, published by NIST on 26 February 2024, is a taxonomy of outcomes, not a control set. A Subcategory such as PR.DS-11 says that backups are created, protected, maintained and tested. It does not say how often, with which tool or to what standard. That is why a CSF assessment cannot be passed or failed. What it produces is an Organizational Profile: where you are, where leadership wants to be and what stands between the two.
NIST does not certify anyone against the CSF and has no plans for a conformity assessment programme. A questionnaire asking whether you are “NIST CSF compliant” is really asking for your Profile, your Tier and the actions still open. This checklist produces that record.
Current Profile
What the organisation achieves today
Records: the practices in place for each outcome, a status and a rating.
Evidence: policies, inventories, test results and logs that show the practice exists.
Scored by: the people who run the controls, challenged by the Profile owner.
Target Profile
What leadership has decided it needs
Records: the selected outcomes, a priority for each and the goals that define success.
Inputs: legal and contractual requirements, risk tolerance, threat trends and planned technology.
Set by: executives, optionally from a sector Community Profile.
Tiers are optional
Rigour of risk practices, not a maturity score per control
The four Tiers, Partial, Risk Informed, Repeatable and Adaptive, describe how rigorous the organisation’s cybersecurity risk governance and management practices are. They are optional. NIST’s Tiers quick-start guide advises selecting them for the organisation as a whole, a Function or a Category rather than for individual Subcategories, and says the selection is generally made by leadership.
What the NIST CSF 2.0 Checklist Covers
Seven phases follow NIST’s five steps for creating and using an Organizational Profile, with the Current Profile split by Function so each owner scores their own outcomes. Identifiers are from the CSF 2.0 Core.
Phase 1
Phase 1: Scope the Profile & Gather Inputs
The answers on the first task drive the conditional tasks in Phases 1, 5 and 6.
Record why the Profile is being built and what it covers — the whole organisation, or a named division, set of systems, data type or threat such as ransomware
Name the Profile owner, the contributors and the executive who sets targets — the person who approves the Target should not be the person scoring the Current Profile
Gather the inputs — policies, the risk register, risk appetite statements, business impact analysis, key contracts and the standards the organisation already follows
Set up the NIST Organizational Profile template — agree the status, rating and priority scales before anyone scores an outcome
Select the outcomes in scope — start from all 106 Subcategories and record a rationale for each one excluded or added
Load the previous Profile and its open actions — shown only for a reassessment, so this cycle is scored against the last one
Phase 2
Phase 2: Current Profile – Govern
Govern shapes how the other five Functions are run, so it is scored first. Each scoring task records practices, status and a rating per Subcategory, with evidence attached.
Score Organizational Context (GV.OC) — mission, stakeholders, dependencies and the legal, regulatory and contractual requirements in GV.OC-03
Score Risk Management Strategy (GV.RM) — written risk appetite and tolerance statements, and one standard method for rating risks
Score Roles, Responsibilities and Authorities (GV.RR) — leadership accountability, defined roles, adequate resources and cybersecurity in HR practices
Score Policy (GV.PO) — policy exists and has been reviewed for changes in requirements, threats, technology and mission
Score Oversight (GV.OV) — evidence that leadership reviews strategy outcomes and risk management performance and adjusts them
Score Cybersecurity Supply Chain Risk Management (GV.SC) — suppliers known and ranked by criticality, contract requirements, due diligence and exit provisions
Phase 3
Phase 3: Current Profile – Identify & Protect
Score Asset Management (ID.AM) — hardware, software, services and data inventories and data-flow diagrams, tested against a sample of real assets
Score Risk Assessment (ID.RA) — vulnerabilities and threats recorded, risk responses tracked and critical suppliers assessed before acquisition
Score Improvement (ID.IM) — lessons drawn from evaluations, tests, exercises and incidents, with response plans kept current
Score Identity Management, Authentication and Access Control (PR.AA) — including least privilege and separation of duties under PR.AA-05
Score Awareness and Training (PR.AT) — general staff and people in specialised roles, rated separately
Score Data Security and Platform Security (PR.DS, PR.PS) — backups created and tested, configuration management, software maintenance and logging
The Six CSF 2.0 Functions and Where Each Is Assessed
The CSF 2.0 Core has three levels: 6 Functions, 22 Categories and 106 Subcategories. Subcategory numbers have gaps where CSF 1.1 outcomes moved. Govern is the largest Function, which is why it gets a phase of its own. The CSF creates no legal obligation by itself, although the requirements you record under GV.OC-03 may, so treat the table as a map of the framework, not legal advice.
Incident Recovery Plan Execution; Incident Recovery Communication
8
Phase 4
Total
22 Categories
106
Phases 5–7 set targets and close gaps
At the time of review, CSF 2.0 remains the current version and NIST has announced no revision of the Core; its FAQ says there are no immediate plans to update the Core to address AI. The Cyber AI Profile (NIST IR 8596) is still a preliminary draft, released in December 2025, and a draft quick-start guide on using AI for CSF analysis (SP 1353) is open for comment until 15 October 2026. Informative References change more often than the Core: NIST finalised mappings from ISO/IEC 27001:2022 in May 2025 and SP 800-53 Rev. 5.2.0 in November 2025, and the PCI Security Standards Council mapped PCI DSS v4.0.1 to CSF 2.0 in July 2026. Check the CSF 2.0 Reference Tool before you write goals.
Why Run Your NIST CSF Assessment in CheckFlow?
1
Each Function scored by its owner
Assign Govern to the risk lead, Protect to IT operations and Respond to the incident manager. Each scoring task holds a table of its Subcategories, and the policy, inventory or test report behind each score is attached to that task.
2
Targets wait for the evidence
Enforced step order stops the Target Profile being set before the Current Profile review is complete, and the Target is signed off as an approval by a named executive. Conditional logic adds the Tiers, Community Profile and reassessment steps only when the first task says they apply.
3
The action plan keeps moving
A recurring schedule starts the action review every month or quarter, with dynamic due dates, and the next full reassessment on the date leadership chose. The activity trail shows who changed each score and when.
CheckFlow is not a GRC platform, a vulnerability scanner or an assessor, and nobody can certify you against the CSF. It keeps the scores, evidence, approvals and actions in one record. CheckFlow’s compliance checklist software shows how the same schedules, evidence and sign-offs work across your whole compliance calendar.
A CSF Profile does not replace a scheme with its own requirements and assessors. If a defence contract requires CMMC, use the CMMC Compliance Checklist. If you want a certifiable information security management system, the ISO 27001 Compliance Checklist covers it, and NIST’s ISO/IEC 27001:2022 mapping lets one body of evidence support both. The Respond outcomes you score here are run live with the Incident Management Checklist.
Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in version 2.0 and covers context, risk strategy, roles, policy, oversight and supply chain risk. Together the six Functions contain 22 Categories and 106 Subcategories, and NIST says they should be addressed concurrently rather than in sequence.
What changed between NIST CSF 1.1 and 2.0?
+
Version 1.1, from April 2018, had five Functions, 23 Categories and 108 Subcategories. Version 2.0 adds Govern and moves the governance, risk strategy and supply chain Categories out of Identify into it. It also adds an Improvement Category under Identify and two Protect Categories, Platform Security and Technology Infrastructure Resilience. NIST states that no 1.1 content was removed, only relocated. To convert a 1.1 Profile, use NIST’s published crosswalk.
Is NIST CSF mandatory?
+
For most organisations, no. NIST is not a regulator and most organisations use the CSF voluntarily. NIST’s FAQ notes that Executive Order 13800 made it mandatory for US federal agencies, and that some companies require it of their customers or suppliers. In practice it often arrives through a contract or a customer questionnaire, which is why GV.OC-03 asks you to record those obligations.
Can an organisation be certified against NIST CSF?
+
No. NIST does not offer certifications or endorsements for CSF implementations, and says it has no plans to develop a conformity assessment programme. A consultant can assess you against the CSF, but the result is their opinion, not a NIST certificate. The best evidence for a customer is a dated Current Profile, the approved Target and progress on the action plan.
What are the NIST CSF Implementation Tiers?
+
Four levels describing the rigour of an organisation’s cybersecurity risk practices: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3) and Adaptive (Tier 4). Each Tier has a governance description, which relates to Govern, and a risk management description for the other five Functions. They are optional, and they are not a scoring scale for individual outcomes.
How often should a NIST CSF assessment be repeated?
+
The CSF sets no frequency. It says the Profile steps can be repeated as often as needed. A practical rhythm is a full reassessment once a year, a monthly or quarterly review of the action plan, and an out-of-cycle review after a significant incident, acquisition or new legal requirement. Record the cadence you chose, and why, in the Profile.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
A Profile You Can Defend and an Action Plan That Keeps Moving
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more