# NIST CSF 2.0 Maturity Assessment

> From $15K · Compliance & GRC · https://cisomarketplace.services/services/nist-csf-2-assessment

A named, fixed-scope assessment against all six NIST Cybersecurity Framework 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover. Evidence-based interviews and document review produce a current-state maturity score per category, a target profile matched to your risk appetite, and a funded roadmap. The scorecard is built to be shown to a board, an acquirer or a cyber insurer.

## In scope

- Current-profile assessment across all six CSF 2.0 functions
- Evidence review and stakeholder interviews
- Target profile and risk-based prioritization
- Roadmap with effort and cost bands
- Board and insurer-ready scorecard

## Deliverables

- NIST CSF 2.0 maturity scorecard
- Gap analysis by category and subcategory
- 12-24 month prioritized roadmap
- Board presentation

## Tiers

### Essential CSF Assessment: $15K

Single business unit, up to 250 employees: maturity scorecard, gap analysis and roadmap

Limits: employees 250, locations 3

### Advanced CSF Assessment: $28K

Up to 1,500 employees or regulated environments: adds control evidence sampling, target profile workshop and board presentation

Limits: employees 1500, locations 10

### Enterprise CSF Program: $55K

Multi-entity or 1,500+ employees: adds per-entity profiles, cross-mapping to ISO 27001 / SOC 2 / CIS and a quarterly re-scoring plan

Limits: employees 10000, locations 50

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=nist-csf-2-assessment
