NIST CSF Self-Assessment
Answer 6 quick questions to get an instant estimate of where your business sits against the NIST Cybersecurity Framework - no email required.
0 of 6 answered
1.[Govern]How is cybersecurity risk managed at a governance level in your business?
2.[Identify]How well do you know what needs protecting - your devices, data, and critical systems?
3.[Protect]How would you describe your protective controls - access control, security training, data protection?
4.[Detect]How would you know if something suspicious was happening on your network right now?
5.[Respond]If you had a confirmed security incident today, what would happen?
6.[Recover]How confident are you in your ability to recover systems and data after a serious incident?
Answer all 6 questions to see your estimated tier.
What the Tiers Mean
The NIST CSF describes an organisation's overall risk management approach using four Implementation Tiers, from Tier 1 (Partial), where risk management is ad hoc and reactive, to Tier 4 (Adaptive), where practices are formalised and continuously improved based on lessons learned.
Unlike the Essential Eight, the NIST CSF doesn't treat your weakest area as the sole determinant of your overall tier - it's a broader picture across governance, technical controls, and response capability. That said, a single major gap, like no tested incident response plan, is still worth fixing regardless of how the average looks.
For most Perth SMBs, Tier 2 to Tier 3 is a realistic and proportionate target, formal, documented practices without the overhead a large enterprise might carry.
FAQs
Is this self-assessment an official NIST result?
No. NIST does not certify organisations, and this tool isn't an official NIST Tier determination. It's a quick way to estimate roughly where your business sits based on your own answers. A full assessment reviews evidence, policies, and configurations to confirm your actual alignment.
How long does it take?
About 2 minutes. There are 6 questions, one for each NIST CSF function - Govern, Identify, Protect, Detect, Respond, and Recover - with plain-English answer options.
What tier should my business be aiming for?
Most small and medium Perth businesses realistically sit at Tier 2 (Risk Informed) and aim for Tier 3 (Repeatable), where policies and processes are documented and consistently applied. Tier 4 (Adaptive) is generally more relevant for larger or higher-risk organisations.
Is my information saved or sent anywhere?
No. This self-assessment runs entirely in your browser - your answers and results aren't recorded, stored, or sent to us unless you choose to contact us afterwards.
What happens after I get my result?
You'll see an estimated tier and which functions are holding it back. If you'd like a verified result and a prioritised, costed roadmap, you can book a full NIST CSF assessment with our team.
Want a verified result and a roadmap?
Our NIST CSF assessment confirms your tier with evidence and gives you a prioritised, costed plan to improve it.