NIST CSF 2.0 Compliance Checker
The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive, risk-based approach to managing cybersecurity risk. Version 2.0 introduces Govern as a new core function, emphasizing cybersecurity governance and supply chain risk management. This tool assesses your organization across all six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, and Recover — with questions designed for healthcare organizations managing sensitive patient data and critical clinical systems.
Progress: 0/24
Govern (GV)
0/4Identify (ID)
0/4Protect (PR)
0/4Detect (DE)
0/4Respond (RS)
0/4Recover (RC)
0/4Govern (GV)
Assessment of cybersecurity governance, risk management strategy, and organizational context.
Q1
Has your organization established a cybersecurity governance structure with clearly defined roles, responsibilities, and authority levels, including board or executive-level oversight of cybersecurity risk?
Q2
Do you have a documented cybersecurity risk management strategy that defines your organization's risk appetite, risk tolerance thresholds, and criteria for accepting, mitigating, transferring, or avoiding risks?
Q3
Is there a formal cybersecurity policy framework that is reviewed at least annually, approved by senior leadership, and communicated to all workforce members and relevant third parties?
Q4
Do you integrate cybersecurity risk into your organization's enterprise risk management (ERM) process, ensuring cyber risks are weighed alongside financial, operational, and clinical risks?
VertiComply
Build HIPAA-compliant healthcare applications with AI-powered code generation.
Product
Features
Pricing
Tools
Company
About
Blog
Contact
Legal
Privacy
Terms
Compliance
© 2026 VertiComply. All rights reserved.
Built for HIPAA + SOC 2 Type II
About the NIST CSF Compliance Checker
This assessment scores your organisation against the six Functions of NIST Cybersecurity Framework 2.0, released in February 2024: Govern, Identify, Protect, Detect, Respond and Recover. Govern is the addition that matters most — CSF 1.1 had five Functions and treated governance as an Identify category, which let organisations report strong technical control while accountability, policy and supply-chain oversight went unowned. The scoring is weighted toward Govern and Protect because those are where healthcare organisations most often show a gap between documented intent and operating reality. The framework is voluntary and outcome-based rather than prescriptive: it tells you what result to achieve, not which product to buy. That makes it useful as a common language across HIPAA, ISO 27001 and payer security questionnaires, all of which map onto it.
What this NIST CSF assessment covers
The 24-question assessment scores 100 points across 6 weighted categories. Each category reflects a distinct NIST CSF control domain.
Govern (GV) · 18 pts · 4 questions
Assessment of cybersecurity governance, risk management strategy, and organizational context.
Identify (ID) · 17 pts · 4 questions
Evaluation of asset management, risk assessment, and supply chain risk management.
Protect (PR) · 17 pts · 4 questions
Assessment of access control, awareness training, data security, and platform security.
Detect (DE) · 16 pts · 4 questions
Evaluation of continuous monitoring, anomaly detection, and security event analysis.
Respond (RS) · 16 pts · 4 questions
Assessment of incident response planning, analysis, mitigation, and communication.
Recover (RC) · 16 pts · 4 questions
Evaluation of recovery planning, improvements, and communication during restoration.
Common NIST CSF compliance gaps
The patterns we see most frequently in NIST CSF self-assessments and remediation work. Each is the kind of finding an auditor flags first.
Govern is unassigned. The newest Function is the one most often left without an owner — organisational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. If no named person owns GV, the answer to every governance subcategory is aspirational.
Asset inventory is partial, so Identify is overstated. You cannot protect what you have not enumerated. Cloud accounts, SaaS, shadow IT, third-party integrations, and medical devices on the clinical network are the usual omissions — and medical devices are the ones with the longest patch latency.
Detect is thin relative to Protect. Most organisations invest heavily in preventive controls and then have no continuous monitoring, no baseline of normal, and no defined adverse-event analysis process. Dwell time in healthcare breaches is measured in weeks for exactly this reason.
Recover has never been exercised. Backups exist; restoration has not been timed. A recovery plan that has not been tested against a realistic ransomware scenario is an assumption, not a capability — and recovery time is the variable that decides whether an incident becomes a patient-safety event.
Supply chain risk management stops at the contract. GV.SC expects tiering of suppliers by criticality, security requirements written into agreements, and ongoing monitoring. Signing a BAA and filing it is not supply chain risk management.
Tiers are confused with maturity scores. Implementation Tiers 1 to 4 describe how rigorously cybersecurity risk governance is applied, not a grade. Reporting 'we are Tier 3' without a Current and Target Profile behind it tells a board nothing actionable.
What to do with your NIST CSF results
Your score is a starting point — these are the steps that convert the assessment into actionable remediation.
Assign an owner for the Govern Function this week. It is the cheapest gap on the list to close and the one that unblocks the rest, because policy and risk-strategy decisions gate the other five Functions.
Build a Current Profile and a Target Profile. CSF is designed to be used as a gap between where you are and where you intend to be, prioritised by your own risk appetite — not as a score to maximise uniformly.
Complete the asset inventory before trusting any Identify score. Include cloud, SaaS, third parties and networked clinical devices. Most Identify gaps are inventory gaps wearing a different label.
Map your existing HIPAA Security Rule work onto CSF subcategories. The overlap is substantial, and the mapping usually reveals that you have more evidence than your score suggests — plus a small number of genuine blind spots.
Run a recovery exercise with a real time target. Restore a production-representative system from backup, measure how long it takes, and document what failed. That number is the single most useful output of this whole assessment.
NIST CSF compliance FAQ
What changed in NIST CSF 2.0 versus 1.1?
The headline change is a sixth Function, Govern, which elevates organisational context, risk strategy, roles, policy, oversight and supply chain risk management out of Identify and into their own top-level Function. CSF 2.0 also broadened scope beyond critical infrastructure to all organisations, and added implementation examples and quick-start guides.
Is NIST CSF mandatory for healthcare organisations?
No, the framework is voluntary. But it is the backbone of the HHS 405(d) Health Industry Cybersecurity Practices and the HPH Cybersecurity Performance Goals, and it is frequently referenced in payer and health-system security questionnaires. In practice it functions as an expected baseline even though nothing legally compels it.
How does NIST CSF relate to the HIPAA Security Rule?
They overlap heavily but serve different purposes. The Security Rule is a legal minimum with required and addressable implementation specifications; CSF is a risk-management framework with no legal force. Most Security Rule safeguards map cleanly onto CSF subcategories, so work done for one produces evidence for the other. NIST publishes a HIPAA-to-CSF mapping for this reason.
What are NIST CSF Tiers and do we need Tier 4?
Tiers 1 to 4 — Partial, Risk Informed, Repeatable, Adaptive — describe the rigour of your cybersecurity risk governance, not your security level. Tier 4 is not a universal goal. The right Tier is the one proportionate to your risk, resources and regulatory exposure; most small healthcare organisations target Tier 2 or 3 deliberately.
Can NIST CSF be used for a SOC 2 or ISO 27001 programme?
It is a useful organising layer, but not a substitute. SOC 2 requires an auditor's opinion against the Trust Services Criteria and ISO 27001 requires certification against a defined management system with a Statement of Applicability. CSF has no certification. Many organisations use CSF to structure the programme and then map it onto whichever attestation their customers demand.
Build it instead of buying it
Generate a NIST CSF-compliant healthcare app with the controls built in
VertiComply generates production-ready healthcare applications with NIST CSF controls scaffolded from the first commit — no add-on tier, no platform lock-in, code exported to your GitHub.
Start free