Answer
106 guided multiple-choice questions across the six functions of the framework. No technical data to enter, no account to create.
Cybersecurity › Free assessment
A free self-assessment based on the NIST Cybersecurity Framework 2.0: 106 questions across the six functions of security, no registration, a PDF report with your maturity level and priority gaps. The tool is public and the report is yours. If you then want to read the result with people who do security every day, the way to do it is at the bottom of the page.
Most companies have no picture of their own security: they have an antivirus, a firewall, a backup, and the feeling that it is enough. A structured assessment asks everyone the same questions, in the same order, and returns a measurable level for each function. It is the starting point of any serious journey, from NIS2 to ISO/IEC 27001, and the cheapest way not to spend in the wrong place.
Guided multiple-choice questions on processes, roles and controls. No technical data to enter: it is answered by whoever knows the company, not whoever knows the servers.
The time it usually takes to complete. You can pause and resume. At the end the PDF report downloads immediately, without waiting for a sales email.
The NIST CSF 2.0 functions on which maturity is measured: Govern, Identify, Protect, Detect, Respond, Recover. A score for each, and an overall one.
How it works
The assessment is a public tool: use it whenever you want, as many times as you want, and the report is yours. You only take the third step if you need it.
106 guided multiple-choice questions across the six functions of the framework. No technical data to enter, no account to create.
The overall maturity level and the level per function, strong areas and priority gaps. A document you can share with management as it is.
Use the report to set priorities. If you wish, we read it together in a no-obligation conversation and turn the gaps into a plan.
Read the report with us
Write to us and attach or describe the result. In a no-obligation conversation we read the six functions together, separate the gaps that matter from those that can wait and tell you frankly what we would do and what your team can do on its own. We reply within 24 working hours.
The questions we hear before and after the report is downloaded.
Yes. The assessment is public at nist.atws.app, it does not ask you to create an account, it does not require a contract with AtWorkStudio and it has no cost. You answer the questions and download the report. The form at the bottom of this page is separate and optional: it is only there if you want to read the report with us.
It is the reference framework of the US National Institute of Standards and Technology for organising an organisation’s security. Version 2.0, published in 2024, applies to organisations of every size and sector and adds a sixth function, Govern, to the five historical ones (Identify, Protect, Detect, Respond, Recover): strategy, roles, supply chain risk and oversight. It is the common language spoken by ISO/IEC 27001, NIS2 and most audits, which is why we use it as the basis.
As reliable as the honesty of whoever fills it in. A self-assessment does not replace an audit or a technical vulnerability assessment: it measures the maturity of processes and controls as known by the person answering, it does not test systems. Its value lies elsewhere: in a quarter of an hour it gives a picture you can share with management, puts priorities in order and shows where it is worth digging deeper with technical tools. If the answers were given with due caution, the report is a good starting point.
The application is GDPR compliant. Your answers are used to generate the report and can be deleted on request. You do not need to enter data about systems, IP addresses or sensitive technical information: the questions concern processes, roles and controls in place. AtWorkStudio is certified to ISO/IEC 27001, 27017, 27018 and ISO 9001.
It helps, but it is not enough on its own. NIS2 requires risk management measures, incident handling procedures, business continuity, supply chain security and accountability of management bodies: the six functions of the NIST CSF 2.0 cover exactly these areas, and the report shows where you are exposed. For organisations in scope it is a quick way to understand where to start; the actual compliance path is described on our NIS2 page.
The assessment is the first step of everything we do in cybersecurity: from NIS2 compliance to the path towards ISO 27001 certification.