NEW · The Founders' Circle Grant — full-platform access for select companies. Redeem a grant →
Compliance · NIST CSF

NIST CSF 2.0 maturity scoring, function-by-function.

Full 108-control NIST CSF 2.0 coverage with heat-map scoring at the function level. QFX templates support the Govern, Identify, Protect, Detect, Respond, and Recover functions with maturity-graded responses.

What NIST CSF requires

How Verisq covers NIST CSF.

NIST Cybersecurity Framework 2.0 — 108 controls, six functions

CSF 2.0 with Govern function

Includes the new Govern (GV) function added in CSF 2.0 — risk management strategy, oversight, and policy mapping.

Maturity scoring

Five-level CMMI-style scale per control with partial-credit scoring rolled to a 0–100% function score. Beats binary pass/fail.

M&A diligence default

NIST CSF is the default scoring framework for M&A Cyber Diligence engagements — the heat map drives the executive Cyber Diligence Pack.

Cross-mapped to SOC 2 + ISO 27001

Each CSF control is mapped — evidence collected for CSF satisfies the corresponding SOC 2 TSC and ISO Annex A controls.

What you take to the audit

Outputs auditors and regulators expect.

CSF heat map

Function-level (GV / ID / PR / DE / RS / RC) maturity heat map ready for board reporting.

Gap analysis

Controls with no evidence flagged with recommended remediation path — assign training, publish policy, run assessment.

Trend reporting

Coverage percentages tracked quarter-over-quarter — proves the program is maturing, not regressing.

Industries

NIST CSF relevance.

Technology Financial Services Healthcare Federal

Stop building NIST CSF evidence in spreadsheets.

Verisq generates the artifacts your auditors and regulators expect — on demand, with current data, with framework mappings embedded.

See pricing Sign in to platform