NIST CSF 2.0 Self-Assessment Workbook
14-tab NIST CSF 2.0 workbook — all 106 Subcategories with verbatim NIST.CSWP.29 outcome statements, Current/Target tier dropdowns, Organizational Profile Generator, heatmap, gap analysis pre-seeded with 12 high-gap 2026 scenarios, and crosswalks to SP 800-53r5, SP 800-171r3, CIS Controls v8.1, and ISO 27001:2022.
What this actually gives you
- Built around the 26 February 2024 final publication of NIST CSF 2.0 (NIST.CSWP.29).
- All 106 Subcategories with verbatim outcome statements, not paraphrases — plus a nested-IF gap calculation that works across all Excel versions.
- Includes the Organizational Profile Generator — the new-in-2.0 concept most vendors fail to implement well.
The entry-tier acquisition workbook for the ciso.diy catalog — built around the February 26, 2024 final publication of NIST CSF 2.0 (NIST.CSWP.29). All 106 Subcategories with verbatim outcome statements, not paraphrases.
14-tab architecture (270 formulas, zero errors):
Organizational Profile Generator — the new-in-2.0 concept that most vendors fail to implement well. Captures organizational context, sector, regulatory environment, and risk appetite to ground your tier assessments in business reality rather than abstract maturity scoring.
Function tabs (GV / ID / PR / DE / RS / RC) — all 6 Functions, all 22 Categories, all 106 Subcategories. Each Subcategory has the verbatim outcome statement from NIST.CSWP.29, Current Tier dropdown (0–4), Target Tier dropdown, and a nested-IF Gap calculation that works across all Excel versions. DETECT tab correctly handles the non-sequential numbering (DE.CM-01, -02, -03, -06, -09) with guide notes for first-time assessors.
Heatmap — aggregates Subcategory ratings up to Category and Function levels using SUMPRODUCT/ISNUMBER-SEARCH pattern. Blank-aware: unrated Categories show empty, not zero — critical for partial assessments. Function colors match NIST's published wheel (purple=GOVERN, teal=IDENTIFY, green=PROTECT, amber=DETECT, rose=RESPOND, indigo=RECOVER).
Dashboard — 8 KPI tiles and Function-level summary table. Auto-populates from all assessment tabs.
Gap Analysis — pre-populated with 12 representative 2026 high-gap scenarios including GV.SC-04 (supplier prioritization), PR.DS-10 (data-in-use protection), RC.RP-03 (backup integrity verification), and 9 others reflecting where organizations consistently score lowest in 2026 assessments.
Tier Assessment — maps your profile to CSF Tiers 1–4 with the four Tier dimensions (Risk Governance, Risk Management, Third-Party, Organizational Culture).
Crosswalks — 37 rows mapping Subcategories to SP 800-53 rev 5, SP 800-171 rev 3, CIS Controls v8.1, and ISO 27001:2022. Enables scope-once, satisfy-many compliance strategy.
Forest green palette — visually distinct from the teal US Privacy workbook, blue GDPR workbook, and burgundy executive products in the catalog.
User Guide (30 pages): Full walkthrough of all six Functions including the DETECT numbering gap, four Organizational Profile strategy templates (Balanced maturity, Governance-led, Operational depth, Minimum viable), and three worked examples — new FTE CISO at Series C SaaS, vCISO starting a 20h/month retainer, compliance lead pursuing SOC 2 + ISO 27001 dual-track.
Also available in 7 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Board Preparation Bundle
CISO Budget Workbook + CISO Board Reporting Pack + NIST CSF 2.0 — everything a CISO needs for the quarterly board cycle. 19% off list.
Compliance Program Starter
The Pillar 01 operating system plus the two workbooks most first programs actually need — SOC 2 Readiness and the NIST CSF 2.0 Self-Assessment — with both PDF readiness checklists included. 24% off buying separately.
vCISO Starter Pack
vCISO Client-in-a-Box + NIST CSF 2.0 Assessment + CISO Board Reporting Pack — drop-in kit for fractional CISOs running concurrent clients. 19% off list.
New CISO Starter Pack
CISO 90-Day Onboarding + NIST CSF 2.0 Assessment + CISO Budget Workbook + Board Reporting Pack — your Day-90 board meeting in a bundle. 19% off list.
CISO Executive Suite
CISO 90-Day Onboarding + Budget + Board Pack + NIST CSF 2.0 + Tabletop Exercise Pack — the most complete CISO toolkit in the catalog. 25% off list.
Federal Contractor Pack
CMMC 2.0 + NIST CSF 2.0 + PCI DSS for defense and federal contractors — built for DoD, GSA, and agency RFP responses. 19% off list.
vCISO Complete Practice
vCISO Client-in-a-Box + CISO 90-Day Onboarding + NIST CSF 2.0 + Budget + SOC 2 + Board Pack — complete vCISO practice toolkit. 24% off list.
What's included
- Excel (.xlsx) — fully editable
- Word (.docx) — User Guide — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee