Are you CSF-ready? The 2-minute check
Eight questions, two minutes. Scored against the six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover.
What a CPG gap assessment actually includes
A CSF 2.0 gap assessment is a dry run against the framework’s 106 subcategories: a consultant interviews your team, tests controls, and hands you a prioritized gap list. This quiz is the 2-minute version — it tells you whether you’re ready for that conversation.
The 2-minute quiz
1. Do you have a documented cybersecurity risk management strategy approved by leadership?
2. Do you maintain a current inventory of assets — devices, data, and systems?
3. Is multi-factor authentication enforced for remote access and privileged accounts?
4. Do you remediate known exploited vulnerabilities on a defined cadence?
5. Are security logs centralized and monitored for detection?
6. Do you have an incident response plan that has actually been tested?
7. Are backups isolated from the network and tested for restore?
8. Do you assess the cybersecurity risk of third-party vendors?
How scoring works
Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with CISA's free services plus a gap assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready. This is a self-assessment aid, not an audit opinion.
Know your score? Get quotes
Firms scope fees around readiness. Tell us where you stand and get matched.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.