Get Demo
↑

NIST CSF 2.0 Assessment Template: Score All 106 Subcategories

Self-assessment worksheet for CSF 2.0 — Current versus Target Profile across 106 Subcategories, with Tier notes.

Published: September 2026 Compliance · NIST 8-12 min read

NIST CSF 2.0 organizes cybersecurity outcomes into 6 Functions, 22 Categories, and 106 Subcategories (CSWP 29). A practical assessment template records your Current Profile, desired Target Profile, and gaps — without pretending the spreadsheet is a NIST certification.

Related: Tiers and Profiles · Govern · CSF 2.0 guide.

How to Use the Template

  1. List all 106 Subcategories (or import NIST’s Core reference export)
  2. Score Current state with a simple scale such as Not Started / Partial / Implemented / Optimized (editorial scale — label it as yours)
  3. Set Target based on risk appetite and Tier intent
  4. Capture evidence links and owners for Implemented items
  5. Roll gaps into a prioritized roadmap; revisit after major incidents or annual risk reviews

Profiles, Tiers, and Scoring

Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) describe risk-management culture — they are not subcategory maturity scores. Use Tiers to set expectations for how formal your processes should be; use Profiles to show Current vs Target outcomes across the Core.

How CyberSilo Helps

Replace Annual Spreadsheets with Continuous Profiles

Keep Current and Target Profiles tied to evidence your board and auditors can follow.

Frequently Asked Questions

Is there an official NIST Excel template?

NIST publishes Core materials and tools; organizations commonly build scoring sheets on top. Treat any third-party template as a starting point, not an official NIST form.

Must every organization implement all 106 Subcategories?

No. CSF is risk-based. Profiles select and prioritize outcomes; document why lower-priority items remain Partial or Not Started.

How does this relate to Tier selection?

Tiers set process formality; Subcategory scores show outcome coverage. Use both, but do not treat Tier 4 as a requirement for every Subcategory.

NIST hub · What Is NIST CSF 2.0? · 800-171 Rev 3 Changes · CSF 1.1 vs 2.0

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!