NIST CSF Maturity Assessment for Regulated Organizations
A NIST CSF maturity assessment tells you where your cybersecurity program actually stands — not where your policies say it should stand. It maps current practices against the six functions, identifies gaps between current and target profiles, and produces a remediation roadmap with defensible priorities. Armorstack's VERITY team delivers structured CSF assessments across healthcare, financial services, manufacturing, and the defense industrial base.
What a Maturity Assessment Actually Measures
CSF uses the concepts of Current Profile and Target Profile to frame the assessment. A Current Profile documents the CSF outcomes — specific subcategories across the six functions — that the organization is currently achieving. A Target Profile documents the outcomes it needs to achieve given its risk appetite, regulatory obligations, and business context. The gap between the two is the remediation roadmap.
This framing matters because it prevents the most common failure mode in framework assessments: evaluating what policies exist rather than what controls are operational. A real assessment is not a document review — it examines whether controls are deployed, operating consistently, monitored and enforced, and whether evidence of their operation exists in a form that satisfies auditors and regulators. GOVERN, introduced in CSF 2.0, is often where the most significant gaps appear: mature IDENTIFY, PROTECT, and DETECT capabilities frequently coexist with immature GOVERN practices, creating a profile that looks stronger than it is until governance is examined. See the GOVERN function deep dive for what that gap typically looks like.
The Six Functions: What the Assessment Examines
GOVERN
Whether a documented risk management strategy with defined risk appetite exists, whether roles and accountabilities are formally assigned, whether policies are current and enforced, whether leadership acts on risk information, and whether third-party risk management is operational. GOVERN gaps at GV.OC, GV.OV, and GV.SC are the most common blockers to advancing beyond Tier 2.
IDENTIFY
Asset inventory completeness (systems, data, applications), business environment documentation, risk assessment rigor and cadence, and improvement planning. Common gaps: inventories that miss cloud workloads, SaaS, and OT, and annual risk assessments that don't drive resource allocation.
PROTECT
Identity and access control including MFA and access reviews, awareness training, data security, platform configuration and patch management, and infrastructure resilience. Common gap: MFA on remote access but not on administrative access to critical systems.
DETECT
Continuous monitoring capability, log collection scope and retention, anomaly detection, and documented evidence that alerts are reviewed and acted upon. The most common gap: monitoring in place that no one systematically reviews.
RESPOND
Whether an incident response plan exists and has been tested (tabletop or functional), whether roles and communications are documented, and whether lessons-learned processes exist. Untested plans are treated by auditors as demonstrating intent, not capability.
RECOVER
Recovery planning documentation, restoration process testing, and communications protocols. Backup and DR are examined against documented recovery time/point objectives and whether those objectives have actually been tested.
How Armorstack Conducts the Evaluation
Armorstack's VERITY team conducts assessments through a structured process combining document review, technical validation, and stakeholder interviews. Document review alone is insufficient — the gap between documented policy and operational reality is precisely what the assessment is designed to surface.
The process begins with a pre-assessment data collection phase covering policies, risk assessments, asset inventories, incident response plans, business continuity plans, training records, and vendor management documentation, reviewed against the applicable CSF subcategories.
The technical validation phase examines operational evidence: log collection coverage against the asset inventory, MFA deployment against the user population, patch currency against policy, and endpoint protection deployment against the endpoint inventory — identifying the gaps between what policy says should happen and what the evidence confirms is happening.
Stakeholder interviews with IT leadership, security operations, business unit leadership, and executive sponsors surface the governance and integration gaps that neither documents nor technical configuration can reveal — whether risk decisions involve executive input, whether cybersecurity risk appears in board reporting, and whether security requirements flow into vendor selection.
Assessment Output: What You Receive
The output is a Current Profile documenting assessed status across all applicable subcategories, a Target Profile defined by regulatory context and risk appetite, a gap analysis organized by function and priority, and a remediation roadmap with specific actions, owners, and timelines.
The roadmap is not a ranked list of every gap found — it is a sequenced plan that addresses foundational gaps before advanced ones: GOVERN and IDENTIFY gaps before PROTECT and DETECT enhancements, governance integration before additional monitoring tooling, because sequencing matters as much as content. Organizations that invest in detection capability before establishing the oversight function to act on findings add cost without reducing risk. For organizations whose assessment reveals significant gaps, the 90-Day Proof delivers the highest-priority remediation within a single quarter, establishing the foundation for a continuous compliance program.
Ready to See Where Your Program Actually Stands?
Schedule a NIST CSF maturity assessment with Armorstack's VERITY team — document review, technical validation, and stakeholder interviews, translated into a sequenced remediation roadmap.
Schedule a Consultation →