Cybersecurity › Free assessment

How secure is your organization from cyberattacks?

Find out for free with our assessment based on the international NIST Cybersecurity Framework 2.0 standard, used by thousands of organizations worldwide.

106 questions · about 15 minutes · instant report · no commitment

Why take this assessment?

The NIST CSF 2.0 is the world’s leading standard for cyber risk management, adopted by organizations of every size. The assessment is free, with no commitment, and designed for executives and managers: clear, accessible questions, even without specific technical expertise. Your data is processed in compliance with GDPR and you can delete it at any time with a single click.

106 questions on the NIST CSF 2.0

Guided multiple-choice questions on security processes, roles and controls. No technical data to enter: whoever knows the company can answer.

Instant report in 15 minutes

The average time to complete the self-assessment questionnaire. Your cyber maturity score, overall and per function, arrives immediately, also by email.

6 functions, one score each

Govern, Identify, Protect, Detect, Respond, Recover: the six framework functions, each with a dedicated score plus the overall score.

How it works

Three steps to a snapshot of your security.

The tool is free and confidential: complete it when you like, get the result immediately and decide how to proceed.

Step 1 · about 15 minutes

Complete the questionnaire

Answer 106 questions across the 6 functions of the NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover.

Step 2 · instantly

Receive your score

Instantly get your cybersecurity score, both overall and for each functional area, delivered directly via email.

Step 3 · if you wish

Improve your security

Identify critical areas and priorities for action. Our team can support you on the improvement journey.

What it measures

The 6 NIST CSF 2.0 functions

The framework covers the entire cyber risk management lifecycle: for each function the report shows your level.

GV

Govern

Cybersecurity strategy, policy and organizational oversight.

ID

Identify

Understanding assets, risks and the organizational context.

PR

Protect

Access controls, training, data protection and platform security.

DE

Detect

Continuous monitoring and security event analysis.

RS

Respond

Management, analysis and mitigation of security incidents.

RC

Recover

Service restoration and communication after an incident.

A service by AtWorkStudio

Ready to assess your organization’s cybersecurity?

This assessment is developed and managed by AtWorkStudio, a company certified ISO/IEC 27001, ISO 9001, ISO/IEC 27017 and 27018 and compliant with ISO/IEC 20000-1. We offer specialized consulting in cybersecurity, NIS2 Directive compliance, IT service management and international certification support.

It takes about 15 minutes to complete the assessment and receive your score.

Start now

Find out more about AtWorkStudio