Cyber Maturity · NIST CSF 2.0
How mature is your cybersecurity program, really?
You patch what breaks and react to what alerts. But when your board, your insurer, or your next auditor asks where you actually stand, “we think we’re fine” isn’t an answer they’ll accept. This 2-minute self-check gives you a directional maturity score across the six NIST CSF functions, and shows where to focus first.
12 quick questions · No answer is wrong · Your score at the end
Who are we tailoring this for?
Just so the questions read properly, and so we can address the results to you.
Two details so the questions fit your situation
Maturity looks different for a 40-person firm than a 4,000-person one, and different again depending on where you sit. This shapes how we read your answers.
Where should we send {company}’s results?
{first_name}, your score and six-function snapshot are on the next screen. We’ll email a copy so you have it for your records, and so you can forward it.
Where to focus first
Continue {company}’s Skyrocket journey
You’ve completed a directional Assess. Your formal Skyrocket Maturity Score comes from an expert-led, evidence-based assessment, benchmarked against NIST CSF 2.0 and delivered with a Gap Analysis report and executive walkthrough. From there, Skyrocket sequences the climb: Prioritize (Quick-Win Sprint) → Implement (Managed Security Services) → Operate (Continuous vCISO Oversight).
Reference
The four NIST CSF implementation tiers
Your score bands into one of the four implementation tiers published in the NIST Cybersecurity Framework. The tier matters more than the number. It describes how consistently security decisions get made, not how many tools are deployed.
| Tier | Score | What it describes |
|---|---|---|
| Partial | 0–25 | Cybersecurity is handled case by case. Risk decisions happen without organization-wide awareness, and practice varies between teams. |
| Risk-Informed | 26–50 | Leadership has approved risk practices, but they are applied inconsistently and are not yet policy across the organization. |
| Repeatable | 51–75 | Practices are formal policy, applied consistently, and updated as requirements and the threat landscape change. |
| Adaptive | 76–100 | The program improves continuously from lessons learned and predictive indicators, and adapts ahead of emerging threats. |
How this self-check is scored
Twelve questions, two per NIST CSF 2.0 function (Govern, Identify, Protect, Detect, Respond, Recover). Each answer maps to an implementation tier worth 0, 33, 67, or 100. Each function score is the average of its two answers; the overall score is the average of the six function scores. Grounded in NIST CSF 2.0, CIS Controls v8, and the CISA Cybersecurity Performance Goals.
What this is, and what it isn’t
This is a directional, self-reported starting point rather than an assessment. A full engagement scores the same areas against evidence (interviews, configuration review, and technical validation), and most organizations land lower than they expect. Results here are indicative, based on our engagements, and not a guarantee of outcome.
DigitalEra Group · Doral, Florida · serving the United States, Latin America, and the Caribbean since 2000. SOC 2 Type II certified.
Skyrocket: a DigitalEra cybersecurity maturity journey. This self-check provides a directional indicator only and is not a formal Skyrocket Maturity Assessment.