Cybersecurity Maturity Assessment (NIST CSF)

See exactly how mature your security program is against the NIST Cybersecurity Framework - and get a clear, tiered roadmap to where it needs to be.

A cybersecurity maturity assessment measures how well your security program meets the NIST Cybersecurity Framework (CSF 2.0) across its six core functions, then scores you against the framework's four implementation tiers. Consilien runs NIST CSF maturity assessments for mid-market California companies and delivers a tiered roadmap from your current state to your target tier.

A pile of security tools isn't a security program.

You've bought the firewall, the endpoint protection, the email filtering, maybe a SIEM. Each one works. None of them tells you whether they add up to a program that would hold under a real attack - or stand up to a board, an auditor, or a cyber insurance underwriter asking how you measure security.

That's the question a NIST CSF maturity assessment answers. Not "do you have controls," but "how good are they, how consistently are they applied, and how do they compare to a recognized national standard." The NIST Cybersecurity Framework is the most widely adopted security framework in the United States, used by organizations of every size to structure and measure their security programs. Verizon's 2025 Data Breach Investigations Report found that 88% of breaches at small and mid-sized businesses involved ransomware. IBM's 2025 Cost of a Data Breach Report put the average U.S. breach at $10.22 million. Most of the companies in those numbers had security tools. What they didn't have was a measured, structured program.

For mid-market companies, the gap usually isn't budget or intent. It's structure. Tools get bought reactively - one incident or one audit at a time - and nobody ever steps back to score the whole thing against a standard. A maturity assessment is that step back.

What a NIST CSF Maturity Assessment Actually Measures

NIST CSF 2.0 organizes security into six core functions. We assess your program against each one, then score how consistently it's actually applied.

The six core functions of the NIST Cybersecurity Framework on a shield

The Four NIST CSF Implementation Tiers

The NIST framework scores a program across four implementation tiers. The tiers don't measure how many tools you own - they measure how rigorously and consistently you manage cybersecurity risk. Here's what each one looks like, and where mid-market companies usually land.

Tier What it looks like Typical mid-market reality
Tier 1 - Partial Risk managed case by case. Reactive, ad hoc, little formal process or awareness. Security lives with whoever has time. No written policy, no owner.
Tier 2 - Risk Informed Management approves risk practices, but they aren't applied across the whole organization. Good intentions and some controls, applied inconsistently. Where most companies start.
Tier 3 - Repeatable TARGET Formal policies applied consistently across the organization and updated as risk changes. The right target for most mid-market companies. Repeatable, defensible, sustainable.
Tier 4 - Adaptive Continuous improvement. Security adapts to evolving threats in near real time. Often more than a mid-market business needs or can sustain day to day.

Why Mid-Market Companies Land at Tier 1 or 2 - and What Gets Them to Tier 3

Most mid-market companies we assess come in somewhere between Tier 1 and Tier 2. That's not a failure - it's the predictable result of growing faster than your security structure. Headcount doubled, a second site opened, the tool stack grew one purchase at a time, and the policy that governs all of it never caught up.

The jump to Tier 3 is mostly about structure, not spend. Written policies that actually get followed. Governance that puts a named person accountable for security risk. Consistent application across the whole organization, not just the parts IT touches directly. The controls you already own, configured and maintained instead of installed and forgotten. For most mid-market companies, Tier 3 - not Tier 4 - is the right target: repeatable, defensible, and sustainable without a Fortune 500 security budget.

By the Numbers

88%

88% of breaches at small and mid-sized businesses in 2025 involved ransomware. Most of the companies hit had security tools. What they lacked was a measured program.

Verizon DBIR 2025

$10.22M

$10.22 million - the average U.S. data breach cost in 2025. A maturity assessment costs a fraction of that and is entirely in your control.

IBM Cost of a Data Breach Report 2025

6

Six core functions in NIST CSF 2.0 - Govern, Identify, Protect, Detect, Respond, and Recover. We score your program against every one.

NIST CSF 2.0

4 Tiers

Four implementation tiers, from Partial to Adaptive. Most mid-market companies start at Tier 1 or 2. The practical target is Tier 3.

NIST CSF Implementation Tiers

How the Assessment Works

1

Phase 1 - Scope and Discover

We define what's in scope and build a picture of your environment - systems, data, people, and the controls already in place. No assumptions, no guessing at what you have.

2

Phase 2 - Assess Against the Framework

We score your program across all six NIST CSF functions using interviews, documentation review, and evidence - not a self-rated questionnaire. We measure what's actually in place, not what's on paper.

3

Phase 3 - Tier and Gap Analysis

We assign the implementation tier you sit at today, set a target tier based on your risk and obligations, and map the specific gaps between the two. This is where "we have security" becomes a number.

4

Phase 4 - Roadmap and Readout

You get a prioritized roadmap to close the gap and an executive readout built to brief a board. If you want help doing the work, that's part of what we do. If you have an internal team, they get a clear plan to run with.

Maturity Assessment vs. Risk Assessment

These two assessments get confused constantly, and the difference matters when you're deciding which one you actually need.

A cybersecurity risk assessment identifies your specific threats and vulnerabilities - what could go wrong, how likely it is, and what it would cost you. A maturity assessment measures how good your overall program is at managing risk, scored against the NIST CSF standard. One finds the fires. The other tells you whether your fire department is any good.

They work best together, and most companies eventually run both. If you're earlier in the process and need to find your specific gaps first, start with a cybersecurity risk assessment. If you already know you have a program and need to measure and prove how mature it is, the maturity assessment is the one you want.

What Is a Cybersecurity Maturity Assessment?

A cybersecurity maturity assessment is a structured evaluation of how well an organization's security program meets a recognized framework - in this case NIST CSF 2.0 - measured across the framework's core functions and scored against defined maturity tiers. Unlike a one-time vulnerability scan, it evaluates the program as a whole: governance, process, and consistency, not just technical gaps.

Who This Is For, and Who It Is Not

A NIST CSF maturity assessment fits mid-market California companies that have outgrown ad hoc security and need to know where they actually stand - from growing manufacturers and distributors to professional services firms and multi-site operations.

It's the right engagement if a customer, partner, or insurer has started asking how you measure security. If you're a manufacturer or defense subcontractor that needs to show structured security to win or keep contracts. If your board or leadership wants a defensible answer to "how secure are we, really." Or if you've accumulated security tools over the years and suspect they don't add up to a coherent program.

It's probably not the right fit right now if you're a very small business with a handful of employees and no compliance pressure - a lighter risk assessment may serve you better. Or if you're mid-incident and need immediate response rather than a structured evaluation. Or if leadership has no appetite to act on the roadmap - the assessment produces a prioritized plan, and the value drops sharply if no one intends to work through it.

Checklist and maturity gauge showing whether a NIST CSF assessment is the right fit

The Questions We Get Asked Most

"We already follow security best practices. Why do we need a formal assessment?"

Following best practices and being able to prove a measured maturity level are different things. Boards, auditors, customers, and insurers increasingly want the second one - a defensible score against a recognized standard, not a list of tools. A maturity assessment turns "we take security seriously" into "we're at Tier 2 today, here's our roadmap to Tier 3."

"Isn't NIST CSF overkill for a company our size?"

It's the opposite. NIST CSF scales by design - it's a framework, not a checklist of expensive controls. For mid-market companies it's the most practical way to structure security without taking on something as heavy as full ISO 27001 certification. You assess against the same six functions either way; the depth scales to your size and risk.

"What do we actually get at the end?"

A current maturity score across all six NIST CSF functions, the implementation tier you sit at today, a target tier based on your risk and obligations, and a prioritized roadmap to close the gap. It's built to brief a board and to hand to whoever does the work - your internal team or ours.

Common Questions About Cybersecurity Maturity Assessments

What is a cybersecurity maturity assessment?


A cybersecurity maturity assessment is a structured evaluation of how well your security program meets the NIST Cybersecurity Framework (CSF 2.0). It scores your program across the framework's six core functions - Govern, Identify, Protect, Detect, Respond, and Recover - and assigns an implementation tier from 1 to 4. The result is a clear picture of where your security program stands and a roadmap to where it should be.

Most companies discover the gaps in their security program the hard way - during an incident, a failed audit, or a contract they didn't win. A maturity assessment is the controlled version of that discovery: the same hard truths, surfaced on your schedule instead of an attacker's.

You can't improve what you haven't measured. A NIST CSF maturity assessment gives you a number, a tier, and a roadmap - and unlike a breach or a lost contract, it's entirely in your control. Start with where you actually stand.

Find out what tier your security program is really at.

Most companies discover the gaps in their security program the hard way - during an incident, a failed audit, or a contract they didn't win. A maturity assessment is the controlled version of that discovery: the same hard truths, surfaced on your schedule instead of an attacker's.

You can't improve what you haven't measured. A NIST CSF maturity assessment gives you a number, a tier, and a roadmap - and unlike a breach or a lost contract, it's entirely in your control. Start with where you actually stand.