Work out security maturity score instantly with clear inputs, formula shown and shareable results.
Scoring the NIST Cybersecurity Framework functions separately exposes the imbalance that an aggregate hides. Organisations routinely invest heavily in Protect while Detect and Respond lag, which produces exactly the profile where a breach goes unnoticed for months. The spread between strongest and weakest is often a more actionable number than the average.
Maturity aggregation
overall = mean of the function scores; spread = highest - lowest; tier bands at 2, 3 and 4
No. The framework's own guidance is to choose a target profile appropriate to your risk, not to reach level 5 everywhere. Over-investing in low-risk areas is a real failure mode.
Detection needs continuous telemetry, tuning and staffed analysis rather than a one-off deployment, so it carries ongoing cost that preventive controls do not.