Cybersecurity is no longer a problem the IT department can solve on its own. A single incident can drain cash, halt operations, invite regulatory scrutiny, and shake the confidence of the customers, partners and stakeholders an organization depends on.

The financial stakes make that clear. The FBI’s Internet Crime Complaint Center (IC3) reported $20.877 billion in losses in its 2025 annual report, up from $16.6 billion the year before — a 26% increase in a single year. Of that total, $17.7 billion was tied to cyber-enabled fraud, meaning schemes in which criminals use the internet or other technology to steal money, data, and identities or to create counterfeit goods and services.

The pattern behind those losses is instructive. Investment-related fraud was again the largest single category, followed by business email compromise (BEC) and tech support scams. These cyber incidents are patient, well-resourced schemes that exploit ordinary business processes and human trust — and they are growing more convincing as attackers put generative AI to work.

For C-suite leaders and boards, the takeaway is not to chase every headline threat but understand where the organization actually stands, where its gaps are, and whether its defenses match its risk. That understanding starts with a NIST Cybersecurity Framework (CSF) maturity and gap assessment.

Understanding the NIST Cybersecurity Framework

An Overview of NIST CSF

The NIST Cybersecurity Framework is a voluntary, widely adopted standard developed by the National Institute of Standards and Technology (NIST). Rather than prescribing a rigid checklist, it provides a common language and structure for managing enterprise-wide cybersecurity risk in terms leadership can act on. Its current version, NIST CSF 2.0, organizes cybersecurity risk into six core functions:

  • Govern: Organizational context, risk management strategy, roles and responsibilities, policies, oversight, and supplier risk.
  • Identify: Asset visibility, risk assessment and continuous improvement.
  • Protect: Identity and access controls, awareness and training, data security, platform security, and resilience.
  • Detect: Continuous monitoring, detection processes and adverse event analysis.
  • Respond: Incident management, analysis, communication and mitigation.
  • Recover: Recovery planning, restoration, communication and improvement.

Framing cybersecurity around these functions shifts the conversation away from technicalities and toward enterprise risk. It gives executives and boards a way to see current capabilities relative to business objectives, regulatory expectations and how peer organizations operate. These functions also create a shared vocabulary for prioritizing investments and tracking progress over time.

NIST CSF Functions and Categories 

NIST CSF Functions and Categories graphic

Why Cybersecurity Maturity Matters

Having security tools in place is not the same as managing risk well. Maturity describes how consistently, deliberately and effectively an organization applies its practices — and it is often the difference between an incident that is contained and one that becomes a crisis.

Your IT team can rebuild a server. It is much harder to rebuild the trust of customers and stakeholders that a cyber incident breaks.

Systems can usually be restored from tested, isolated backups in days or weeks. Trust, once broken, can take years to rebuild, and some relationships never fully recover. The exposure is real and growing, as data breaches accounted for 39% of the cyber threats reported to IC3 in 2025, the single largest category.

Artificial intelligence (AI) is widening the gap further. Staff across nearly every organization are entering sensitive information — customer records, financial data, HR files and confidential documents — into AI tools, frequently without anyone knowing. So, now the question shifts from "Are employees using AI?," to "Does the organization have the policies, training, and technical controls to govern how they use it with organizational data?"

Cybersecurity risks and needs are different for every organization, because they are dynamic, and the response to them must align with the business, its operations and its goals. There is no one-size-fits-all program. That is precisely why a maturity and gap assessment matters. A NIST CSF maturity assessment and gap analysis establishes where an organization stands today, where it needs to be, and how to close the distance in a way that fits its priorities and resources.

The Four NIST CSF Maturity Levels

NIST CSF describes maturity through four levels that reflect how rigorous and integrated an organization’s cybersecurity risk management has become, progressing it through consistency, governance and the ability to adapt versus technology. 

Level

What It
Looks Like

The Risk It
Leaves Behind

1. Partial

Cybersecurity is handled reactively and informally. Practices are ad hoc, undocumented and dependent on individuals rather than repeatable processes. Risk decisions happen in isolation with little visibility. The organization often does not know what it does not know.

2. Risk-informed

Leadership is aware of cyber risk and has approved some practices, but they are applied inconsistently and are not yet organization-wide. Awareness outpaces execution. Controls exist on paper but are unevenly enforced across teams and systems.

3. Repeatable

Policies are formalized, consistently applied, and updated as the business and threat landscape change. Risk management is embedded in operations. A strong baseline, but the program may still respond to change rather than anticipate it.

4. Adaptive

The organization actively refines its practices based on lessons learned, predictive indicators and evolving threats. Cybersecurity informs strategic decisions. The goal state for most organizations, though the appropriate target depends on risk tolerance and resources.

The highest level (level four) is not automatically better for every organization. The right target tier depends on an organization’s risk tolerance, regulatory obligations and available resources. A maturity assessment helps leadership decide where it genuinely needs to be and where a given level of risk may be acceptable.

Inside a NIST CSF Maturity and Gap Assessment

Conducting the Assessment

A well-run assessment is a structured, evidence-based review rather than a questionnaire. It typically moves through five stages, each building on the last:

  • Objectives and Scope: The assessment begins by clarifying the parts of the organization, systems, data, vendors and business processes that should be included. This step also establishes the organization’s risk tolerance and the type of reporting leadership will need to make informed decisions.
  • Current-state Discovery: The assessment then reviews the policies, standards, procedures and technical evidence that define the organization’s cybersecurity program. Stakeholder interviews across IT, security, operations, legal, HR and finance help validate whether documented practices reflect how risk is managed daily.
  • Gap Analysis: Findings are mapped to NIST CSF categories and subcategories to identify where controls are mature, where practices are inconsistent and where risk may be concentrated.
  • Prioritization and Roadmap Development: Not every gap carries the same level of risk. The most useful assessments prioritize findings based on likelihood, impact and remediation feasibility, then translate them into a phased roadmap that reflects operational realities.
  • Executive Reporting: The final output should give leadership a clear view of maturity, gaps and next steps through an executive summary, detailed gap and maturity matrix, and prioritized roadmap.

Because the process relies on both documentation and candid conversation, its value depends heavily on stakeholder participation. The most useful assessments surface the difference between the program that exists on paper and the one that operates day to day.

A Typical Timeline

A NIST CSF risk, gap and maturity assessment generally runs six to eight weeks, depending on stakeholder availability and the complexity of the environment. The work unfolds across four phases:

NIST CSF timeline graphic

Assessing Current State Against Desired State

The gap analysis is the heart of the engagement. It compares where an organization is against where it needs to be, translating a broad sense of “are we secure?” into a specific, prioritized picture of risk. Gaps are ranked by likelihood and impact, then weighed against how practical each remediation is. This way, leadership can focus first on the exposures that matter most.

The output is a phased roadmap, typically organized into zero to 90-day, three to six-month, and six to 12-month horizons. That structure turns findings into a manageable sequence of decisions rather than an overwhelming list, and it aligns cybersecurity investment with organizational priorities and resources.

The Benefits of a NIST CSF Maturity and Gap Assessment

A Stronger Cybersecurity Posture

The most direct benefit of a NIST CSF maturity and gap assessment is clarity. As organizations grow financially, operationally and technologically, their cybersecurity risk profile often becomes more complex. New systems, expanded data use, third-party relationships, remote work arrangements and evolving customer or stakeholder expectations can all create exposures that informal or outdated governance structures were not designed to manage.

A maturity assessment helps leadership understand whether the organization’s cybersecurity program has kept pace with that growth. It replaces assumptions with an evidence-based view of strengths, weaknesses and emerging risk areas, so resources can be directed toward the initiatives that matter most. The result is a more structured and scalable approach to cybersecurity governance, risk management and continuous improvement — one that can evolve alongside the organization rather than lag behind it.

Alignment With Compliance Requirements

From SEC disclosure rules to industry frameworks (e.g., ISO 27001, PCI DSS, and NIST SSDF) and customer contract requirements, regulatory expectations are converging around demonstrable cybersecurity governance. Because NIST CSF maps cleanly to many of these obligations, an assessment helps organizations identify where they already meet expectations and where they fall short, reducing the risk of findings, penalties, and last-minute scrambles when a regulator, auditor or major client comes asking.

Greater Trust With Stakeholders

A maturity baseline aligned to NIST CSF does more than protect data; it demonstrates sound stewardship. It gives boards, customers, investors, auditors and partners confidence that cybersecurity is being managed deliberately and reviewed at the right level.

That trust is especially important for organizations that depend on public confidence, member engagement, donor support or long-term stakeholder relationships. For not-for-profit organizations, protecting sensitive donor, beneficiary and financial information is closely tied to preserving donor trust. For businesses, the same principle applies to customers, employees, investors and partners who expect their information to be handled responsibly. In a market where trust is hard to earn and easy to lose, a mature cybersecurity program can become a meaningful differentiator.

Making the Most of a NIST CSF Assessment

What an Effective Assessment Delivers

Not every assessment is created equal. The ones that hold up under board and diligence scrutiny share a few traits worth insisting on:

  • Ratings mapped to NIST CSF categories, so results are consistent and comparable over time and against peer organizations.
  • An executive-level report on gaps and risks, paired with the detail needed to act.
  • A prioritized, phased roadmap tied to real operational constraints rather than an idealized end state.
  • A common language that lets technical teams, executives, and the board make informed, risk-based decisions together.

Turning the Assessment Into Continuous Improvement

Cyber risk does not hold still, and neither should the response to it, so the greatest value comes from treating an assessment as a recurring discipline rather than a one-time event. Cyber risk should be reassessed as the business grows, as technology changes and as new threats emerge. Each cycle measures progress against the last, keeps the roadmap current, and promotes cybersecurity maturity advancement in step with the organization it protects.

The Bottom Line

Cybersecurity has become a core leadership risk, and managing it well requires knowing where an organization truly stands and where it needs to go. A NIST CSF maturity and gap assessment provides exactly that: a clear-eyed view of current capabilities, a prioritized understanding of risk and a practical path forward. For executives and boards, it turns cybersecurity from a reactive expense into a deliberate, defensible investment in resilience.

Frequently Asked Questions 

A NIST CSF maturity assessment gives leadership an objective, business-aligned view of how well the organization manages cybersecurity risk across the six NIST CSF functions: govern, identify, protect, detect, respond and recover. By comparing current practices against a defined target state, it pinpoints gaps, prioritizes them by risk, and produces a roadmap for closing. The goal of the assessment is to ground cybersecurity decisions in evidence rather than assumptions. 

A clear maturity baseline enables leadership to direct resources toward the risks that matter most, demonstrate sound governance to regulators and stakeholders, and track measurable progress over time. It also creates a shared language that helps technical teams, executives, and boards make aligned, risk-based decisions instead of talking past one another.

The most frequent misstep is treating the review as a paperwork exercise and evaluating what policies say rather than how the organization actually operates. Others include limited stakeholder participation, scoping that is too narrow to reflect real risk, and treating the assessment as a one-time event rather than an ongoing practice. Strong engagement across departments and honest input are what make the findings reliable.

Your Guide Forward

Cherry Bekaert’s Risk & Cybersecurity Services team provides trusted advice to help organizations understand and respond to cybersecurity risks and gaps — through assessments, analysis, roadmap development, remediation assistance, and cybersecurity program and project management. A NIST CSF maturity and gap assessment is a practical first step toward a clearer, more defensible view of your cyber risk.

Ready to understand where your organization stands?

Connect With Us

Related Insights

Kurt Manske headshot

Kurt Manske

Cybersecurity Leader

Partner, Cherry Bekaert Advisory LLC

Contributor

Connect With Us

Kurt Manske headshot

Kurt Manske

Cybersecurity Leader

Partner, Cherry Bekaert Advisory LLC

Recommended Insights