For businesses in the U.S. federal supply chain

See where your cybersecurity is ready, and where it needs work.

Answer 65 structured questions in about 31 minutes. See your readiness grade and where to focus first.

Cyber AB Registered Practitioner badge

Cyber AB Registered Practitioner · RP-3056

Verify on the Cyber AB website (opens in a new tab)
Questions
65
Yes, Partial, No or Not sure
Estimated time
~31 min
Progress saves as you go
Readiness grade
Free
A+ to C−, with CSF breakdown
Initial unlock
…
… results included, then … each

How it works

Four clear steps from answers to action

Answer from what you know today. Nothing to upload and nothing to install.

  1. 1

    Answer 65 questions

    Choose Yes, Partial, No or Not sure across the six NIST CSF 2.0 functions.

    Free · about 31 minutes

  2. 2

    See your grade

    Get your A+ to C− grade, function breakdown and potential gaps immediately.

    Free · no card needed

  3. 3

    Unlock your action plan

    Get the Excel POA&M, exact score and Pre-Assessment Certificate when ready.

    … initial unlock

  4. 4

    Fix gaps and retake

    Assign owners, work the gaps and reassess to see what changed.

    … results included

Interactive questionnaire preview

Try three real assessment questions

Choose an answer below. Nothing is saved, and you can change each response.

Start all 65

Yes

In place everywhere it applies.

Partial

Some coverage, or completed but not documented.

No

Not currently in place.

Not sure

Scored as No and flagged for confirmation.

3 of 65 questions

Answered 0 of 3

Sample question 1
01 · ConfidentialitySC 3.13.8, 3.13.11, 3.13.16

The organization uses some form of encryption for both (1) data at rest and (2) data in motion.

Sample question 2
02 · IdentifyCM 3.4.1

The organization maintains an inventory of the organization's hardware assets, including endpoints, mobile assets, networking devices, and other I/O devices.

Sample question 3
03 · RespondIR 3.6.1, 3.6.2

The organization has defined and formalized a company-wide security incident response program.

Select an answer to see whether it creates a POA&M row.

Yes = 2 · Partial = 1 · No / Not sure = 0

Deliverables

What you get, before you pay

Previews use one illustrative sample organization and are laid out like the real downloads.

SAMPLE · PLAN OF ACTION AND MILESTONES

POA&M, Sample Organization

Excel download
Answered No11
Answered Partial7
Suggested dates30 / 60 / 90 days
ItemWeakness / findingRelated controlsPoint of contactSuggested date
V-009The organization has the capability to conduct continuous monitoring that discovers breaches in their early stages.DETECT · Answer: NoSystem & Info Integrity (SI): 3.14.6, 3.14.7
Audit & Accountability (AU): 3.3.5
Pat Lee (IT Manager)90 days
V-013The organization has defined and formalized a company-wide security incident response program.RESPOND · Answer: PartialIncident Response (IR): 3.6.1, 3.6.2Pat Lee (IT Manager)60 days
V-018The organization has cybersecurity policies and procedures that are formally approved, regularly reviewed, and accessible to all staff.GOVERN · Answer: NoGV.PO, governance recommendation (not a mandatory 800-171 Rev 2 control)Pat Lee (IT Manager)90 days

Pricing

Know the scope and price before you begin

A fixed-price readiness baseline, before you decide whether you need a larger consulting engagement.

Your unlocked report packReady to use
Three deliverables unlocked from one assessmentAn open folder containing an Excel POA and M, an exact IFST score report and a Pre-Assessment Certificate.POA&M ACTION REGISTEREXCELFINDINGCONTROLTARGETEXACT IFST SCORE385/ 500PDFPRE-ASSESSMENTCERTIFICATEUNLOCKED
One assessment becomes an editable action plan, an exact score and a dated Pre-Assessment Certificate.

Assessment unlock

…

One purchase. No subscription or retainer.

Everything included in your report pack:

  • Editable Excel POA&M for every gap
  • Exact IFST score out of 500
  • Pre-Assessment Certificate (PDF)
  • … completed assessment results
Start assessment

After the included results, each additional result costs …. Review the sample outputs before purchasing; generated reports are non-refundable.

Grade methodologyHow your grade is calculatedOpen the scoring model, weights and all nine grade bands.View details

How your grade is set

Nine grade bands on a 0 to 500 scale

Yes earns 2 points, Partial 1, No and Not sure 0. Answers are weighted by what they protect and by CSF function; Govern adds up to 50 points. The last maturity question gives context and does not change your score.

A+445 to 500

Strong and consistent

A389 to 444

Strong, a few gaps

A-333 to 388

Mostly in place, some uneven

B+278 to 332

Core in place, notable gaps

B222 to 277

Partial, several priority gaps

B-167 to 221

Limited, many priority gaps

C+111 to 166

Early stage, mostly informal

C56 to 110

Few practices in place

C-1 to 55

Little or none in place

You see your grade the moment you finish. Your exact number within the band comes with the unlock.

Cybersecurity readiness across the six NIST CSF 2.0 functionsSix cybersecurity functions connect to one central readiness picture.GOVERNDirection & policyIDENTIFYKnow your exposurePROTECTPut safeguards in placeDETECTFind events earlyRESPONDAct with a planRECOVERRestore & improveONE READINESS PICTURESee strengths, gaps and where to focus first
Your answers are organized across the full NIST CSF 2.0—not reduced to a generic checklist.

FAQ

Clear answers before you begin

The important details, without sales pressure or fine-print surprises.

Which NIST revision do you use?

Questions are organized around the six NIST CSF 2.0 functions. POA&M rows list related NIST SP 800-171 Rev 2 controls so you can connect each reported gap to an action area.

Is this a certification or an audit?

No. It is a self-assessment. Your result is generated automatically from your answers and is not reviewed individually. It does not certify your company, replace a C3PAO or CMMC assessment, or guarantee compliance.

What do I get for free, and what for …?

Free: your IFST™ grade, the function by function breakdown and your potential gaps. Your initial … purchase unlocks the editable Excel POA&M, your score out of 500 and a Pre-Assessment Certificate (PDF), with … assessment results included. After those included results are used, each additional result costs …. Review the sample outputs before purchasing. Because reports are generated immediately, completed purchases are non-refundable.

How is my information handled?

You answer multiple-choice questions only; nothing is uploaded, and you are never asked for passwords to your systems, network diagrams or IP addresses. Your account password is stored hashed, card payments are handled by Stripe, and the site runs no analytics or ad trackers. Your results stay in your account and are visible to you and to InfoSecTel LLC administrators. Ask us to delete your account and everything linked to it is removed.

Still have a question? Email wlyle@infosec.tel.

No card needed to start

Understand your cybersecurity readiness today.

Review your grade and potential gaps before you decide to unlock anything.

About 31 minutes · No card needed to start