This is a self-assessment, not an audit. It records what the people who filled it in believed to be true on the day, and has not been independently verified or tested.
Answer honestly — a flattering score helps nobody. Anything you genuinely do not know is better left blank than guessed; unanswered items are reported separately and never counted against you. Mark an item N/A only when it cannot apply to your organization.
Everything not in place, then everything partial. Each line names the safeguard and one concrete first move.
This is a self-assessment, not an audit. Nothing here has been independently verified or tested, and a good score is not evidence of a secure environment — only of stated intent.
Structured around the NIST Cybersecurity Framework 2.0 and scoped for smaller organizations using NIST SP 1300, the Small Business Quick Start Guide. The questions and the guidance are the author's own; NIST does not endorse this tool or its results. Further reading: the CIS Critical Security Controls and the Canadian Centre for Cyber Security's baseline controls for small and medium organizations.
Your answers stay in this browser and are never uploaded.
Built by Steven Turgeon, IT and cybersecurity consultant in Ottawa. If this turned up more gaps than you expected — or you want the fixes done rather than listed — that's usually worth a conversation.