How the score is calculated
Each question scores 0, 1, or 2 depending on the answer chosen. A function's score is the sum of its answers divided by the maximum possible, expressed as a percentage. The overall score is the average across all six NIST CSF functions - visible as the radial gauge on your results page. This is a straightforward roll-up, but it isn't the whole picture: see "the part that isn't just averaging" on the Methodology page for how compounding-risk flags factor in separately.
The AI Readiness & Governance track's scored questions count exactly the same way - they add to Protect's and Govern's own 0/1/2 totals, not a separate AI-specific score off to the side, so your function percentages reflect AI-specific posture wherever it applies to you, the same as every other question.
Why your score is what it is
Bands below are shown on a 0–10 scale (your overall percentage ÷ 10) - a 5–7, for example, means something specific about your organization, not just "middling." For how each phase of the Maturity Model connects to these bands, see that page directly.
Good bitsRare - if anything scores here, it's usually one isolated function (often Recover) while everything else is failing too.
Bad bitsCore controls are absent, not just weak - no MFA, no logging, no incident response plan, often no named security owner at all. This reflects total absence, not partial effort.
Why this numberEvery question in the affected function was likely answered at its lowest option - this isn't measurement noise, it's an accurate reflection of nothing being in place yet.
PriorityStart at Maturity Model Phase 1 - asset discovery. Nothing later matters until you know what you're protecting.
1.5 – 3.5
Elevated (severe)
Good bitsUsually one or two functions (often Identify or Recover) have partial coverage - an asset list exists, or backups happen even if untested.
Bad bitsProtect and Detect are typically the weakest here - MFA partial at best, no centralized logging, meaning an intrusion would likely go unnoticed for a long time.
Why this numberA handful of "Partial" answers pull the average up slightly off zero, but the functions that stop real attacks are still mostly unanswered at their lowest tier.
PriorityClose the highest-severity items in the Priority list first - this band is where compounding-risk flags (like exposed RDP plus weak backups) are most common and most dangerous.
Good bitsBaseline hygiene exists - patching happens, some endpoint protection is deployed - but inconsistently applied across the organization.
Bad bitsGovernance is usually the gap here - controls exist without policy backing them, so they aren't sustained once the person who set them up moves on.
Why this numberIndividual controls score "Partial" across the board rather than a mix of strong and absent - the org is doing things, just not consistently or on paper.
PriorityMove into Maturity Model Phase 3 (Governance) and Phase 6 (Policy & Documentation) - enough is in place that formalizing it will lock in real gains.
Good bitsThis is usually where MFA is enforced, backups are tested at least occasionally, and a written security policy exists - real, working fundamentals, not just intentions.
Bad bitsResponse readiness is the most common weak point in this band - plans exist on paper (Respond/Recover score fine) but haven't been rehearsed, and detection tends to be reactive rather than proactive.
Why this numberMost functions individually look "fine" (Partial-to-Yes answers throughout), but nothing has been tested end-to-end - the score reflects presence of controls, not proof they'd hold up under a real incident.
PriorityMaturity Model Phase 7 - Response Readiness & Testing - is where this band gets stuck without deliberate rehearsal (tabletop exercises, restore drills).
7 – 8.5
Strong (developing)
Good bitsControls are implemented and tested - this is typically an org that's been through at least one real incident or a serious tabletop exercise.
Bad bitsMonitoring/tuning is the usual gap - alerting exists but hasn't been tuned enough to avoid noise, or audits happen but findings aren't tracked to closure.
Why this numberAlmost every question scores at or near its top option, with only Detect/Optimization-related items pulling the average down slightly.
PriorityMaturity Model Phase 8–9 - Continuous Monitoring and Auditing - is where this band should focus, since the foundational work is already done.
Good bitsFull coverage across all six functions, tested and audited, with a demonstrated feedback loop from past incidents and audits into current priorities.
Bad bitsEven here, the compounding-risk flags still matter - a single overlooked combination (like a new vendor integration nobody reviewed) can create real exposure that a per-function score alone wouldn't catch.
Why this numberConsistently top-tier answers across every function - this band is earned, not assumed, and should be re-verified every assessment cycle rather than taken for granted.
PriorityMaturity Model Phase 10 - Adaptive Iteration. The job here is sustaining the loop, not finding new gaps.