Running a NIST CSF gap assessment
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · NIST CSF
A CSF gap assessment is just the current profile meeting the target profile — and writing down everything in between.
What it is
A NIST CSF gap assessment walks the framework's functions, categories, and subcategories and asks, for each relevant one, where you are versus where you want to be. It is the practical realisation of comparing your current and target profiles — the exercise that produces the work list.
How to run it
Scope to the outcomes relevant to your risk, score each (present, partial, absent, or on a maturity scale), and note where the evidence would come from. Be honest about "partial" — a control that exists but runs inconsistently is a gap. The assessment is only useful if it is candid.
Prioritise by risk
Not all gaps are equal. Rank them by the risk they leave open, not by how cheap they are to close — closing easy low-risk gaps while ignoring a hard high-risk one is motion without progress. The risk lens is what makes the roadmap defensible.
Turn it into a roadmap
The deliverable is a prioritised plan: which outcomes to improve, in what order, with owners and dates. SentinelPanda runs the assessment against the framework and produces the gap-driven roadmap, then tracks progress.