First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/NIST CSF Assessment
Security and Protection

NIST CSF Assessment — Cybersecurity Gap & Compliance Review

IT Partner’s NIST CSF Assessment evaluates an organization’s existing cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans against NIST Cybersecurity Framework guidelines. It is for organizations that have cybersecurity practices and related documentation in place and need identified gaps, areas of weakness, non-compliance findings, actionable recommendations, and a final review meeting.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

The NIST CSF Assessment is a structured review of the organization’s cybersecurity posture against the National Institute of Standards and Technology Cybersecurity Framework. IT Partner assesses current cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans; identifies gaps or areas of weakness and non-compliance; documents the findings; and provides recommendations for improvement. The assessment maps your practices against NIST CSF 2.0 — the framework's first major update, released in February 2024 — across its six functions: Govern, Identify, Protect, Detect, Respond, and Recover, including the Govern function's emphasis on risk-management strategy, roles, and policy.

Success criteria

01The organization's cybersecurity practices are fully assessed against the NIST CSF guidelines.
02Gaps and areas of non-compliance are identified and addressed.
03A detailed report with improvement recommendations is provided.
04The organization's cybersecurity practices align more closely with the NIST CSF guidelines.

What you receive

Initial meeting to understand the organization's cybersecurity practices.
Assessment of the organization's risk management processes, cybersecurity policies, and incident response plans.
Identification of gaps or areas of weakness and non-compliance against the NIST CSF.
Comprehensive report documenting findings and actionable recommendations for improvement.
Final meeting to discuss the report, clarify the findings, and provide guidance on implementing the recommendations.

How the work unfolds

Initial meeting

Scope the project and understand the organization's cybersecurity practices (Day 1).

Assessment

Conduct an in-depth review of the risk management processes, cybersecurity policies, and incident response plans (Day 2-5).

Reporting

Document findings, gaps, and recommendations (Day 6-7).

Final meeting

Discuss the report, explain findings, and guide on next steps (Day 8).

Prerequisites

Existing cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans that can be assessed.
Availability of the organization's team members for discussions.

Who does what

IT Partner

  • Conduct an initial meeting to understand the organization's cybersecurity practices.
  • Assess the organization's risk management processes, cybersecurity policies, and incident response plans.
  • Identify gaps or areas of weakness and non-compliance against the NIST CSF.
  • Document these findings and provide a comprehensive report with actionable recommendations for improvement.
  • Conduct a final meeting to discuss the report, clarify the findings, and provide guidance on implementing the recommendations.

Your team

  • Provide all necessary access to the systems, documentation, and personnel for the assessment.
  • Review the findings and recommendations from IT partner.
  • Implement recommended actions to address identified gaps and enhance compliance.
  • Adjust the cybersecurity practices based on the assessment report.

What's not included

Hands-on remediation of identified gaps, including Microsoft 365, Azure, endpoint, network, identity, or security tool configuration changes.
Creation or full rewrite of cybersecurity policies, standards, procedures, risk registers, business continuity plans, or incident response plans beyond recommendations in the assessment report.
Formal certification, attestation, audit opinion, legal opinion, or guarantee of compliance with NIST CSF or any other regulatory framework.
Penetration testing, vulnerability scanning, red team exercises, phishing simulations, incident response retainer services, or forensic investigation.
Deployment, licensing, or ongoing management of security products such as Microsoft Defender, Microsoft Sentinel, Microsoft Purview, SIEM, EDR, GRC, or ticketing platforms.
Third-party vendor assessments, supplier questionnaires, or detailed review of external service provider controls unless separately scoped.
Ongoing compliance monitoring, recurring reassessments, managed security operations, or post-assessment implementation project management unless purchased as a separate engagement.

Limitations & technical notes

!The assessment is a point-in-time review; your posture against the framework will change as your environment and the threat landscape change.
!No certification or attestation is issued — NIST CSF is a voluntary framework, and the deliverable is an assessment report with recommendations.

Frequently asked questions

What is IT Partner’s NIST CSF Assessment?

IT Partner’s NIST CSF Assessment is a structured review of an organization’s cybersecurity posture against the National Institute of Standards and Technology Cybersecurity Framework. The assessment evaluates existing cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans to identify gaps, weaknesses, and areas of non-compliance.

Which version of the NIST CSF is used?

The assessment uses NIST Cybersecurity Framework 2.0, released in February 2024. CSF 2.0 organizes cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — and broadens the framework's scope beyond critical infrastructure, with added emphasis on governance and supply-chain risk management.

Who is the NIST CSF Assessment intended for?

The NIST CSF Assessment is intended for organizations that already have cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans in place. It is best suited for buyers who need an expert review against NIST CSF guidelines, documented findings, and actionable recommendations for improvement.

What deliverables will we receive from the NIST CSF Assessment?

The primary deliverable is a comprehensive report documenting findings, identified gaps, areas of weakness or non-compliance, and actionable recommendations for improvement. IT Partner also provides an initial discovery meeting and a final meeting to review the report and explain recommended next steps.

How long does the NIST CSF Assessment take?

The listed project duration is 30 days; within that window the working plan runs from the initial meeting (Day 1) through assessment (Days 2–5), reporting (Days 6–7), and the final meeting (Day 8), scheduled around stakeholder availability.

How much does the NIST CSF Assessment cost?

IT Partner’s NIST CSF Assessment is listed at $4,000 per project.

Does the NIST CSF Assessment include remediation work?

The stated scope includes assessment, documentation of findings, actionable recommendations, and guidance during the final meeting. Implementation of recommended actions is listed as the client’s responsibility, so any hands-on remediation or managed implementation should be confirmed separately with IT Partner.

What are the prerequisites for starting the NIST CSF Assessment?

The organization must have existing cybersecurity practices, risk management processes, cybersecurity policies, and incident response plans available for review. The organization’s team members also need to be available for discussions during the assessment.

What are the client’s responsibilities during and after the assessment?

The client is responsible for providing access to systems, documentation, and personnel, reviewing IT Partner’s findings and recommendations, and implementing recommended actions. The client is also responsible for adjusting cybersecurity practices based on the assessment report.

Does the assessment certify that our organization is compliant with NIST CSF?

The service identifies gaps, weaknesses, and areas of non-compliance against NIST CSF guidelines and provides recommendations to improve alignment. The stated scope does not include a formal certification or guarantee of compliance, so buyers should confirm any certification-related requirements separately.

What happens after the final report is delivered?

After the report is delivered, IT Partner holds a final meeting to discuss the findings, clarify the recommendations, and provide guidance on implementation. The client is then responsible for implementing recommended actions and adjusting cybersecurity practices to address the identified gaps.

What is not included in the NIST CSF Assessment?

The stated source scope focuses on assessment, reporting, recommendations, and a final review meeting. Hands-on remediation, full policy rewrites, formal certification or attestation, penetration testing, tool deployment or management, third-party vendor assessments, and ongoing compliance monitoring should be treated as not included unless separately scoped and confirmed with IT Partner.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,000 per project
30 days
Book a meeting