Free SMB Assessment · NIST CSF 2.0 + CIS Controls v8.1

Cybersecurity Risk AssessmentScore Your SMB Across Six NIST Functions in About 3 Minutes

Ten yes / partial / no questions, mapped to NIST CSF 2.0 and CIS Controls v8.1 IG1, with a five-must-have cyber-insurance bar and the top three prioritized gaps for businesses with 10 to 500 users. Free, no account, instant on-screen result. Delivered remotely to businesses across the United States.

10 questions~3 minutesNo signupNIST CSF 2.0CIS Controls v8.1 IG1
Updated May 2026
Cybersecurity Risk Assessment0 of 10 answered
Loading the assessment…
Quick Answer

What is a cybersecurity risk assessment?

A cybersecurity risk assessment is a structured evaluation of how well an organization can prevent, detect, and recover from cyber threats. It scores existing security controls against a recognized framework (most commonly NIST Cybersecurity Framework 2.0, which spans six Functions: Govern, Identify, Protect, Detect, Respond, and Recover) and identifies the highest-priority gaps. For small and mid-sized businesses with 10 to 500 users, a useful assessment also maps results to CIS Controls v8.1 Implementation Group 1 (the 56 essential safeguards every business should have in place) and to current cyber-insurance underwriting requirements. The On-Site Technology Cybersecurity Risk Assessment is a 10-question tool that produces an instant on-screen score, a five-must-have cyber-insurance bar, and the top three prioritized gaps. It is delivered remotely to businesses across the United States.

47%
SMB ransomware via
compromised credentials
88%
Cyber insurers requiring
EDR or MDR for renewal
78%
Breaches involving
phishing or social eng.
6 / 22 / 106
NIST CSF 2.0 Functions /
Categories / Subcategories
How the Assessment Is Scored

Three Frameworks, One Score

Each of the 10 questions maps to a NIST CSF 2.0 Subcategory, a CIS Controls v8.1 IG1 Safeguard, and (where applicable) a 2026 cyber-insurance underwriting flag. One concise tool, three industry frameworks behind it.

FrameworkWhat It CoversWhere It Scores in This Tool
NIST CSF 2.0 (2024)6 Functions, 22 Categories, 106 SubcategoriesAll 10 questions mapped at the Subcategory level
CIS Controls v8.1 IG156 essential SMB safeguards8 of the 10 questions map directly
CMMC Level 117 basic safeguarding practices for FCISubset of CIS IG1; covered (deeper coverage in our CMMC Readiness Checker)
Cyber-insurance baseline (2026)MFA, EDR, immutable backup, IR plan, awareness trainingQ1 to Q5, surfaced as the must-haves bar at the end
2026 threat realityGenerative AI use, phishing resilience, credential theftReflected in Q1, Q5, and Q10
What Good Looks Like

The Six NIST CSF 2.0 Functions

NIST CSF 2.0 organizes cybersecurity outcomes into six Functions. Each one defines a discrete operating capability, and a strong SMB program shows visible practice in all six. The cards below describe what good looks like at the SMB scale.

Govern

A written cybersecurity policy with a named accountable owner. Board or owner reviews posture at least annually. Vendors with data access are inventoried and reviewed.

Identify

Current inventory of hardware, software, data, and users. Data classified by sensitivity. Operational technology and IoT footprint understood. Third-party risk assessed before access is granted.

Protect

MFA enforced on email, VPN/RDP, and admin accounts. Endpoints encrypted. Critical patches applied within 14 days. Privileged accounts separated from daily use. Awareness training plus phishing simulations.

Detect

EDR or MDR running on every endpoint, including servers. Centralized log retention of at least 90 days. A defined alert-triage and escalation path. Anomalous activity is reviewed on a documented cadence.

Respond

Written incident response plan, tested via tabletop or live exercise within the last 12 months. IR roles, contacts, and escalation paths current. Third-party IR retainer available. Familiarity with breach-notification deadlines.

Recover

Immutable or offline backups with restore tested in the last 6 months. Defined RTO and RPO targets per critical system. Documented post-incident lessons-learned process that feeds plan and control updates.

2026 Threat Reality

What Is Actually Breaking SMBs Right Now

A useful assessment scores against current threat reality, not a checkbox list from 2018. The four data points below shape several of the questions in this tool and several of the weights in the score.

47%

Compromised Credentials

Stolen or reused credentials drive about 47% of SMB ransomware initial access (Coalition Q3 2025 claims data). MFA on remote access and admin accounts is the highest-leverage control.

#1

Phishing Resurgence

Phishing reemerged as the #1 initial access vector in Q1 2026 (Cisco Talos IR Trends). Annual training plus a simulation cycle is the practical defense.

48%

VPN / RDP Exposure

VPN and RDP services were the second-largest pathway, behind phishing, accounting for roughly 48% of ransomware initial access in Q3 2025 (Halcyon). MFA on remote access closes most of this.

New

Generative AI Risk

Carrier questionnaires now ask about AI use policy, data leakage into public LLMs, and prompt-injection exposure. A short written policy with approved tools satisfies the bar for most SMBs.

Cyber Insurance Baseline

What Carriers Expected for Renewal in 2026

Cyber insurance underwriting standards moved meaningfully in 2024 and 2025, then settled into the baseline below across most U.S. carriers. The five must-haves bar in the assessment reflects this baseline. It is informational and not a binding underwriting decision.

RequirementWhat Most Carriers Expected
MFAEnforced on email, VPN/RDP, and all admin accounts. Phishing-resistant factors (FIDO2 / passkeys) for admin where feasible.
EDR or MDRReal-time detection on every endpoint, not just AV. Required by roughly 88% of carriers in 2026.
BackupImmutable or offline copies. Documented restore test in the last 6 months. Carriers ask for the restore log, not just the backup product.
Incident ResponseWritten plan, tabletop exercise within the last 12 months, and ideally a third-party IR retainer.
Awareness TrainingAnnual training for all employees, plus a phishing simulation cycle (typically quarterly).
Patch ManagementCritical patches inside 14 days, with a documented exception process for systems that cannot be patched on schedule.
Who Should Run This Assessment

Three Common Reasons SMBs Run It

Owner / CFO

Pre-Renewal Confidence Check

Cyber insurance application is coming up. Want a fast read on which of the must-haves are clear and which need attention before the carrier asks.

IT Director

Direction-Setting

Need a defensible starting point for the next 90 days of security work. Want a NIST CSF 2.0 frame the leadership team will recognize.

MSP Customer

Independent Second Opinion

Already pay an MSP. Want an independent read on whether the program covers what 2026 carriers and frameworks actually expect.

Frequently Asked Questions

Cybersecurity Risk Assessment: FAQs

The questions executives, IT directors, and compliance officers ask us most often about this assessment.

What is a cybersecurity risk assessment?

A cybersecurity risk assessment is a structured evaluation of how well an organization can prevent, detect, and recover from cyber threats. It scores existing security controls against a recognized framework (NIST CSF 2.0 is the most common in 2026) and identifies the highest-priority gaps. For SMBs with 10 to 500 users, a useful assessment also maps results to CIS Controls v8.1 IG1 and to current cyber-insurance underwriting requirements. This tool is a 10-question version of that assessment.

How long does this assessment take?

About 3 minutes for the typical SMB. The 10 questions are yes / partial / no, so most users complete the flow without research. If you want to pull data first (last patch report, last phishing simulation results, last restore test date) it might take 5 to 10 minutes.

Do I need to enter my email to get a score?

No. The on-screen score, the cyber-insurance must-haves bar, and the top three prioritized gaps are visible immediately when you finish Q10. Email is only required if you want the optional 2-page PDF gap report mailed to you.

What framework does the assessment use?

NIST Cybersecurity Framework 2.0 as the scoring backbone, mapped against CIS Controls v8.1 IG1 (the 56 essential safeguards every SMB should have in place) and the cyber-insurance underwriting baseline most U.S. carriers used in 2026. Each question maps to a NIST Subcategory and, in most cases, a specific CIS Safeguard.

What is the difference between NIST CSF 2.0 and CIS Controls v8.1?

NIST CSF 2.0 is outcome-oriented: it defines what a mature cybersecurity program looks like across six Functions. CIS Controls v8.1 is implementation-oriented: it defines how to actually do it through specific safeguards (passwords, MFA, EDR, and so on). Most SMBs benefit from using both, with NIST as the strategic map and CIS IG1 as the tactical floor.

Why is multi-factor authentication weighted so heavily?

Compromised credentials drive about 47% of SMB ransomware initial access (Coalition Q3 2025 claims data) and most cyber insurers in 2026 require MFA enforced on email, VPN/RDP, and admin accounts as a renewal baseline. MFA is the single highest-leverage control for the SMB threat profile, which is why Q1 carries an insurance flag and feeds the must-haves bar.

Will this assessment satisfy my cyber insurance application?

No. An underwriting questionnaire from your specific carrier is the binding document. The five must-haves bar in this tool reflects what major carriers required for renewal in 2026 and is informational only. It is a useful pre-check before you submit, not a substitute for the carrier’s own form.

Is this assessment SOC 2, HIPAA, or PCI aware?

Yes, in the sense that the foundational controls (MFA, encryption, training, IR plan, logging) are common across all three regimes. It is not a substitute for a SOC 2 readiness assessment, a HIPAA Security Rule audit, or a PCI Report on Compliance. For Defense Industrial Base SMBs, the dedicated CMMC Readiness Checker is the better starting point.

How often should an SMB run a cybersecurity risk assessment?

Most security teams run a structured assessment annually, with mini-reviews after any major change (new system, acquisition, key staff change, near-miss incident). Some compliance frameworks (HIPAA, NY DFS Part 500, CMMC) effectively make annual cadence the floor. This tool is fast enough to run more often than that as a directional check.

How accurate is a self-administered assessment vs a third-party audit?

Self-assessments are well suited to direction-setting and prioritization. They can miss what you do not know you do not know. A third-party audit, which OST offers as part of Managed Cybersecurity Services, verifies controls with technical testing and adds an outside perspective. Both are useful: self-assessment first, third-party as confidence rises.

What does the PDF report contain?

A 2-page report. Page one carries the score, the must-haves bar, and the top five gaps with one-paragraph fix guidance each. Page two maps each gap to a recommended OST service and lays out a 30/60/90-day remediation roadmap. It is designed to function as a board-meeting handout, not a marketing brochure.

What does On-Site Technology do with my data?

Your answers are processed in your browser and saved to your device’s local storage so you can return to them. If you request the PDF, your address plus answer summary is stored in our contact-form record system the same way any inquiry through the site is. We do not sell data, do not share it for marketing, and do not enroll you in unrelated mailings. Send us a message through the form on the page or call (973) 777-7227 with any questions.

Talk to a Cybersecurity Specialist

Score in Hand? Let’s Close the Gaps.

Share your environment, regulators, and timeline. We will reply with a scoped proposal targeted at the gaps the assessment surfaced. We typically respond within 4 business hours.

    Your Name (required)

    Your Email (required)

    Subject

    Your Message

    Your info stays with us. No resale.
    Run It, Then Talk to Us

    Find Out Where Your Program Stands in About 3 Minutes

    Ten questions, mapped to NIST CSF 2.0 and CIS Controls v8.1 IG1. Score, must-haves bar, top three gaps. Optional 2-page PDF. Free, no account, takes minutes.

    10
    Questions
    ~3 min
    To Complete
    100%
    Remote, Nationwide
    $0
    Free To Use