ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
AlvorAdvisory
Advisory/Assess/Maturity Assessment

Assess · The flagship diagnostic

Security maturity assessment against NIST CSF 2.0.

A fixed-fee diagnostic of your whole security program: scored on a CMMI-aligned 0 to 5 scale across all six CSF functions, mapped to ISO 27001 and SOC 2, and resolved into one maturity scorecard and one risk-ranked gap register. The diagnosis and the roadmap are the same artefact.

Book a consultationAll engagements

Scope and price agreed in writing before any work. No obligation.

Maturity scorecard · CSF 2.02.1 → 3.4 / 5Govern2.0 → 4.0Identify3.0 → 4.0Protect2.0 → 4.0Detect1.0 → 3.0Respond2.0 → 3.0Recover1.0 → 3.0CurrentAgreed targetOne scorecard · one gap register
NIST CSF 2.0 · C2M2Fixed scope, fixed feeTypically 3–4 weeks

Three moments this answers.

A first, complete read

Security has grown organically and nobody can say, in one page, where the program stands. The scorecard gives you that page, on a recognised scale rather than an opinion.

The board asked where we stand

Directors, investors, or an acquirer want a defensible answer, not reassurance. A scored profile with an evidence basis is an answer you can table and stand behind.

Before funding a program

You are about to spend real money on security and want the baseline first, so the spend lands on the highest-exposure gaps and the improvement is measurable afterwards.

What you are commissioning

The engagement, as a term sheet.

The flagship engagement of the Assess track backs this page. Scope and the fixed fee are agreed in writing before any work begins.

Assess track·Fixed-fee·Typically 3–4 weeks

Security Program Assessment

Know exactly where you stand, and what to fix first.

Best for a first, complete read of where the program stands.

Includes

  • Current-state review of the whole program against the framework you answer to
  • Maturity scoring on a recognised whole-program model (NIST CSF 2.0 or C2M2)
  • Risk analysis across the enterprise, your cloud, and your vendors
  • A prioritised, risk-ranked gap register with a costed roadmap

Deliverables

Maturity scorecardPrioritised gap registerRisk-ranked exposure pictureCosted remediation roadmap

The standardised assessments are fixed-fee. Every other engagement is scoped and priced in writing before you commit, from a one-off review to a managed service.

The method

Why this read is worth having.

01

Scored, not opined

Every category is scored against a published rubric, and scores reflect evidence sighted, not practices described: interviews, documents, and technical sampling of the estate. Where the story and the evidence differ, the evidence prevails.

02

One artefact, two jobs

The maturity scorecard and the gap register resolve into a single deliverable: each gap carries a risk rank, an owner, a recommendation, and a costed remediation, so accepting the diagnosis is the same act as adopting the plan.

03

Senior eyes only

Led by a principal security architect, reviewed by a function subject-matter specialist, and quality-reviewed by the practice lead before issue. The sample report below shows exactly who signs what.

04

Comparable over time

The same rubric is applied every time, so a repeat assessment measures movement rather than re-litigating the baseline. Many teams re-run it annually; under Operate, the tracking becomes continuous.

Proof of method

Read the deliverable before you buy it.

Eight pages of the standard report, redacted: the executive summary, the function profile, per-category summaries, a full control-level assessment, and the gap register with recommendations.

Download the sample report
  • 1The scoring rubric and evidence basis, stated in the report itself
  • 2A control assessed end to end: observations, score, recommendation
  • 3The gap register rows your roadmap is built from

Questions

What teams ask about this engagement.

What does the assessment cost?

It is fixed-fee, sized to your organisation in a short scoping conversation and agreed in writing before any work begins. The fee buys a defined scope: all six NIST CSF 2.0 functions, the interviews and evidence review behind them, and the full report.

What access do you need from us?

Typically a set of interviews across engineering, operations, and leadership, your existing policies and documents, and read-only technical sampling of agreed control families. The engagement is designed to take senior people's hours in minutes, not days.

We answer to ISO 27001 and SOC 2, not NIST. Is this still right?

Yes. NIST CSF 2.0 is the measurement frame because it covers the whole program including governance; every finding is also mapped to ISO/IEC 27001:2022 Annex A and the SOC 2 Trust Services Criteria, so the same work serves your certification path.

What happens after the assessment?

The gap register doubles as the scoped proposal for what comes next, and the next move is entirely yours: remediate with your own team, hand the roadmap to a partner, or continue with us into Architect and Build. The assessment stands on its own and commits you to nothing.

How is this different from an audit?

An audit judges you against a standard's pass line; this measures the whole program's maturity and tells you what to fix first and what it will cost. It is the artefact you want before an audit, and we remain deliberately separate from the body that eventually certifies you.

AlvorAdvisory

Scope it before you commit to it.

One conversation, then the scope and the price in writing. Your enquiry arrives already marked for maturity assessment.

Book a consultationSee every engagement
ALVOR

Security architecture, management, and compliance - connected into one source of truth.

Security, Simplified.

Platform

  • Overview
  • Assets
  • Dependency Mapping
  • Business Continuity
  • Data Governance
  • Secure by Design
  • Risk
  • Compliance
  • Policy
  • Program
  • TPRM

Solutions

  • Startups
  • Mid-Market
  • Enterprise

Company

  • About
  • Advisory
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor, Inc. All rights reserved.

LinkedIn