Cyber Maturity Audit

Cyber Maturity Audit

NIST CSF 2.0, measured.

How mature is your cyber security, really? This app turns the NIST Cybersecurity Framework 2.0 into a structured self-assessment: 6 functions, 22 categories, 106 subcategories — each one rated 0 to 4, each one with guidance on how to actually implement it.

iPhone · iPad · Mac · iOS 17 or later, macOS 14 or later · One purchase covers all three

106subcategories, all with guidance
6functions: Govern to Recover
5languages incl. Romansh
0network requests

The framework says what. The app says how.

Everything you need to get from "we should look at NIST CSF" to a documented, defensible maturity assessment.

The complete catalog

All 106 subcategories of NIST CSF 2.0 across Govern, Identify, Protect, Detect, Respond and Recover — walked through in a guided flow or navigated freely.

Practical guidance

Per subcategory: one sentence for the management, three to five concrete steps, typical pitfalls, audit evidence, effort, ownership and tool suggestions — open source first.

Maturity 0–4, per level

Scores per category, per function and overall — averaged transparently and compared against your own target value. A radar chart shows strengths and gaps at a glance.

A report you can hand over

Management summary, category overview with gap analysis, maturity profile with radar charts, complete detail pages. Auditors add their firm, logo and accent colour — no rework. CSV export included.

Multiple assessments

Assess several companies, or the same one year over year. Each assessment carries its own company details; comparisons show exactly what changed.

Fully offline

No account, no cloud, no analytics, no network requests at all. Face ID / Touch ID lock optional. Your assessment stays on your device — which is rather the point.

ID.AM-01 · What it looks like

"Maintain a hardware inventory." Fine — how?

The framework tells you what is expected. Every subcategory in the app also carries this:

For the management Without a complete list of your devices you will not know what is affected in an incident — and you keep paying for hardware nobody needs any more.
01

Record once everything that processes or stores data: servers, PCs, notebooks, mobile devices, network equipment, printers, and controllers — including devices in home offices and in production.

02

For each device, record: designation, location, responsible person, purpose, and criticality for the business.

03

Define who updates the inventory on procurement, relocation, and decommissioning — anchor this in the procurement process, not in IT alone.

04

Have the network scanned automatically for devices on a regular basis and reconcile the result with the inventory; unknown devices are investigated.

05

Review the inventory completely at least once a year and document the review with a date.

Switch language, keep your work.

The framework's original English plus four translations — changeable at any time, not tied to the system language. Translations are marked as unofficial in the app.

EnglishOriginal
Deutschunofficial
Françaisunofficial
Italianounofficial
Rumantschunofficial

Try it on 24 subcategories. Then decide.

The free version is a real working version, not a preview: the first four subcategories of every function, fully readable, ratable and with the complete guidance.

Free

CHF 0

24 of 106 subcategories, one assessment.

  • Official text and guidance for 24 subcategories
  • Maturity scoring and radar
  • All five languages

Pro · monthly or once

4.99

Per month — or 199.00 once, without a subscription.

  • Same scope as yearly
  • Cancel any time
  • One purchase covers iPhone, iPad and Mac
Download on the App Store Download on the Mac App Store

Free to download. Prices in US dollars as listed on the App Store; you pay in your own currency. Subscriptions renew until cancelled in the App Store account settings.

An independent app. treeinspired GmbH is not affiliated with or endorsed by the U.S. National Institute of Standards and Technology (NIST). The Cybersecurity Framework 2.0 itself is publicly available free of charge at nist.gov/cyberframework.

What you are paying for is the implementation guidance, the assessment and the report — not the framework, which stays free.

Translations of the original English framework text (German, French, Italian, Romansh) are unofficial and marked as such throughout the app.

Not legal advice. The guidance describes common practice; it does not replace legal advice, an audit or a certification.

Support

Questions, bug reports, wrong wording?

Write to us — in German, French, Italian or English. We answer within two working days.

info@treeinspired.com

treeinspired GmbH · Switzerland · Imprint · Privacy · Terms