NIST CSF 2.0 Continuous Monitoring

A posture snapshot ages out the day it ships.
Continuous monitoring stays current.

A point-in-time NIST CSF 2.0 assessment gives you a score, then quietly drifts as controls change, infrastructure shifts, and staff turnover erodes adherence. Continuous monitoring re-baselines on your cadence — 3, 6, or 12 months — and feeds a live dashboard that shows Current State plus Change Over Time. The output isn't a thicker report. It's posture you can stake decisions on.

Subscription
Continuous Monitoring Current State + Change Over Time 3 / 6 / 12 Month Cadence Self-Service or Advisor-Led PDF Export
How it works

Baseline. Refresh. Dashboard. Repeat.

Continuous monitoring is structured so each cycle is short, the dashboard stays live between cycles, and the burden on your team stays predictable. You start with a fresh NIST CSF 2.0 baseline, then your cadence cycles keep the score honest.

01
Phase 1 · Days 1–7
Initial Baseline Assessment

Your first cycle establishes the baseline — the NIST CSF 2.0 instrument runs across all six functions (Govern, Identify, Protect, Detect, Respond, Recover) with role-specific webforms. Self-Service clients complete the refresh themselves; Advisor-Led clients schedule an intake interview or email exchange with the founder. Output: a Current State dashboard and a baseline PDF you can hand to a board, a prime contractor, or an underwriter.

02
Phase 2 · Cadence cycles
Cadence Updates (3 / 6 / 12 months)

At each cadence boundary the same instrument runs again — refreshed webforms capture what changed since the last cycle. The dashboard adds a new row of function scores, the Change Over Time view extends one more step, and the cycle PDF is filed in your history. No quarterly scramble: most Self-Service clients spend ~30 minutes per cycle; Advisor-Led clients spend ~5 minutes reviewing founder-produced updates.

03
Phase 3 · Always-on
Live Dashboard Access

Between cycles the dashboard is live. Current State shows your latest function scores and the controls driving each score; Change Over Time shows the trajectory per function across every cycle you've run. Both views export to PDF on demand — for board updates, vendor security questionnaires, cyber insurance renewals, or evidence packs during a procurement cycle.

04
Phase 4 · Every cycle
Quarterly PDF Exports

Each cycle produces a packaged PDF export that captures Current State + Change Over Time at that moment in time — a dated snapshot suitable for auditors, underwriters, and procurement teams. The full export history is retained on your dashboard so you can show the trajectory to anyone who needs to see it, no assembly required.

Cadence options

Pick the cadence that matches your change rate.

Faster-moving operations need shorter cycles to catch drift early. Stable environments can stretch to annual. Both tier options support all three cadences — switching cycle length is a single check at the next cycle boundary.

Quarterly
3-Month Cadence
4 cycles per year
Best-fit for fast-moving SaaS, scale-ups mid-fundraise, or any environment with monthly infra or staffing change. Catches regressions before they accumulate, keeps the Change Over Time view densely sampled for board reporting.
Semi-Annual
6-Month Cadence
2 cycles per year
Best-fit for regulated SMBs with a stable technical footprint, established security program, and quarterly internal control reviews already in place. Aligns naturally with mid-year board cycles and annual insurance renewals.
Annual
12-Month Cadence
1 cycle per year
Best-fit for mission-driven non-profits and small organizations with low infrastructure change between fiscal years. Tethers the dashboard to a single annual review while still capturing drift relative to the baseline.
Two tiers

Same dashboards. Different data-collection model.

Both tiers deliver identical Current State + Change Over Time dashboards and PDF export. The difference is who drives data collection each cycle.

Feature Self-Service Advisor-Led
Webform data entry Client completes the refresh webforms each cycle Founder gathers data via interview or email and inputs on client's behalf
Current State dashboard
Change Over Time dashboard
One-click PDF export
Interview / email data gathering
Founder-led synthesis
Time investment per cycle ~30 minutes (webform refresh) ~5 minutes (review founder output)
Price [TBD]
Pricing being finalized
[TBD]
Pricing being finalized
What's in the dashboard

Two views, one PDF export button, every cycle.

The dashboard is the deliverable. Both tiers get the same set of views plus on-demand PDF export. Every cycle refreshes the views and adds a timestamped PDF to your export history.

Current State view

Live snapshot of your NIST CSF 2.0 function scores — Govern, Identify, Protect, Detect, Respond, Recover — with the controls currently driving each score. Useful for vendor questionnaires, board updates, and "where do we stand right now" conversations.

Change Over Time view

Trend line per NIST function across every cycle you've recorded. Shows what improved, what regressed, and where the next quarter's effort should land. The view that makes a continuous-monitoring subscription worth more than an annual assessment.

One-click PDF export

Every dashboard view exports to a dated, branded PDF on demand. Cyber-insurance renewals, prime-contractor vendor security reviews, and audit evidence packs go from "let me run a report" to a single button click.

Cadence reminder

Email notification when your next cycle window opens. Self-Service clients get the reminder plus the link to the refresh webform; Advisor-Led clients get the reminder plus scheduling for the founder intake interview. No calendar drift.

Pricing

Two subscription tiers. Pricing is being finalized — early-access clients book a discovery call.

Pricing research is in progress as of this page's launch. Subscribe buttons below take you to a discovery call where we share current pricing and confirm fit, cadence, and tier. Live pricing will appear here once final.

Self-Service
Your team owns the cycle. The dashboard and PDF exports are yours.
[TBD] Pricing being finalized · book a discovery call for early-access pricing
  • Client completes the refresh webforms each cycle
  • Current State + Change Over Time dashboards
  • One-click PDF export
  • 3 / 6 / 12 month cadence — switch at any boundary
  • Cadence reminder emails
Subscribe — Self-Service
Pricing is currently listed as [TBD] because we are finalizing the structure with current and prospective clients. Subscribe buttons route to a discovery call so we can confirm fit and share current pricing before launch. Both tiers are independent of cadence length — switching cadence is not a price change.

Pick a cadence. Pick a tier.
Start with a call.

Continuous monitoring is best scoped with a 30-minute conversation — we'll confirm the right cadence, the right tier, and answer implementation questions for your stack. Early-access clients lock in launch pricing.

Frequently asked

Common continuous monitoring questions.

What is NIST CSF 2.0 continuous monitoring? +
NIST CSF 2.0 continuous monitoring is the practice of repeatedly assessing your security posture against the six NIST CSF functions (Govern, Identify, Protect, Detect, Respond, Recover) on a scheduled cadence — instead of treating the assessment as a one-time event. Each cycle refreshes your function scores, surfaces drift, and feeds a live dashboard that tracks Current State and Change Over Time. The result is a posture record that holds up to underwriters, partners, regulators, and procurement teams rather than a snapshot that ages out the day it is delivered.
How is continuous monitoring different from an annual assessment? +
An annual assessment gives you a point-in-time posture score, then quietly drifts as controls change, infrastructure evolves, and staff turnover erodes policy adherence. Continuous monitoring re-baselines on a 3, 6, or 12-month cadence, so each cycle shows you what improved, what regressed, and where the next quarter's effort should land. The output isn't a thicker report — it's a live dashboard plus PDF exports that you can hand to cyber insurance underwriters, prime contractors asking for vendor security posture, or your board without re-running the assessment.
Who should pick Self-Service vs Advisor-Led? +
Self-Service fits teams with a security lead, IT generalist, or operations owner who has 30 minutes per cycle to walk through the webform refresh and is comfortable owning the answers. Advisor-Led fits executives and lean teams who would rather have the founder run a short interview or email exchange each cycle, then review the resulting dashboard. Both tiers deliver the same Current State + Change Over Time dashboards and PDF exports — the difference is who gathers and inputs the cycle data.
When is the first deliverable ready? +
Your first cycle starts with a baseline assessment using the same NIST CSF 2.0 instrument as the free readiness assessment on this site, then loads into the Current State dashboard. For Self-Service clients the baseline typically completes in one cycle within a week of kickoff; for Advisor-Led clients the founder schedules an intake interview and the baseline typically lands within 10 business days. After that, your next cadence cycle opens automatically per your chosen cadence (3, 6, or 12 months).
Can we switch tiers later? +
Yes. Most clients start on one tier and switch as staffing changes. Tier changes take effect at the start of the next cadence cycle so the dashboard history and Change Over Time view stay consistent — your prior cycles aren't reset. Cadence changes (3 vs 6 vs 12 month) are similarly handled at the next cycle boundary.