Start with an answer you can act on
A small-business security assessment should help you name what is unprotected, who will fix it, and how you will verify the fix. The NIST Cybersecurity Framework (CSF) 2.0 gives you a common language for that work. NIST's Small Business Quick-Start Guide, SP 1300, is a practical starting point for organizations with modest or no formal security program.
You can take the free Valydex assessment without an account. It asks about your current controls, shows a limited picture when you skip or do not know an answer, and puts actions ahead of product suggestions. It is aligned with selected CSF 2.0 themes; it is not a NIST certification, audit, compliance determination or complete assessment of every CSF outcome.
If you already know your largest gap, use the six-function worksheet below and act on it. A purchased tool is one possible response, not the default result.
What the six NIST functions ask you to manage
| Function | Practical question for a 5–100-person team | Example evidence |
|---|---|---|
| Govern | Who owns cybersecurity decisions, vendors and exceptions? | Named owner, risk register, approved policies, review dates |
| Identify | Which people, devices, accounts and data matter most? | Asset and account lists, critical-service map |
| Protect | Are access, updates and data safeguards working? | MFA policy, patch records, role permissions, staff guidance |
| Detect | Would someone notice a stolen account or failed backup? | Alerts, review owner, escalation record |
| Respond | Does the team know what to do during an incident? | Contact list, decision tree, tabletop notes |
| Recover | Can priority operations and data be restored? | Backup coverage, restore-test result, recovery target |
NIST describes these as connected risk-management outcomes, not a sequence that a company completes once. See the official CSF 2.0 resource page. An excellent Protect answer cannot cancel out an untested recovery process. Likewise, selecting a productivity suite or having more employees does not prove a control works.
How to use the Valydex assessment
The current question definitions contain 12 Quick questions, 27 Standard questions in total, and 69 Comprehensive questions in total. The first two Quick questions establish business context; they do not create security strengths or gaps. Standard and Comprehensive continue from prior answers, so the totals are cumulative. Completion time depends on how much you need to check with an administrator; do not guess an answer to finish faster.
- Choose Quick first. Answer based on current practice, not an intended purchase. If you do not know, use the unknown option and assign someone to verify it.
- Read coverage with the findings. A skipped, unknown or inapplicable answer is not evidence that a control exists. The results distinguish what was assessed from what remains unverified.
- Pick three next actions. For each, record the supporting answer, affected service, owner, effort, and completion proof. Existing Microsoft 365, Google Workspace or other subscription capabilities may be the fastest fix.
- Continue to Standard or Comprehensive if useful. A deeper tier can improve coverage, especially if the Quick result exposes uncertainty. It does not turn self-reported answers into an audit.
- Export and review locally. Scoring and the PDF report run in your browser. Optional AI analysis sends assessment context to an external service only after a separate consent step. If you decline it, the core results and local report still work.
Do not put passwords, secrets or customer records in free-text input. Read the privacy policy before using the optional AI feature. The assessment is a prioritization aid; regulated or contract-specific requirements need a qualified review of their exact obligations.
Turn findings into a 30/60/90-day plan
Days 1–30: establish ownership and close obvious access gaps. List critical systems, administrators and external support contacts. Require MFA on business email and privileged accounts, remove access for departed staff, verify that automatic updates are working, and identify which critical data has a recoverable copy. Record exceptions and unknown answers.
Days 31–60: test the controls that claim to work. Review roles and sharing permissions, check patch and alert reports, run a restore of representative business data, and walk through who would handle a suspicious login or ransomware alert. Fix one broken workflow at a time. Keep screenshots, logs or meeting notes as evidence.
Days 61–90: refine and repeat. Check open gaps against your business impact, assign remaining owners, and set a quarterly review for account access, vendors, recovery and incident contacts. Re-run the same assessment after real changes; compare the answered controls and coverage, not just the headline score.
These are sequencing examples, not a universal budget or guarantee that every team can complete each item within the stated period. A business with one critical legacy server may need to prioritize differently from a cloud-only consultancy.
A one-page control worksheet
Copy this structure into your normal project tracker for each material gap:
| Field | What to write |
|---|---|
| Observation | The answer or evidence that showed a missing or uncertain control |
| Business impact | The service, people or data affected if it fails |
| Current capability | Included subscription feature or existing process to try first |
| Action and owner | One implementable change and the person who can complete it |
| Effort and date | Estimated work, dependencies and target review date |
| Completion test | A sign-in, restore, alert, offboarding or other repeatable check |
| Remaining uncertainty | The question that still needs vendor or specialist confirmation |
For example, “we think backups run” is an unknown until someone identifies the covered system, checks the last successful job and restores a sample file. If the service is missing entirely, use the small-business backup guide to compare recovery needs before buying storage.
Where the framework stops
The CSF helps organize outcomes and communicate priorities. It does not itself certify that your organization complies with HIPAA, SOC 2, PCI DSS or an insurance policy. A self-assessment can miss a control that was misunderstood or never tested. If the result will support a contract, audit or regulated workload, ask the responsible specialist to map evidence to the exact requirement.
This guide is documentation-based. We have not audited your environment or observed actual control operation. Sources checked September 24, 2026: NIST CSF 2.0, NIST Small Business Quick-Start Guide, and NIST's small-business resource page. The assessment and worksheet are free; if you later follow a product link elsewhere on Valydex, review our affiliate disclosure and research methodology.