Skip to main content

Find the cyber gaps worth fixing first.

Choose Cyber Essentials preparation or a broader NIST CSF 2.0 posture review. Answer focused questions and receive prioritised, plain-English actions without uploading raw evidence or entering your organisation’s name.

Start Free Cyber Essentials Report

Free to start · No RightCyber account

Compare Assessments

Work email required for delivery

Designed for safer self-assessment
  • S/01No organisation or person names requested
  • S/02No evidence-file uploads
  • S/03Deterministic scoring before AI-generated wording
  • S/04Readiness support, never certification

Choose a framework

Start with the outcome you need

These are two distinct reviews. Cyber Essentials focuses on certification preparation; NIST CSF 2.0 provides a broader posture view.

Certification preparationAvailable now

Cyber Essentials readiness check

Prepare for Cyber Essentials with a prioritised action plan aligned to the current requirements.

Framework basis
NCSC Cyber Essentials Requirements for IT Infrastructure v3.3 · effective 27 April 2026
Price
Free report · Advanced report £49
Broader posture reviewAvailable now

NIST CSF 2.0 posture review

Build a practical view across Govern, Identify, Protect, Detect, Respond and Recover.

Framework basis
NIST Cybersecurity Framework 2.0 · NIST CSWP 29
Price
Free report · Advanced report £49

Free and advanced reports

Know what each report level provides

Start free for a high-level view. Choose the £49 advanced report when you need a deeper, evidence-focused improvement plan.

Free report

Free
  • High-level readiness or posture indicator
  • Summary of the priority gaps identified
  • Practical action starting points
  • Secure report link available for 30 days

Advanced report

£49
  • Everything in the free report
  • Framework-specific evidence-focused follow-up checks
  • Deeper evidence examples and area-level actions
  • A clearer 30-day and 90-day improvement plan
  • Secure report link available for 90 days

How it works

From focused questions to practical actions

  1. 01

    Choose a framework

    Use Cyber Essentials for certification preparation or NIST CSF 2.0 for a broader posture review.

  2. 02

    Answer focused questions

    Describe your current practices without uploading evidence files or entering your organisation's name.

  3. 03

    Calculate the indicator

    Deterministic scoring evaluates the submitted answers before any report wording is generated.

  4. 04

    Generate the report

    OpenAI turns the structured findings into plain-English explanations and practical actions.

  5. 05

    Open the secure link

    The report link is sent to the work email supplied for delivery.

Privacy and AI

Understand what happens to your answers

The service is data-minimised, not anonymous. It collects a work email, non-identifying business context, answers, optional notes and the generated report so it can provide the requested service.

OpenAI receives the supplied context, answers, optional notes, deterministic scores and report instructions to generate the wording. Your delivery email is not sent to OpenAI.

Not requested

Organisation or person names, evidence files, passwords, keys, raw logs or configuration exports.

Required for delivery

A work email is used to send the secure report link and service messages. Starting a report does not subscribe you to marketing emails.

Keep optional notes safe

Remove identifying or sensitive technical detail before you submit free-text context or notes.

Scope and limitations

Use the result as a planning aid

Cyber Essentials boundary

The review uses RightCyber-authored questions aligned to the current requirements. It is not the official questionnaire, an assessment, a certification decision or a Cyber Essentials Plus technical audit.

NIST CSF 2.0 boundary

The review samples the six CSF Functions. It is not a complete Organizational Profile, CSF Tier, maturity assessment, compliance review, assurance exercise, certification or independent validation.

After the report

Cyber Essentials Workspace — In-house

If your goal is Cyber Essentials, organise one organisation’s questions, evidence context, gaps, actions and renewal record.

RightCyber Documents

Choose a focused policy, register, exercise or evidence pack for a specific operational need identified in your follow-on work.

Common questions

Before you begin

Which assessment should I choose?

Choose Cyber Essentials when you are preparing for that certification. Choose NIST CSF 2.0 when you want a broader posture review across Govern, Identify, Protect, Detect, Respond and Recover.

Do I need a RightCyber account?

No RightCyber account is required to start a free report. A work email is required so the secure report link can be delivered.

Do I need to upload evidence or provide an organisation name?

No. The assessment does not request evidence-file uploads or your organisation's name. Do not put names, credentials, keys, network identifiers, raw logs, configuration exports, personal data or exploitable incident details into optional notes.

How is the result calculated?

A deterministic scoring engine calculates a self-reported planning indicator from the submitted answers before AI writes anything. It is not an official marking method, pass probability, compliance percentage, maturity rating or risk measurement.

Where is AI used?

OpenAI processes the supplied business context, assessment answers, optional notes, deterministic scores and report instructions to generate the report wording. The delivery email is not sent to OpenAI.

Is this an official assessment or certification decision?

No. RightCyber Analysis is an automated self-assessment aid. It does not perform an audit, certification or attestation, and it cannot guarantee an external assessment outcome.

What is included in the £49 advanced report?

The advanced report adds framework-specific evidence-focused follow-up checks, deeper evidence examples, area-level actions and a clearer 30-day and 90-day improvement plan.

How long is the report link available?

Free report links remain available for 30 days. Advanced report links remain available for 90 days.

A practical starting point

Start without uploading sensitive evidence.

Answer focused questions and receive prioritised gaps and practical actions. No RightCyber account is required; a work email is used to deliver the report.