NIST CSF 2.0 × CIS Implementation Groups

Security posture, made visible.

A security-posture platform for MSPs. Build your posture template on the framework insurers and auditors already recognize — then run the client conversation live, with the score moving as gaps get closed.

Built for MSPs and the clients they protect. Currently onboarding a small first group.

Live — try itthis is the real scoring model
Posture score
40/ 100
Insurability
2 of 5 must-haves

Posture score 40 of 100. 2 of 5 insurer must-have controls in place.

IdentifyProtectDetectRespondRecoverGovern
Toggle a control — the map reacts
Or start from:

A sample of 8 controls, weighted. The product scores the full library (29 controls on NIST CSF 2.0 × CIS IG1–IG3) with per-template weights, and tracks 7 insurer must-haves.

Built on the standards the industry already speaks
NIST CSF 2.0CIS Critical Security Controls v8.1CIS Implementation Groups (IG1 / IG2 / IG3)FTC Safeguards RuleCyber-insurance underwriting
For MSP owners

Sell a posture your client can see — not a list of tools.

Built on NIST CSF and CIS: credible to insurers, defensible to auditors, and finally legible to the person across the table.

  • Live what-if assessmentsSit with a partner, toggle controls, and watch the score and posture map move in real time. The conversation a PDF report can't have.
  • The posture template builder finds the gapsCompares the stack you already sell against the posture's target — so you extend what a client already pays for before recommending anything new.
  • Insurability, called out explicitlyThe seven controls cyber-insurers effectively require are flagged on their own. A concrete hook for the renewal conversation.
  • White-label client reportsYour brand on the partner-facing posture page. Posturit stays in the background with a "powered by" mark.
Request early access →
How it works

Three moves, one posture model.

1

Build your posture template

Guided intake maps the products you already sell onto NIST CSF and CIS. The framework is pre-baked — nothing is custom unless you want it to be.

2

Run the conversation live

Assess a client, toggle controls, and let the map and score react in front of them. Save the snapshot; track what got approved.

3

Show the client what they pay for

Each partner gets a posture page in your brand — their score, their gaps, their roadmap. The visual every quarterly review wishes it had.

Methodology

Two axes the industry already trusts.

Posturit doesn't invent its own taxonomy. The posture is structured on NIST CSF 2.0 (the six functions Govern / Identify / Protect / Detect / Respond / Recover) and CIS Implementation Groups (IG1, IG2, IG3 — the official maturity progression). Every CIS Safeguard ships with an official NIST CSF function mapping, so controls self-place. IG1 is the codified “essential cyber hygiene” minimum — and where most SMBs should aim first.

Wedges
NIST CSF 2.0 functions
Outcomes recognized by insurers, auditors, and boards.
Rings
CIS Implementation Groups
IG1 → IG2 → IG3. Strictly nested — one product at increasing depth, not two products.
IdentifyProtectDetectRespondRecoverGovern
What's next

Where this is going.

Posturit is built for MSPs first, and that's the only part shipping today. Three other audiences are on the map — listed here so you can see the direction without me pretending any of it is ready.

In design

Enterprise / CISO

One posture model across subsidiaries, with roll-up scoring at the parent and per-org drill-down. The role model is built; the parent-level surfaces are not.

Release 2

Security vendors

A vendor portal for mapping products to the controls MSPs need to fill, with aggregate-only category signal. Vendors would never see client data — that boundary is the design premise, not a feature.

Exploring

SMBs without an MSP

A free self-assessment on the same framework, routed to an MSP that fits. Channel-friendly by design — the intent is never to sell direct. Not built.

Rich Anderson
Who's behind this

Built by an MSP operator, not a security startup.

I'm Rich Anderson. I've spent more than two decades running and advising managed service providers, and eleven years facilitating MSP peer groups. Posturit exists because I kept watching good MSPs lose security conversations they should have won — not for lack of a good stack, but for lack of a way to make the stack visible to the person paying for it.

It's early. I'd rather build the first version with a handful of MSPs who'll tell me what's wrong with it than launch loudly to nobody.

Early access

The first six MSPs get six months free.

I'm building toward a small founding group who'll help shape the product — full features, white-label included, no charge for six months.

Being straight with you: the product isn't open yet. Leave your details and I'll reach out personally when there's something worth your time — no drip sequence, no sales team.

No spam, no list-selling, no drip sequence. See our privacy policy.
What a founding MSP gets
  • Full features + white-label, free for six months
  • Direct input on what gets built
  • Locked-in pricing when it goes paid
  • A direct line to me, not a ticket queue