Technology readiness self-check
This page asks seventeen questions taken from three published instruments. Every statement is quoted from the instrument named above it, and every answer scale is the one that instrument uses. The result reports your answers back on each instrument's own scale and names which full instrument to run next. Nothing is saved or sent anywhere.
A partner organization can run this on itself in about ten minutes. An SIL 503 pair runs it in the Week 9 lab and again with the organization it interviews for the Technology Strategy Pitch. It takes one statement per area from instruments that run much longer, so it points at the areas worth a closer look and does not substitute for the published instruments.
Digital maturity
The eight statements below are quoted from the NCVO Digital Maturity Matrix, a free tool that asks 63 statements across eight areas and scores each one twice, once for where the organization is now and once for where it plans to be. One statement per area appears here. The four ratings are NCVO's.
Data maturity
The three questions below come from the Data Orchard Data Maturity Framework, version 2.1, which gives five stages across seven themes for not-for-profit organizations. Each option quotes one line from the framework's description of that stage in that theme. Leadership, Tools, and Skills appear here; the framework's other four themes are Uses, Data, Analysis, and Culture.
Essential cyber hygiene
The six items below are reproduced without modification from Implementation Group 1 of the CIS Critical Security Controls, version 8.1. The Center for Internet Security defines IG1 as essential cyber hygiene, a set of 56 safeguards for organizations with limited IT and cybersecurity expertise. Each safeguard is written as something an organization either does or does not do, so the answers here record whether each one is in place.
Result
The routing rule reads each section as a share of its own maximum and names the instrument behind the lowest section. Ties go to the security section, which CIS describes as an emerging minimum standard of information security for all enterprises. An answer of "not sure" counts as not in place, because an unconfirmed safeguard cannot be counted as working.
All seventeen questions need an answer before the result can be worked out, and any question you leave blank is marked in place when you press the button. The copy button below works on whatever has been answered so far.
The browser blocked the clipboard, so the result is in the box below instead. The text in it is already selected: press Control and C together, or Command and C on a Mac, to copy it.
Other tools
Each of these goes further than any section above, and all of them are free to run.
- NCVO Digital Maturity Matrix. 63 statements across leadership and strategy, expertise and capacity, technology, service design, content, communications and campaigns, data and insight, and security and data protection. It takes a current rating and a target rating on each statement, and one login can be shared across a staff team so different people answer for their own areas.
- Data Orchard Data Maturity Assessment. The online version of the framework quoted above, in free and paid versions, covering all seven themes. The framework document describes what each of the five stages looks like in each theme, so an organization can read what the next stage would involve.
- CIS Controls Implementation Group 1. All 56 safeguards, with the CIS Controls Self Assessment Tool to track them over time.
- NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide, NIST SP 1300. The same ground as a planning document, organized by the six CSF functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- NTEN Tech Accelerate. About ninety questions across leadership, infrastructure, engagement, and organization, returning a benchmark against organizations of similar size and budget. The strategy pitch names this one.
- TechSoup Digital Assessment. Programs, fundraising, communications, operations, security, and infrastructure, with a twenty-question introductory version. The strategy pitch names this one too.
Sources and licensing
The digital maturity statements and the four ratings are quoted from the NCVO Digital Maturity Matrix. NCVO publishes its website content under the Attribution-NonCommercial-ShareAlike 4.0 International license.
The data maturity options are quoted from the Data Maturity Framework, version 2.1, copyright Data Orchard CIC, January 2022, licensed under CC BY-NC-SA 4.0. Data Orchard CIC is the source of the original.
The six safeguards are reproduced from the CIS Critical Security Controls version 8.1, copyright Center for Internet Security, licensed under CC BY-NC-ND 4.0. That license permits redistribution without modification, so the safeguard numbers, titles, and text appear exactly as published. Current guidance is at cisecurity.org/controls.
The CSF functions named above come from NIST CSWP 29, a United States government publication. This page is non-commercial coursework, and the material adapted from NCVO and Data Orchard is redistributed under the same Attribution-NonCommercial-ShareAlike 4.0 International license as the originals.