Built for non-profits & small organizations

Know where your security policies stand — in minutes, not months

Upload the policy documents you already have. PolicyAlign maps them against the NIST Cybersecurity Framework — plus the HIPAA, AI-governance, and questionnaire checks you're measured by — and shows what's covered, what's missing, and what to fix first. Plain language, no security team required.

Currently invite-only · early access by request · your documents stay private to your organization

73%CSF 2.0Compliance posture▲ +6 pts622816Score over timeProtectIdentifyDetectRespondPR.AA-01ID.AM-02DE.CM-01RS.MA-01
Framework watch: NIST CSF 2.0 · SP 800-53 · HIPAA · AI RMF · FERPA/COPPA — verified against official sources 12d agoFramework updates →

106

NIST CSF 2.0 subcategories analyzed

~5 min

from upload to report

AES-256

encryption at rest & in transit

No training

your docs never train AI models

Compliance shouldn't require a consultant you can't afford

Grant funders, cyber-insurers, and partner agencies increasingly ask small organizations to prove their security posture. PolicyAlign turns the policies you already have into the evidence and the roadmap — without a $15,000 consulting engagement.

See your real coverage

A single score and a control-by-control breakdown across all six NIST functions — Govern, Identify, Protect, Detect, Respond, Recover.

Know what to fix first

Quick wins, weakest areas, and the gaps that matter most — prioritized so you spend effort where it counts.

Prove it over time

Re-assess as you improve and watch the score climb — the trajectory boards, insurers, and grant audits actually want to see.

Three steps to a clear picture

A guided wizard walks you through it. Most assessments finish in about five minutes.

1

Upload

Drag in the policies you already have — handbooks, IT policies, memos. PDF, Word, or text.

2

Analyze

AI reads each document and maps it against the NIST framework, flagging weak or outdated language.

3

Act

Get a plain-language report: your score, your gaps, your quick wins, and a tracker to work from.

app · your compliance dashboard
73%CSF 2.0 SCORECompliance postureLatest assessment · 106 NIST CSF 2.0 subcategories62 covered28 partial16 missingSection performance vs. sectorGovern62%Identify55%Protect82%Detect30%Respond20%Recover42%Weakest areasRisk AssessmentIncident MgmtAdverse EventsQuick winsAssign a security lead (GV.RR-01)Document cyber roles (GV.RR-02)Identify key risks (ID.RA-01)
New · AI governance readiness

One analysis, multiple lenses

Your documents are analyzed once against the NIST Cybersecurity Framework — then re-projected through the frameworks that matter to your organization, at no extra effort. That now includes AI governance — the question every funder and board is starting to ask.

  • LiveNIST CSF 2.0The full 106-subcategory framework — the backbone of the analysis.
  • LiveAI Governance (NIST AI RMF)The question funders and boards now ask: how do you govern your use of AI? Maps your readiness against the NIST AI Risk Management Framework.
  • LiveHIPAA Security RuleFor organizations handling health information — safeguard-by-safeguard readiness.
  • LiveEducation data privacyFERPA, district Data Privacy Agreements (SDPC/NDPA) & COPPA — for organizations serving schools.
  • ComingCyber-insurance readinessThe controls carriers ask about at renewal.

Curious how scores and comparisons are calculated? Read the methodology.

Plain-language, document-first, built for organizations with no security team. That's the difference.

Govern
Identify
Protect
Detect
Respond
Recover

Plus AI governance

Govern · Map · Measure · Manage — the NIST AI RMF, in the same report.

Every report is yours to download and keep — even if you cancel.

Security questionnaires

Answer the questionnaires they send you — from what you already have

Insurers, grant funders, auditors, and certification bodies all send the same kind of long security questionnaire. Upload it and PolicyAlign answers each question from your assessment, cites the source policy, and scores how well you're covered — so you review and send instead of starting from a blank page.

Cyber-insurance renewals

The MFA, EDR, backup, and training questions carriers ask at every renewal — answered from your documented controls.

Grant & funder reviews

Prove your security posture to win and keep funding — without a consultant drafting every answer.

Audits & certifications

Auditor, certification, and PCI self-assessment (SAQ) questionnaires, mapped to the policies you already have on file.

How it works

  • Upload any format — Excel, Word, CSV, or PDF. The questions are read automatically.
  • Each answer is drafted from your own policies, with the source document cited.
  • Scored Met / Partial / Not met, so you see the gaps before they do.
  • Review, edit, and export. It assists — you always own the final submission.

Built into your account — turns the questionnaire you dread into a quick review-and-send.

Simple pricing for small organizations

A one-time setup for your first assessment, then a subscription that includes regular re-assessment. Annual billing saves two months.

Starter

For a single organization getting its first clear picture.

$69/moor $690/yr

+ $399 one-time setup (first assessment)

  • 2 assessments per month
  • Up to 20 documents each
  • Full NIST CSF 2.0 report
  • HIPAA readiness lens
  • Score history & trend
Request access

Pro

Most popular

For organizations that re-assess often and want deeper analysis.

$149/moor $1,490/yr

+ $599 one-time setup (first assessment)

  • 5 assessments per month
  • Up to 40 documents each
  • Everything in Starter
  • Deep-analysis mode
  • Priority support
Request access

Need a one-time assessment without a subscription, or pricing for multiple agencies? Talk to us.

Why I built this

The documentation problem looked the same everywhere

I've done IT and security work across organizations of all sizes — some with dedicated security staff, some running on a one-person IT team. What surprised me early on was that the documentation problem looked the same everywhere. Policies that existed but hadn't been reviewed in years. Frameworks referenced in job postings that nobody could map their actual controls to. Gap reports that lived in someone's head or a spreadsheet that was already out of date.

Larger organizations at least had the staff to grind through it. Nonprofits had the same problem with none of the options. When a funder or cyber insurance renewal asked for NIST alignment, there was no affordable tool that could take their existing policies and tell them where they stood — just a questionnaire with no output, or an enterprise platform starting at $7,500 a year.

PolicyAlign is what I built for that gap. Upload what you already have, get a real analysis against NIST CSF 2.0, and walk away with something you can actually use — a gap report, an action plan, a board-ready summary. No consultant required.

Questions we'd ask too

Straight answers, no gloss. Anything else — email us and a human replies.

Is this a compliance certification or legal advice?

No. PolicyAlign shows how your written policies align to frameworks like NIST CSF 2.0 and where the gaps are — guidance to work from, not a certification, an audit, or a legal compliance determination. For formal attestation you still need a qualified auditor.

Do I need a security team or an IT background to use it?

No. The report is written in plain language: what each control means, why it matters, and what to fix first. It's built for executive directors, operations managers, and the person who ended up owning IT.

What happens to the documents I upload?

They're encrypted, isolated to your organization, and never used to train AI models. Documents are deleted within 14 days if you cancel, and you can request deletion anytime. The Security page describes exactly how this works — including what we don't claim.

How do I know the AI isn't making things up?

Every finding cites the exact excerpt from your document it came from, so you can verify each rating yourself. Findings that can't be traced back to your actual text are automatically discarded before you ever see them.

What do I need to get started?

Just the documents you already have — employee handbook, IT policies, memos, procedures — in PDF, Word, or text. Upload, and the report is ready in about five minutes. No agents to install, nothing to configure.

Which frameworks are covered?

Documents are analyzed once against the full NIST CSF 2.0 catalog (106 subcategories), then re-projected through HIPAA Security Rule, AI governance (NIST AI RMF), and education data privacy lenses at no extra effort. A cyber-insurance readiness lens is on the way.

How is this different from hiring a consultant?

A consultant engagement for this kind of assessment typically runs $10,000–$15,000 and gives you a point-in-time PDF. PolicyAlign costs a fraction of that and lets you re-assess every month, so you can show funders and insurers actual progress — not a snapshot from last year.

Your data is treated the way we'd want ours treated

Per-organization isolation enforced at the database, AES-256 encryption, two-factor authentication, and a clear data-processing agreement. We keep as little as possible and delete on request within 14 days. No marketing gloss — read exactly how we secure it.

See where you stand today

Upload your first set of policies and get a clear, prioritized report in about five minutes.