Ross ROSS = Recommend OSS · open-source software intelligence for agents

cisagov/cset

Cybersecurity Evaluation Tool observed · 2026-08-28

github.com/cisagov/cset · TSQL · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

69/100

  • Activity 97
  • Release rhythm 16
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 127.0
  • age_days: 2667
  • days_rel: 411
  • days_push: 21
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

1887 stars · 329 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

CSET is a free desktop application from CISA and Idaho National Laboratory that guides organizations through step-by-step cybersecurity assessments of their IT and industrial control system (ICS) environments. It compares collected facility information against security standards and regulations, evaluates compliance, and generates recommendations for improving cybersecurity posture.

Use cases

  • assess my organization's cybersecurity compliance against standards like NIST
  • audit security of industrial control systems in a facility
  • identify vulnerabilities in our IT and OT network architecture
  • generate a cybersecurity gap analysis with recommendations
  • evaluate ICS security posture before and after changes
  • document a vulnerability assessment process for auditors

When to choose

  • you need a free, standards-based cybersecurity assessment tool for IT or ICS environments
  • you are an asset owner of critical infrastructure evaluating compliance with security guidelines
  • you want structured, repeatable vulnerability assessments with actionable recommendations

When to avoid

  • you need continuous automated vulnerability scanning of live networks rather than guided assessments
  • you require a lightweight CLI or cloud-native tool rather than a Windows desktop application
  • you need penetration testing or red-team capabilities rather than compliance evaluation

Facets

application · maturity active

security vulnerability-scanning developer-tools security infrastructure-as-code legal windows cross-platform cybersecurity ics-security security-audit compliance-assessment cisa critical-infrastructure standards-assessment docker

1 source

Member repositories

RepositoryRoleHealth v2
cisagov/csetmain69

For agents

markdown · JSON · MCP: product_card(name="cisagov/cset")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem