# cisagov/cset

Cybersecurity Evaluation Tool

Repository: https://github.com/cisagov/cset
Canonical: https://ross.abutalabs.com/products/cset
Language: TSQL
License: MIT
License Family: permissive
Topics: cset, security-audit
Last push: 2026-08-12T20:09:06+00:00

## Health v2 (maintenance only)
Score: 69/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 16, longevity 100
- inputs: {"age_days": 2667, "days_push": 21, "days_rel": 411, "gap_med": 127.0, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1887, forks 329 (observed 2026-08-28T04:05:49.151758+00:00)

## What it is
CSET is a free desktop application from CISA and Idaho National Laboratory that guides organizations through step-by-step cybersecurity assessments of their IT and industrial control system (ICS) environments. It compares collected facility information against security standards and regulations, evaluates compliance, and generates recommendations for improving cybersecurity posture.

## Use cases
- assess my organization's cybersecurity compliance against standards like NIST
- audit security of industrial control systems in a facility
- identify vulnerabilities in our IT and OT network architecture
- generate a cybersecurity gap analysis with recommendations
- evaluate ICS security posture before and after changes
- document a vulnerability assessment process for auditors

## When to choose
- you need a free, standards-based cybersecurity assessment tool for IT or ICS environments
- you are an asset owner of critical infrastructure evaluating compliance with security guidelines
- you want structured, repeatable vulnerability assessments with actionable recommendations

## When to avoid
- you need continuous automated vulnerability scanning of live networks rather than guided assessments
- you require a lightweight CLI or cloud-native tool rather than a Windows desktop application
- you need penetration testing or red-team capabilities rather than compliance evaluation

## Facets
- artifact type: application
- maturity: active
- function: security, vulnerability-scanning, developer-tools
- domain: security, infrastructure-as-code, legal
- platform: windows, cross-platform
- tags: cybersecurity, ics-security, security-audit, compliance-assessment, cisa, critical-infrastructure, standards-assessment, docker

## Member repositories
- cisagov/cset (main) score 69

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:49.151758+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:13:32.301773+00:00, confidence not recorded.
  - readme: https://github.com/cisagov/cset (fetched 2026-08-28T04:05:49.151758+00:00, sha 699e098241be)
- Data as of 2026-08-30T08:39:29.467469+00:00.
