RISKFORGE v2.0 · UPDATED MAY 2026 · PCI DSS v4.0.1 + NIST CSF 2.0 45 TABS · 701 SUB-REQUIREMENTS · 10 SAQ TYPES · 106 CSF SUBCATEGORIES Explore Demo →
NIST CSF 2.0 · PCI DSS v4.0.1 · v2.0 · Updated May 2026

Stop paying $15K for what an expert team already built.

Professional-grade NIST CSF 2.0 and PCI DSS v4.0.1 workbooks — 45 tabs, 701 sub-requirements, every artifact a QSA or auditor expects. Built by IT Risk & Compliance practitioners with a decade across banking, defense, and financial services. Pay once. Download instantly. Audit-ready.

Built by practitioners with experience at
01Tier-1 Banking
02U.S. Defense
03Financial Services
04FinTech / Payments
05Insurance
01 · The Problem

Compliance work is broken. It doesn't have to be.

Most teams pay consultants thousands for spreadsheets that could have been built once and reused forever. RiskForge gives you the workbooks the consultants charge you for — without the invoice.

01

Consultant invoices that don't end

Big-4 firms charge $15K–$50K for gap assessments and SAQ prep. The deliverable is usually a workbook you could own outright.

Banking · Finance
02

Internal teams reinventing the wheel

Every audit cycle, someone rebuilds the same tracker from scratch in Excel. Hours lost. Inconsistent across business units.

Defense · GovCon
03

Free templates that miss the controls

Online templates skip Govern, omit testing procedures, and lack maturity scoring. They fail the audit they were built for.

FinTech · Payments
04

Frameworks updating faster than tools

NIST CSF moved to 2.0 in Feb 2024. PCI DSS v4.0.1 made every future-dated requirement mandatory in March 2025. Most templates online still ship the old versions.

Insurance · HealthCo
02 · Frameworks

Six frameworks. One vault.

Each workbook is built to the latest version of the framework, with cross-references and evidence trackers. Two ship today; four are on the roadmap and included in the Full Vault.

FWK · 01 · v2.0

NIST CSF 2.0 Gap Assessment

All 106 CSF subcategories across the six functions with NIST's official Implementation Examples, Informative References cross-walk (ISO 27001, NIST 800-53 Rev. 5, CIS v8), Tier Self-Assessment, Org Profile, and a radar Executive Summary.

18 tabs · 106 subcats$99
FWK · 02 · v2.0

PCI DSS v4.0.1 SAQ Prep

All 10 official SAQ types, 595 sub-requirements, plus every artifact a QSA mandates: TRA, CCW, CAW, Scope, and Diagrams. Dynamic Roadmap with P1/P2/P3 priority tiering.

27 tabs · 10 SAQ types$149
FWK · 03

NIST SP 800-53 Rev. 5

Control families AC through SR with baselines for Low / Moderate / High impact systems. POAM tracker and SSP outline included.

20 familiesQ3 2026
FWK · 04

CRI Profile 2.0

Cyber Risk Institute's financial-services profile mapped to NIST CSF and FFIEC CAT, with regulator-ready reporting tabs.

FS-mappedQ3
FWK · 05

CSA CCM v4

Cloud Controls Matrix with CAIQ-style questionnaire, shared-responsibility mapping, and provider evidence collection.

17 domainsQ4
FWK · 06

COBIT 2019

Governance and management objectives with capability scoring, design factors workbook, and goals cascade worksheet.

40 objectivesQ4
Free interactive tools

Try the engine before you buy the workbook.

Two free tools run the exact logic that ships inside the workbooks — no download, nothing to install. Use either one right here, then optionally add your details to receive a free, watermarked sample of the matching workbook by email.

PCI · SAQ Selector · Free

Which SAQ do you actually need?

Up to eight yes/no questions resolve which of the 10 official SAQ types applies to you — with the same precedence the workbook enforces (service provider beats stored-CHD beats virtual-terminal-only). It shows your result first, then offers the email capture.

  1. Answer up to 8 yes/no questions about how you accept cardholder data.
  2. Get your SAQ type instantly — name, scope, card-storage rules, and typical size.
  3. Optionally share your details to receive a one-page checklist and a free sample.
After you finish · free PCI sample workbook

Add your details (name + email required, company + role optional) and we’ll email a free sample of the PCI SAQ Prep Workbook — a generous teaser faithful to the real thing: a “Free Sample” cover, 3–6 populated example rows per key tab, “··· N more rows in the full version ···” notes, a “Get Full Version” tab, and a SAMPLE footer on every sheet.

NIST · Maturity Snapshot · Free

How mature is your program?

Twelve quick questions — two per CSF function, on a 5-point maturity scale — produce an instant radar chart of maturity by function, your overall maturity level, and your two biggest gaps. Exactly what the workbook’s Executive Summary produces.

  1. Rate two statements for each of the six functions (Govern → Recover).
  2. See your radar, overall level, per-function bars, and biggest gaps instantly.
  3. Optionally share your details to receive your scores and a free sample.
After you finish · free NIST sample workbook

Add your details (name + email required, company + role optional) and we’ll email a free sample of the NIST CSF 2.0 Gap Assessment Workbook — a generous teaser faithful to the real thing: a “Free Sample” cover, 3–6 populated example rows per key tab, “··· N more rows in the full version ···” notes, a “Get Full Version” tab, and a SAMPLE footer on every sheet.

riskforge.tech/tools/saq-selector
Live preview — interact with it right here
03 · Pricing

Choose your compliance level.

One-time payment. Instant download. No subscriptions, no renewal fees. Secure checkout via Payhip.

TIER 01 · v2.0

NIST CSF 2.0 Gap Assessment Workbook

All 106 CSF 2.0 subcategories with NIST's official Implementation Examples and Informative References cross-walked to ISO 27001, NIST 800-53, and CIS Controls. Organizational Profile, Tier Self-Assessment, Risk-Adjusted Roadmap, and a radar-chart Executive Summary.

$99one-time
All 6 CSF Functions · 106 subcategories
NIST Implementation Examples (100% coverage)
Informative References (ISO 27001 / NIST 800-53 / CIS)
Tier Self-Assessment + Organizational Profile
Lifetime updates within v2.x
TIER 02 · v2.0

PCI DSS v4.0.1 SAQ Prep Workbook

SAQ selector that actually computes. All 10 SAQ types with 595 sub-requirements. Targeted Risk Analysis, Compensating & Customized Approach Worksheets, scope and CHDFD templates — every artifact a QSA expects. Dynamic Roadmap auto-prioritized from your status entries.

$149one-time
SAQ Type Selector with all 10 SAQ types
595 sub-requirements across all SAQ tabs
TRA · CCW · CAW · Scope · Diagrams artifacts
Dynamic Roadmap with P1/P2/P3 priority tiering
Lifetime updates within v4.x
TIER 03 · FULL VAULTBest Value

RiskForge Full Compliance Vault

Both current workbooks plus every future framework on the roadmap. Save $400 vs. buying individually.

$349all updates incl.
NIST CSF 2.0 + PCI DSS v4.0.1 (both at full v2.0)
NIST SP 800-53 Rev. 5 (Q3 2026)
CRI Profile 2.0 · CCM v4 · COBIT 2019 (roadmap)
All future framework releases within Vault tier
Priority support · early access · v3.x roadmap input
Instant download Secure checkout · Payhip One-time payment
45Visible tabs combined
701Sub-requirement rows
10PCI SAQ types
106CSF subcategories
239Informative References
90Glossary terms
04 · Built for practitioners

Built for the people who use this for a living.

Both workbooks share the same workpaper hygiene, integration, and accessibility features — the conventions QSAs, internal audit, and GRC reviewers actually expect to see.

01

Audit-grade workpaper hygiene

Preparer / reviewer / approver sign-off on every workbook. Document control via Revision History. Industry-standard tickmark legend (✓ Vouched, ∆ Recalculated, ※ Confirmed).

02

PCAOB-aligned deficiency log

Likelihood × magnitude scoring with the three official PCAOB categories: Deficiency / Significant Deficiency / Material Weakness.

03

AICPA-aligned sampling

AU-C 530 sample-size guidance per control frequency. Random / systematic / judgmental / haphazard method definitions and a sample-selection record table.

04

COSO 2013 control attributes

Frequency (Continuous / Daily / Weekly / Monthly / Quarterly / Annual / Event-driven), Type (Manual / IT-Dependent / Automated), and Nature (Preventive / Detective) per control.

05

GRC tool integration

Flat Export tab on both workbooks. Normalized columns, copy as values, save as CSV — ingest into Archer, ServiceNow GRC, OneTrust, or AuditBoard. Stable across versions.

06

White-label ready

Hidden Branding tab with 10 brand strings (name, tagline, URL, footer, primary/accent color, logo reference, license). Unhide, rebrand, ship under your own name.

07

WCAG 2.1 AA accessibility

Status colors paired with bold high-contrast text on every cell. Works for Deuteranopia and Protanopia users (1 in 12 men). Documented in the Tickmarks tab.

08

Print + tool compatibility

Landscape, fit-to-width, headers with CONFIDENTIAL marker. Sheet protection without passwords. Excel 2016+, Microsoft 365, Google Sheets, LibreOffice Calc — tested.

04 · About RiskForge

Built by the people who get audited.

RiskForge was founded by a senior IT Risk & Compliance practitioner with a decade of work across regulated industries — banking, defense contracting, financial services, and FinTech.

Every workbook is structured the way auditors actually want to see evidence presented. No filler. No theatre. Just the deliverables the consulting bill was hiding.

01
IT Risk Manager Tier-1 Banking · Enterprise Risk & Audit
Banking
02
Compliance Lead U.S. Defense · NIST 800-53 & CMMC programs
Defense
03
Senior Auditor Financial Services · SOX ITGC & PCI assessments
FinServ
04
Risk Architect FinTech / Payments · PCI DSS v3 → v4 migration
FinTech
05 · Practitioner Feedback

The work it saved, in their words.

Early customers were heads of GRC, audit managers, and CISOs at mid-market firms. Here's what they said.

★ ★ ★ ★ ★
"Replaced a $22K consultant engagement. The Govern tab alone was worth the price. Our auditor accepted the maturity scoring without revisions."
M. Chen Director · GRC
Mid-Market Bank
★ ★ ★ ★ ★
"The PCI SAQ Type Selector saved me a week of arguing with our QSA about which SAQ applied. Clean, accurate, the way I'd have built it if I had the time."
J. Okafor Head of Compliance
Payments / FinTech
★ ★ ★ ★ ★
"Bought the Full Vault for our team. Standardized our gap assessments across four business units in under a month. Easiest yes I've given all year."
A. Patel CISO
Insurance Carrier
06 · FAQ

Common questions, direct answers.

If you have a question we haven't answered, email us at hello@riskforge.tech — we usually reply within one business day.

Q · 01
Is this a subscription?
No. RiskForge is a one-time purchase. You own the files, store them anywhere, and use them across as many internal assessments as you need.
Q · 02
Do I get updates when the framework changes?
Yes, within the same major version. If NIST CSF moves from v2.0 to v2.1, your file updates for free. A new major version (e.g. CSF 3.0) ships as a new release.
Q · 03
What format are the workbooks in?
Native Microsoft Excel (.xlsx). They open in Excel, Google Sheets, and Numbers without conversion. No macros, no add-ins, no external dependencies.
Q · 04
Can I use these for client engagements?
The standard license covers internal use across your organization. For consultancy or reseller licensing, contact us — we offer a separate practitioner license.
Q · 05
What if it isn't what I expected?
The Demo lets you walk through every tab before you buy — it's a real workbook, not a screenshot. You'll know exactly what you're getting.
Ready when you are

Skip the invoice. Ship the work.

Download the workbooks today and put them to work before your next audit cycle.

01
Instant downloadFiles in your inbox the moment payment clears.
02
One-time paymentNo subscriptions, no renewal fees, ever.
03
Lifetime updatesFree updates within the same major version.