Companies paste the prompts into a chatbot, which drafts the cybersecurity assessment that customers, regulators, and insurers ask to see; comments are open until October 15.
The National Institute of Standards and Technology (NIST) published three free AI prompts that speed up the creation of a company’s cybersecurity assessment. NIST released them on August 19 as a draft and is taking public comments until October 15.
A cybersecurity assessment is a line-by-line record of the policies and practices a company has in place for each of NIST’s security recommendations. Customers, regulators, and insurers ask to see these assessments when they want to judge how a company manages security risk. Producing one means reading every security policy, audit result, penetration test report, and procedure the company holds, then writing up each item by hand.
Companies are already using AI for this, NIST says. Each prompt is a block of text a company pastes into an AI tool along with those documents, and all three prompts follow a format called CO-STAR: context, objective, style, tone, audience, and the desired response. NIST published them to give security teams a usable starting point and to record how practitioners construct prompts for this task.
Each prompt produces a different part of the cybersecurity assessment
The first prompt covers security governance: who makes security decisions and who oversees them. It reads the company’s policies and strategy and rates each item as aligned, partly aligned, misaligned, or not addressed, naming the document behind every mark.
The second drafts the full cybersecurity assessment for where the company currently stands. NIST says this prompt can compress the initial drafting from weeks to hours.
The third recommends the cybersecurity posture the company should have instead, based on risks it already identified and published industry practice. The difference between what the company does today and what it should be doing shows which of NIST’s recommendations it is not yet meeting.
NIST limits the scope of the prompt
The NIST prompts tell the chatbot to use only the documents they receive and infer nothing beyond them, to cite the policy or requirement behind every entry, and to state plainly where those documents say nothing rather than filling the gap. They bar the chatbots from rating how advanced the company’s security is, or comparing it to other companies, unless someone supplies the comparison data.
Each draft must close with a note on where the evidence is thin, including any entry resting on a documented procedure rather than proof that anyone follows it.
NIST tells companies to check
The chatbot analyzes documents a company already holds: security policies, past risk assessments, audit results, penetration test reports, vulnerability scan results, and notes from staff interviews. Before uploading, NIST says to check how the AI tool handles the above data, including how long it keeps what it receives and whether it trains on it, and to follow the company’s own data policy. Once the chatbot produces a draft, NIST recommends that someone qualified review it before anyone acts on it.
How to comment
Comments go to [email protected] until October 15. NIST can revise the prompts, the conditions attached to them, or the three uses before it publishes a final version.
NIST published a separate draft in December on how to protect AI systems from attack and how to defend against attackers who use AI. Comments on that one closed on January 30.

