UNCLASSIFIED — For Official Use Only
🛡

NIST Cybersecurity Framework 2.0

Self-Attestation & Maturity Assessment
Advanced Learning Academy LLC
Document Date: May 2026
Assessment Period: January 2026 – May 2026
Document Version: 1.0

Prepared by:
Timothy E. Parker
Founder & Chief Executive Officer
Document ID: ALA-SEC-CSF2-2026-001
Classification: UNCLASSIFIED // FOUO
ALA-SEC-CSF2-2026-001 • v1.0 • May 2026

Table of Contents

1. Executive Summary3
2. Assessment Methodology4
2.1 Scope4
2.2 Tier Definitions4
2.3 Assessment Process5
3. Organizational Profile5
4. Function Assessment: GOVERN (GV)6
5. Function Assessment: IDENTIFY (ID)8
6. Function Assessment: PROTECT (PR)9
7. Function Assessment: DETECT (DE)11
8. Function Assessment: RESPOND (RS)12
9. Function Assessment: RECOVER (RC)14
10. Summary Maturity Matrix15
11. Gap Analysis & Improvement Plan16
12. Attestation Statement17
Appendix A: Subprocessor Security Summary18

1. Executive Summary

Advanced Learning Academy LLC ("ALA") has conducted a comprehensive self-assessment of its cybersecurity posture against the NIST Cybersecurity Framework (CSF) 2.0, published by the National Institute of Standards and Technology in February 2024. This assessment covers all six CSF 2.0 Functions — Govern, Identify, Protect, Detect, Respond, and Recover — along with their associated Categories and Subcategories.

ALA operates a fully cloud-native technology stack built exclusively on Cloudflare Workers, Cloudflare Pages, Cloudflare D1, Cloudflare KV, and Cloudflare R2. This architecture eliminates traditional server infrastructure and inherits enterprise-grade security controls from Cloudflare's FedRAMP Moderate authorized platform, SOC 2 Type II certified environment, and ISO 27001 certified operations.

Payment processing is handled exclusively through Stripe, a PCI DSS Level 1 certified payment processor. ALA never stores, processes, or transmits cardholder data. Email delivery is managed through Mailgun (SOC 2 Type II, GDPR compliant) with Cloudflare Email Routing for inbound mail handling.

Tier 3
Overall Maturity Rating
Repeatable
6 / 6
CSF Functions Assessed
22
Categories Evaluated

The assessment concludes that ALA maintains a Tier 3 — Repeatable overall maturity level. Security practices are formalized, consistently applied, and regularly reviewed. Several infrastructure security controls inherited from Cloudflare's platform achieve Tier 4 — Adaptive maturity, reflecting the platform's continuous, automated security capabilities.

Key strengths include a zero-server-footprint architecture, automated backup systems with 15-minute intervals, encryption at rest and in transit across all data stores, and reliance on FedRAMP-authorized infrastructure. Areas identified for continued improvement include formalizing tabletop exercises and expanding third-party security validation.

2. Assessment Methodology

2.1 Scope

This self-assessment covers all information systems, data stores, and digital services operated by Advanced Learning Academy LLC, including but not limited to:

2.2 Tier Definitions

The NIST CSF 2.0 defines four Implementation Tiers that describe the degree of rigor and sophistication in cybersecurity risk management:

Tier Description Characteristics
Tier 1 — Partial Cybersecurity risk management is ad hoc, with limited awareness of organizational risk. Reactive; irregular practices
Tier 2 — Risk Informed Risk management practices are approved but may not be established as policy. Awareness exists but implementation is inconsistent. Aware; partially formalized
Tier 3 — Repeatable Risk management practices are formally approved, expressed as policy, and regularly updated. Organization-wide approach is in place. Consistent; policy-driven
Tier 4 — Adaptive Organization adapts practices based on lessons learned and predictive indicators. Continuous improvement is embedded. Proactive; continuously improving

2.3 Assessment Process

The self-assessment was conducted through the following process:

  1. Asset Inventory Review — Complete enumeration of all digital assets via Cloudflare dashboard
  2. Control Mapping — Mapping of existing security controls to CSF 2.0 Categories and Subcategories
  3. Evidence Collection — Documentation of configurations, policies, and automated protections
  4. Gap Identification — Analysis of areas where controls are absent or insufficient
  5. Tier Assignment — Rating of each Category based on implementation maturity
  6. Improvement Planning — Development of remediation priorities for identified gaps

Assessment data was gathered between January and May 2026. Where controls are inherited from Cloudflare's platform, tier ratings reflect Cloudflare's published compliance certifications and documented security posture.

3. Organizational Profile

Legal EntityAdvanced Learning Academy LLC
EIN33-3760515
UEI (SAM.gov)Z272LH7MCDT2
CAGE Code1A8H4
Principal LocationCarmel, Indiana 46033
Organizational SizeSmall Business — Sole Proprietor
Founder & CEOTimothy E. Parker
Primary IndustryEducational Technology (EdTech) / Cognitive Assessment
Infrastructure ProviderCloudflare, Inc. (FedRAMP Moderate Authorized)
Architecture Model100% Cloud-Native / Serverless (Zero on-premise infrastructure)
Data ClassificationAssessment results, educational data, business operational data
PCI ScopeOut of scope — all payment processing delegated to Stripe

Technology Architecture Overview

ALA operates a fully serverless architecture with no traditional servers, virtual machines, containers, or on-premise infrastructure. All computation occurs on Cloudflare's edge network across 300+ global points of presence. This architecture provides several inherent security advantages:

4. Function Assessment: GOVERN (GV)

GOVERN (GV)

Function Rating: Tier 3 — Repeatable

The Govern function establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy. As a sole-proprietor operation, ALA's governance structure is streamlined but comprehensive, with clearly defined policies and regular review cycles.

GV.OC — Organizational Context Tier 3

GV.RM — Risk Management Strategy Tier 3

GV.RR — Roles, Responsibilities, and Authorities Tier 3

GV.PO — Policy Tier 3

GV.OV — Oversight Tier 3

GV.SC — Supply Chain Risk Management Tier 3

5. Function Assessment: IDENTIFY (ID)

IDENTIFY (ID)

Function Rating: Tier 3 — Repeatable

The Identify function ensures the organization understands its current cybersecurity risks. ALA maintains a comprehensive and continuously updated inventory of all digital assets through the Cloudflare management dashboard.

ID.AM — Asset Management Tier 4

ID.RA — Risk Assessment Tier 3

ID.IM — Improvement Tier 3

6. Function Assessment: PROTECT (PR)

PROTECT (PR)

Function Rating: Tier 3 — Repeatable

The Protect function implements safeguards to ensure delivery of critical services. ALA's cloud-native architecture inherits robust protections from Cloudflare while implementing application-level controls for data handling and access management.

PR.AA — Identity Management, Authentication, and Access Control Tier 3

PR.AT — Awareness and Training Tier 2

PR.DS — Data Security Tier 4

PR.PS — Platform Security Tier 4

PR.IR — Technology Infrastructure Resilience Tier 4

7. Function Assessment: DETECT (DE)

DETECT (DE)

Function Rating: Tier 3 — Repeatable

The Detect function enables timely discovery of cybersecurity events. ALA leverages Cloudflare's comprehensive analytics and monitoring capabilities as the primary detection mechanism, supplemented by application-level monitoring within Worker code.

DE.CM — Continuous Monitoring Tier 3

DE.AE — Adverse Event Analysis Tier 3

8. Function Assessment: RESPOND (RS)

RESPOND (RS)

Function Rating: Tier 3 — Repeatable

The Respond function ensures appropriate action is taken regarding detected cybersecurity incidents. ALA maintains documented incident response procedures leveraging both automated Cloudflare protections and manual intervention capabilities.

RS.MA — Incident Management Tier 3

RS.AN — Incident Analysis Tier 3

RS.CO — Incident Response Reporting and Communication Tier 3

RS.MI — Incident Mitigation Tier 3

9. Function Assessment: RECOVER (RC)

RECOVER (RC)

Function Rating: Tier 3 — Repeatable

The Recover function ensures timely restoration of services and capabilities impaired by cybersecurity incidents. ALA maintains a comprehensive, automated backup and recovery system that provides multiple layers of data protection.

RC.RP — Incident Recovery Plan Execution Tier 4

RC.CO — Recovery Communication Tier 3

10. Summary Maturity Matrix

The following matrix summarizes the tier ratings assigned to each CSF 2.0 Function and Category based on the assessment findings documented in Sections 4 through 9.

Function Category Description Tier Rating
GOVERN (GV) — Overall: Tier 3
GV.OCOrganizational ContextTier 3
GV.RMRisk Management StrategyTier 3
GV.RRRoles, Responsibilities & AuthoritiesTier 3
GV.POPolicyTier 3
GV.OVOversightTier 3
GV.SCSupply Chain Risk ManagementTier 3
IDENTIFY (ID) — Overall: Tier 3
ID.AMAsset ManagementTier 4
ID.RARisk AssessmentTier 3
ID.IMImprovementTier 3
PROTECT (PR) — Overall: Tier 3
PR.AAIdentity Management, Authentication & Access ControlTier 3
PR.ATAwareness and TrainingTier 2
PR.DSData SecurityTier 4
PR.PSPlatform SecurityTier 4
PR.IRTechnology Infrastructure ResilienceTier 4
DETECT (DE) — Overall: Tier 3
DE.CMContinuous MonitoringTier 3
DE.AEAdverse Event AnalysisTier 3
RESPOND (RS) — Overall: Tier 3
RS.MAIncident ManagementTier 3
RS.ANIncident AnalysisTier 3
RS.COIncident Response Reporting & CommunicationTier 3
RS.MIIncident MitigationTier 3
RECOVER (RC) — Overall: Tier 3
RC.RPIncident Recovery Plan ExecutionTier 4
RC.CORecovery CommunicationTier 3

Tier Distribution Summary

Tier Count Percentage
Tier 4 — Adaptive523%
Tier 3 — Repeatable1673%
Tier 2 — Risk Informed14%
Tier 1 — Partial00%

11. Gap Analysis & Improvement Plan

The following gaps were identified during the assessment process, along with planned remediation activities and target completion dates.

Category Current Tier Gap Description Planned Remediation Target Goal Tier
PR.AT Tier 2 No formalized personal security training plan with completion tracking Create annual security training checklist; document completion dates; subscribe to SANS newsletters and Cloudflare security blog Q3 2026 Tier 3
RS.MA Tier 3 Incident response plan has not been tested through tabletop exercise Conduct annual tabletop exercise simulating data breach scenario; document results and lessons learned Q4 2026 Tier 3
DE.CM Tier 3 Alerting relies primarily on manual dashboard review; limited automated notifications Implement automated alerting via Cloudflare Notifications for error rate spikes, security events, and backup failures Q3 2026 Tier 4
GV.SC Tier 3 No formal vendor security review cadence documented Establish annual vendor security review calendar; document review of each subprocessor's SOC 2 reports and compliance certifications Q3 2026 Tier 3
RC.RP Tier 4 Disaster recovery testing is ad hoc Schedule semi-annual disaster recovery drill: restore from R2 backup to a test D1 database and verify data integrity Q4 2026 Tier 4

Priority Improvement Initiatives

  1. Automated Alerting Enhancement (Q3 2026) — Configure Cloudflare Notifications for real-time alerting on security events, error rate anomalies, and backup failures. This will reduce mean-time-to-detection (MTTD) for security events.
  2. Formalized Training Program (Q3 2026) — Establish a documented annual security awareness program with tracked completion, covering current threat landscape, phishing defense, secure development practices, and incident response procedures.
  3. Tabletop Exercise (Q4 2026) — Conduct the first annual tabletop incident response exercise, simulating a data breach scenario involving unauthorized access to assessment data. Document findings and update incident response procedures accordingly.
  4. Disaster Recovery Drill (Q4 2026) — Perform a controlled restoration from R2 backup to validate recovery procedures, measure actual recovery time, and verify data integrity.
  5. Third-Party Penetration Testing (2027 Target) — Engage a qualified third-party firm to conduct penetration testing of public-facing APIs and web applications to validate application-level security controls.

12. Attestation Statement

Self-Attestation of Cybersecurity Maturity

I, Timothy E. Parker, Founder and Chief Executive Officer of Advanced Learning Academy LLC, hereby attest that:

  1. The information provided in this self-assessment is accurate and complete to the best of my knowledge as of the date signed below.
  2. This assessment was conducted in good faith against the NIST Cybersecurity Framework 2.0, published by the National Institute of Standards and Technology (February 2024).
  3. All six CSF 2.0 Functions (Govern, Identify, Protect, Detect, Respond, Recover) and their associated Categories have been evaluated, with tier ratings assigned based on the current state of implementation.
  4. The overall organizational maturity has been assessed as Tier 3 — Repeatable, indicating that cybersecurity risk management practices are formally approved, expressed as policy, and regularly updated across the organization.
  5. Gaps identified during this assessment have been documented in Section 11, and remediation activities have been planned with target completion dates.
  6. This self-assessment is not a third-party audit or certification. It represents management's own evaluation of the organization's cybersecurity posture and should be interpreted accordingly.
  7. ALA is committed to continuous improvement of its cybersecurity posture and will conduct this assessment annually, or when significant changes occur to the organization's technology stack, threat landscape, or regulatory environment.

This attestation is made under the authority of the undersigned as the sole owner and executive officer of Advanced Learning Academy LLC.

Timothy E. Parker
Founder & Chief Executive Officer
Advanced Learning Academy LLC
Carmel, Indiana 46033

Appendix A: Subprocessor Security Summary

The following table summarizes the security certifications and compliance posture of ALA's three primary subprocessors. These certifications are verified annually as part of ALA's supply chain risk management activities.

Subprocessor Service Certifications & Compliance Data Processed
Cloudflare, Inc. Infrastructure (compute, storage, CDN, DNS, DDoS protection, WAF, SSL/TLS) FedRAMP Moderate Authorized
SOC 2 Type II
ISO 27001:2013
ISO 27701:2019
PCI DSS Level 1 (Service Provider)
HIPAA-eligible
C5 (Germany)
IRAP (Australia)
All application data, assessment results, user sessions
Stripe, Inc. Payment processing (credit/debit card transactions, invoicing) PCI DSS Level 1 (Service Provider)
SOC 2 Type II
ISO 27001:2013
SSAE 18
Payment card data (never touches ALA systems), transaction metadata
Mailgun (Sinch) Transactional email delivery (receipts, notifications, alerts) SOC 2 Type II
GDPR compliant
CCPA compliant
ISO 27001:2013
Email addresses, email content (transactional only)

Shared Responsibility Model

ALA operates under a shared responsibility model with Cloudflare as the primary infrastructure provider:

Security Domain Cloudflare Responsibility ALA Responsibility
Physical Security Data center physical access controls, environmental controls, surveillance N/A (no on-premise infrastructure)
Network Security DDoS mitigation, Anycast routing, BGP security, network segmentation Firewall rule configuration, rate limiting rules
Compute Security V8 isolate runtime, memory isolation, CPU sandboxing, runtime patching Application code security, input validation
Data Security Encryption at rest (AES-256), encryption in transit (TLS 1.3), key management Data classification, access control logic, data minimization
Identity & Access Cloudflare dashboard authentication, API token management MFA enablement, API key rotation, application-level auth
Monitoring Analytics, threat detection, WAF logs, DDoS event reporting Application logging, business logic monitoring, alert response
Backup & Recovery Platform availability, R2 durability (99.999999999%) Backup scheduling, retention policy, recovery testing
Compliance FedRAMP, SOC 2, ISO 27001, PCI DSS (platform level) Application-level compliance, privacy policies, data handling