NIST Cybersecurity Framework

We help your team use NIST CSF 2.0 to set a target profile, find gaps, implement controls and keep evidence that shows progress.

On this page

What the framework is

The NIST Cybersecurity Framework (CSF) is voluntary guidance from the US National Institute of Standards and Technology. It describes cybersecurity outcomes an organization can aim for, and leaves the choice of tools and procedures to each organization. NIST released version 2.0 in February 2024. It widened the audience from critical infrastructure to organizations of any size or sector and added a Govern function.

Organizations use the CSF to describe their current security posture, agree on a target state and explain priorities to leadership, boards, customers and regulators. Some adopt it because a customer, insurer or sector regulator expects it. NIST does not certify organizations against the CSF, so the result of the work is a documented profile, an improved control set and evidence of progress.

Key facts about CSF 2.0

Six functions

Govern, Identify, Protect, Detect, Respond and Recover. Each function breaks down into categories and subcategories that describe specific outcomes.

Govern function

New in 2.0. It covers risk strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management.

Organizational profiles

A current profile records the outcomes you achieve today. A target profile records the outcomes you plan to reach. The gap between them drives the plan.

Tiers

Four tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your cybersecurity risk governance and management practices are.

Voluntary use

The CSF is voluntary guidance. There is no CSF certification or accredited audit. Contracts or sector rules may still ask you to show alignment.

Related catalogs

NIST SP 800-53 is a detailed catalog of security and privacy controls. NIST SP 800-171 covers protection of controlled unclassified information in nonfederal systems. Both can serve as references for implementing CSF outcomes.

How the work runs with us

We agree on the business units, systems, data and suppliers in scope. We confirm why your team is using the CSF, for example a customer request, a board report or a regulator, because that shapes the target profile. You receive a scope statement and a plan with dates.

What you receive

Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.

Profiles

  • Current profile for the subcategories in scope
  • Target profile agreed with your team
  • Current and target tier with reasoning

Gap assessment

  • Gaps listed by function and category
  • Risk and effort rating for each gap
  • Owner suggested for each item

Remediation plan

  • Prioritized actions with dependencies
  • Controls we implement and controls your team owns
  • Dates agreed during scoping

Evidence and reporting

  • Outcome to control to evidence mapping
  • Control test results
  • Summary suitable for leadership or a board

Control areas we help implement

These areas support outcomes across the six functions. We work inside your existing tools where possible.

Asset and data inventory

Hardware, software, cloud services and data flows recorded with owners. This supports the Identify function.

Identity and access

Single sign-on, multi-factor authentication, least privilege and access reviews. We can deploy Keycloak privately where it fits.

Logging and monitoring

Central log collection, alert rules and triage routines for the Detect function. We can deploy Wazuh privately where it fits.

Vulnerability management

Scanning, patch timelines and tracking of exceptions. Penetration testing can confirm results.

Incident response

Response plan, roles, contact lists and exercises. We also offer incident response training.

Backup and recovery

Backup coverage, encryption, restore tests and recovery targets for critical services.

Supplier risk

Supplier inventory, security review steps and contract requirements for the Govern function.

Encryption

Encryption of data at rest and in transit, with key ownership and rotation recorded.

NIST CSF compared with ISO/IEC 27001

Many organizations use both. The CSF describes outcomes. ISO/IEC 27001 sets requirements for a management system that can be certified.

TopicNIST CSF 2.0ISO/IEC 27001
PublisherNIST, a US federal agencyISO and IEC, international standards bodies
NatureVoluntary framework of outcomesStandard with requirements for an information security management system
StructureSix functions with categories and subcategoriesManagement system clauses plus an Annex A list of controls
CertificationNoneCertification by an accredited certification body
Cost to obtainFree to downloadPurchased from ISO or a national standards body
Common useDescribing posture and priorities, reporting to leadershipShowing customers an independently audited security program

Who does what

We scope the work, assess the current state, recommend the target profile, implement agreed controls, organize evidence and test controls. Your team owns the risk decisions, approves the target profile, runs the controls day to day and keeps evidence current.

NIST publishes the framework and does not certify or audit organizations. Where a customer, insurer or regulator asks you to show alignment, they decide what evidence they accept. We help prepare that evidence and can join calls to explain how it was produced. We work alongside your compliance platform and any assessor you engage.

Common questions

How long does it take?

It depends on the number of systems, business units and suppliers in scope, and on how much remediation is needed. We agree a plan with dates during scoping.

Can we get certified against the NIST CSF?

No. NIST does not offer certification for the CSF. We help you document alignment and keep evidence that customers, insurers or regulators can review. If you need a certificate, ISO/IEC 27001 is a common choice, and the work overlaps.

Do we need to implement every subcategory?

No. The CSF expects each organization to choose outcomes based on its risk, mission and resources. Your target profile records which outcomes apply and how far you plan to go.

Do you work with our existing tools and compliance platform?

Yes. We map evidence into the platform you already use and improve the tools you have before suggesting new ones.

Can you sign an NDA?

Yes. We sign an NDA on request before reviewing documents or systems.

Can you support us after the first engagement?

Yes. Engagements have a fixed scope, and we offer retainers for ongoing support such as profile updates, control testing and evidence upkeep.

How to prepare

Gather what you already have: an asset or system list, network and data flow diagrams, current policies, a list of key suppliers, and any recent audit, assessment or penetration test reports.

Name an internal owner for the work and the people who own identity, infrastructure, security operations and supplier management. Note the reason for using the CSF and any customer or regulator request, so the target profile reflects it.

CSF tiers at a glance

Tiers describe the rigor of cybersecurity risk governance and management. NIST does not require any organization to reach a particular tier. Your team picks a target tier that fits its risk and resources.

TierNameSummary
1PartialRisk management is ad hoc and reactive. Awareness of cybersecurity risk is limited.
2Risk InformedManagement approves risk practices, but they may not be applied across the whole organization.
3RepeatableRisk practices are approved as policy and applied consistently, and they are updated as risks change.
4AdaptiveThe organization adapts its practices based on lessons learned and indicators, and risk is part of the culture.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.