What the framework is
The NIST Cybersecurity Framework (CSF) is voluntary guidance from the US National Institute of Standards and Technology. It describes cybersecurity outcomes an organization can aim for, and leaves the choice of tools and procedures to each organization. NIST released version 2.0 in February 2024. It widened the audience from critical infrastructure to organizations of any size or sector and added a Govern function.
Organizations use the CSF to describe their current security posture, agree on a target state and explain priorities to leadership, boards, customers and regulators. Some adopt it because a customer, insurer or sector regulator expects it. NIST does not certify organizations against the CSF, so the result of the work is a documented profile, an improved control set and evidence of progress.
Key facts about CSF 2.0
Six functions
Govern, Identify, Protect, Detect, Respond and Recover. Each function breaks down into categories and subcategories that describe specific outcomes.
Govern function
New in 2.0. It covers risk strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management.
Organizational profiles
A current profile records the outcomes you achieve today. A target profile records the outcomes you plan to reach. The gap between them drives the plan.
Tiers
Four tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your cybersecurity risk governance and management practices are.
Voluntary use
The CSF is voluntary guidance. There is no CSF certification or accredited audit. Contracts or sector rules may still ask you to show alignment.
Related catalogs
NIST SP 800-53 is a detailed catalog of security and privacy controls. NIST SP 800-171 covers protection of controlled unclassified information in nonfederal systems. Both can serve as references for implementing CSF outcomes.
How the work runs with us
We agree on the business units, systems, data and suppliers in scope. We confirm why your team is using the CSF, for example a customer request, a board report or a regulator, because that shapes the target profile. You receive a scope statement and a plan with dates.
We interview owners, review configurations and documents, and record a current profile against the CSF subcategories in scope. We then work with your team to set a target profile and a target tier, and list the gaps with their risk and effort.
We turn the gaps into a prioritized remediation plan. Our engineers implement or improve technical controls such as identity and access, logging and monitoring, vulnerability management and backups. We update policies and procedures where they are missing or out of date.
We map each outcome to the control that supports it and the evidence that shows it operates. We test selected controls and update the current profile so leadership, customers or assessors can see progress. Retainers are available for ongoing support.
What you receive
Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.
Profiles
- Current profile for the subcategories in scope
- Target profile agreed with your team
- Current and target tier with reasoning
Gap assessment
- Gaps listed by function and category
- Risk and effort rating for each gap
- Owner suggested for each item
Remediation plan
- Prioritized actions with dependencies
- Controls we implement and controls your team owns
- Dates agreed during scoping
Evidence and reporting
- Outcome to control to evidence mapping
- Control test results
- Summary suitable for leadership or a board
Control areas we help implement
These areas support outcomes across the six functions. We work inside your existing tools where possible.
Asset and data inventory
Hardware, software, cloud services and data flows recorded with owners. This supports the Identify function.
Identity and access
Single sign-on, multi-factor authentication, least privilege and access reviews. We can deploy Keycloak privately where it fits.
Logging and monitoring
Central log collection, alert rules and triage routines for the Detect function. We can deploy Wazuh privately where it fits.
Vulnerability management
Scanning, patch timelines and tracking of exceptions. Penetration testing can confirm results.
Incident response
Response plan, roles, contact lists and exercises. We also offer incident response training.
Backup and recovery
Backup coverage, encryption, restore tests and recovery targets for critical services.
Supplier risk
Supplier inventory, security review steps and contract requirements for the Govern function.
Encryption
Encryption of data at rest and in transit, with key ownership and rotation recorded.
NIST CSF compared with ISO/IEC 27001
Many organizations use both. The CSF describes outcomes. ISO/IEC 27001 sets requirements for a management system that can be certified.
| Topic | NIST CSF 2.0 | ISO/IEC 27001 |
|---|---|---|
| Publisher | NIST, a US federal agency | ISO and IEC, international standards bodies |
| Nature | Voluntary framework of outcomes | Standard with requirements for an information security management system |
| Structure | Six functions with categories and subcategories | Management system clauses plus an Annex A list of controls |
| Certification | None | Certification by an accredited certification body |
| Cost to obtain | Free to download | Purchased from ISO or a national standards body |
| Common use | Describing posture and priorities, reporting to leadership | Showing customers an independently audited security program |
Who does what
We scope the work, assess the current state, recommend the target profile, implement agreed controls, organize evidence and test controls. Your team owns the risk decisions, approves the target profile, runs the controls day to day and keeps evidence current.
NIST publishes the framework and does not certify or audit organizations. Where a customer, insurer or regulator asks you to show alignment, they decide what evidence they accept. We help prepare that evidence and can join calls to explain how it was produced. We work alongside your compliance platform and any assessor you engage.
Common questions
How long does it take?
It depends on the number of systems, business units and suppliers in scope, and on how much remediation is needed. We agree a plan with dates during scoping.
Can we get certified against the NIST CSF?
No. NIST does not offer certification for the CSF. We help you document alignment and keep evidence that customers, insurers or regulators can review. If you need a certificate, ISO/IEC 27001 is a common choice, and the work overlaps.
Do we need to implement every subcategory?
No. The CSF expects each organization to choose outcomes based on its risk, mission and resources. Your target profile records which outcomes apply and how far you plan to go.
Do you work with our existing tools and compliance platform?
Yes. We map evidence into the platform you already use and improve the tools you have before suggesting new ones.
Can you sign an NDA?
Yes. We sign an NDA on request before reviewing documents or systems.
Can you support us after the first engagement?
Yes. Engagements have a fixed scope, and we offer retainers for ongoing support such as profile updates, control testing and evidence upkeep.
How to prepare
Gather what you already have: an asset or system list, network and data flow diagrams, current policies, a list of key suppliers, and any recent audit, assessment or penetration test reports.
Name an internal owner for the work and the people who own identity, infrastructure, security operations and supplier management. Note the reason for using the CSF and any customer or regulator request, so the target profile reflects it.
CSF tiers at a glance
Tiers describe the rigor of cybersecurity risk governance and management. NIST does not require any organization to reach a particular tier. Your team picks a target tier that fits its risk and resources.
| Tier | Name | Summary |
|---|---|---|
| 1 | Partial | Risk management is ad hoc and reactive. Awareness of cybersecurity risk is limited. |
| 2 | Risk Informed | Management approves risk practices, but they may not be applied across the whole organization. |
| 3 | Repeatable | Risk practices are approved as policy and applied consistently, and they are updated as risks change. |
| 4 | Adaptive | The organization adapts its practices based on lessons learned and indicators, and risk is part of the culture. |

