Compliance · Cybersecurity framework

NIST CSF, the common language of risk.

A voluntary, outcome-based framework for organising and communicating cybersecurity risk management — six functions, from Govern to Recover.

  • 6core functions
  • 2.0released February 2024
  • 4implementation tiers
What it is

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework was created by the US National Institute of Standards and Technology for critical infrastructure and has become a global reference for describing a security programme. Version 2.0, released in February 2024, extends it to every organisation and adds Govern as a sixth function alongside Identify, Protect, Detect, Respond and Recover.

The framework does not prescribe controls. Its Core lists outcomes; Profiles describe your current and target state; Tiers — Partial, Risk-Informed, Repeatable, Adaptive — rate how rigorous your risk governance is. Informative references map each outcome to ISO 27001, NIST SP 800-53, CIS Controls and others, so the CSF works as the layer that ties your other frameworks together.

That makes it the natural tool for boards and executives: a current-versus-target profile across six functions is a risk conversation that non-specialists can follow, and one that regulators such as NIS2 supervisors recognise as credible governance.

The requirements

What the framework demands

The obligations an auditor or supervisor will test, in plain language.

Govern (GV)

Organisational context, risk-management strategy, roles and responsibilities, policy, oversight and cybersecurity supply-chain risk management — the function added in 2.0.

Identify (ID)

Asset management, risk assessment and improvement: knowing what you have, what threatens it and what to fix.

Protect (PR)

Identity management and access control, awareness and training, data security, platform security and technology-infrastructure resilience.

Detect (DE)

Continuous monitoring and adverse-event analysis to find compromises and anomalies quickly.

Respond (RS)

Incident management, analysis, reporting, communication and mitigation.

Recover (RC)

Incident-recovery plan execution and recovery communication to restore operations and confidence.

Profiles and Tiers

A Current Profile and a Target Profile for the outcomes that matter to you, and a Tier rating of governance maturity that drives the improvement roadmap.

What's at stake

The cost of getting it wrong

  • Risk decisions made without a shared picture, so investment goes to the loudest problem rather than the largest exposure
  • Weak answers to board, investor and customer questions about security posture
  • Duplicated effort when ISO, SOC 2 and regulatory work run as separate projects
  • For US supply-chain work, failing a customer's expectation of CSF alignment
Typical timeline4–8 weeks for the profile and roadmap; implementation phased over 12–24 months
How we help

From gap to evidence

Assessment, remediation, documentation and audit support — run as one programme.

  1. 01

    Current Profile

    We assess each function and category against the CSF Core, interviewing owners and sampling evidence, to produce an honest current-state profile and Tier.

  2. 02

    Target Profile and roadmap

    With leadership we define the target state per category, prioritise the gaps by risk and cost, and set a 12–24 month roadmap.

  3. 03

    Implementation

    Our security team delivers the technical and governance work in the roadmap, mapped through informative references to ISO 27001, SP 800-53 or CIS as you need.

  4. 04

    Measurement and reporting

    Metrics per function and a board dashboard that shows movement from current to target over time.

  5. 05

    Framework alignment

    We use the CSF as the umbrella that keeps ISO 27001, SOC 2, PCI DSS and NIS2 evidence consistent and collected once.

What you get

Deliverables

  • Current Profile and Tier assessment across the six functions
  • Target Profile agreed with leadership
  • Prioritised improvement roadmap with owners and budget ranges
  • Mapping to the ISO 27001, SOC 2 and NIS2 controls you already run
  • Board-level posture dashboard and reporting cadence
  • Annual re-assessment
FAQ

Questions we hear most

Is NIST CSF a certification?

No. It is a voluntary framework with no certification scheme. Its value is in structuring and communicating your programme, and in mapping to the certifications and regulations you do need.

What is new in CSF 2.0?

A sixth function, Govern, covering strategy, roles, policy, oversight and supply-chain risk; explicit applicability to all organisations, not only critical infrastructure; and expanded implementation examples and quick-start guides.

How does it compare with ISO 27001?

ISO 27001 is a certifiable management-system standard with defined controls; the CSF is an outcome framework you self-assess against. Many organisations use the CSF to talk to the board and ISO 27001 to prove it to customers — the two map cleanly.

Do we need it if we are pursuing NIS2 or SOC 2?

Not strictly, but a CSF profile gives you the structure to run those efforts from one plan, and Govern maps well to NIS2's management-accountability requirements.

Get Started

Ready to Transform Your Business?

Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.