Compliance · Cybersecurity framework
NIST CSF, the common language of risk.
A voluntary, outcome-based framework for organising and communicating cybersecurity risk management — six functions, from Govern to Recover.
- 6core functions
- 2.0released February 2024
- 4implementation tiers
NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework was created by the US National Institute of Standards and Technology for critical infrastructure and has become a global reference for describing a security programme. Version 2.0, released in February 2024, extends it to every organisation and adds Govern as a sixth function alongside Identify, Protect, Detect, Respond and Recover.
The framework does not prescribe controls. Its Core lists outcomes; Profiles describe your current and target state; Tiers — Partial, Risk-Informed, Repeatable, Adaptive — rate how rigorous your risk governance is. Informative references map each outcome to ISO 27001, NIST SP 800-53, CIS Controls and others, so the CSF works as the layer that ties your other frameworks together.
That makes it the natural tool for boards and executives: a current-versus-target profile across six functions is a risk conversation that non-specialists can follow, and one that regulators such as NIS2 supervisors recognise as credible governance.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Govern (GV)
Organisational context, risk-management strategy, roles and responsibilities, policy, oversight and cybersecurity supply-chain risk management — the function added in 2.0.
Identify (ID)
Asset management, risk assessment and improvement: knowing what you have, what threatens it and what to fix.
Protect (PR)
Identity management and access control, awareness and training, data security, platform security and technology-infrastructure resilience.
Detect (DE)
Continuous monitoring and adverse-event analysis to find compromises and anomalies quickly.
Respond (RS)
Incident management, analysis, reporting, communication and mitigation.
Recover (RC)
Incident-recovery plan execution and recovery communication to restore operations and confidence.
Profiles and Tiers
A Current Profile and a Target Profile for the outcomes that matter to you, and a Tier rating of governance maturity that drives the improvement roadmap.
The cost of getting it wrong
- Risk decisions made without a shared picture, so investment goes to the loudest problem rather than the largest exposure
- Weak answers to board, investor and customer questions about security posture
- Duplicated effort when ISO, SOC 2 and regulatory work run as separate projects
- For US supply-chain work, failing a customer's expectation of CSF alignment
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Current Profile
We assess each function and category against the CSF Core, interviewing owners and sampling evidence, to produce an honest current-state profile and Tier.
- 02
Target Profile and roadmap
With leadership we define the target state per category, prioritise the gaps by risk and cost, and set a 12–24 month roadmap.
- 03
Implementation
Our security team delivers the technical and governance work in the roadmap, mapped through informative references to ISO 27001, SP 800-53 or CIS as you need.
- 04
Measurement and reporting
Metrics per function and a board dashboard that shows movement from current to target over time.
- 05
Framework alignment
We use the CSF as the umbrella that keeps ISO 27001, SOC 2, PCI DSS and NIS2 evidence consistent and collected once.
Deliverables
- Current Profile and Tier assessment across the six functions
- Target Profile agreed with leadership
- Prioritised improvement roadmap with owners and budget ranges
- Mapping to the ISO 27001, SOC 2 and NIS2 controls you already run
- Board-level posture dashboard and reporting cadence
- Annual re-assessment
Questions we hear most
Is NIST CSF a certification?
No. It is a voluntary framework with no certification scheme. Its value is in structuring and communicating your programme, and in mapping to the certifications and regulations you do need.
What is new in CSF 2.0?
A sixth function, Govern, covering strategy, roles, policy, oversight and supply-chain risk; explicit applicability to all organisations, not only critical infrastructure; and expanded implementation examples and quick-start guides.
How does it compare with ISO 27001?
ISO 27001 is a certifiable management-system standard with defined controls; the CSF is an outcome framework you self-assess against. Many organisations use the CSF to talk to the board and ISO 27001 to prove it to customers — the two map cleanly.
Do we need it if we are pursuing NIS2 or SOC 2?
Not strictly, but a CSF profile gives you the structure to run those efforts from one plan, and Govern maps well to NIS2's management-accountability requirements.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.