Current Profile
All 106 outcomes scored, each with an evidence reference.
NIST CSF 2.0 assessment
We score your security program against the 106 outcomes in NIST CSF 2.0, agree with you where it should be, and write up the gap so a non-technical director can act on it. You get an assessment report: no one issues a CSF certificate.
What you get
All 106 outcomes scored, each with an evidence reference.
Each outcome you select is tied to a mission objective, a stakeholder expectation or a named threat.
Current against Target for each outcome, with every gap's risk written out, not implied by a color. Where PROTECT gaps come down to configuration, our infrastructure hardening work can follow on with a prioritized plan.
We agree the format with you at kickoff: a risk register, a risk detail report or a plan of action and milestones (POA&M), the examples NIST gives. If DETECT gaps lead, our threat detection support can pick them up.
Your current and target Tier. Tiers run from 1 (Partial) to 4 (Adaptive) and rate how deeply cyber risk is built into governance and decisions, not whether controls work, as the memo says on the same page. The board summary gives a six-function view and NIST's Section 5.1 communication flow from executive to manager to practitioner.
A crosswalk (mapping) to what you already run: ISO/IEC 27001:2022 via NIST's official mapping (OLIR), finalized in May 2025, plus SP 800-53 Rev 5, SP 800-171 Rev 3 and CIS Controls v8.1. You also get your Target Profile rewritten as requirements to send to suppliers (the GV.SC supply chain outcomes).
To run the plan, see risk management or risk management as a Service.
What changed in 2.0
Version 2.0 didn't add controls. The framework got smaller.
NIST published CSF 2.0 as CSWP 29 on 26 February 2024, and it is still the current version. Version 1.1 had five functions, 23 categories and 108 subcategories; 2.0 has six, 22 and 106. NIST calls them outcomes, never controls.
The new GOVERN function wraps the other five, whose names date from the 2014 original. Its six categories are Organizational Context; Risk Management Strategy; Roles, Responsibilities and Authorities; Policy; Oversight; and Cybersecurity Supply Chain Risk Management. In 1.1 most of this sat inside IDENTIFY, as ID.GV and ID.SC, and organizations skipped it.
Counted from Appendix A of CSWP 29, the outcomes split GOVERN 31, IDENTIFY 21, PROTECT 22, DETECT 11, RESPOND 13 and RECOVER 8. GOVERN alone is almost as big as DETECT, RESPOND and RECOVER combined.
Plenty of companies run firewalls, logging, backups and a rehearsed incident plan reasonably well. Many can't show a documented risk appetite (how much risk the business accepts), a named owner of cyber risk or a board reporting line.
Where this work goes wrong
You can sit at Tier 3 with weak technical hygiene, and a Tier 4 board slide implies an assurance nobody tested. CSWP 29 says moving up is warranted only where risk, mandate or cost-benefit justifies it.
NIST says the Core isn't a checklist. A Current Profile shows how, and to what extent, each outcome is achieved. Pass or fail scoring throws away partial achievement and relative priority.
Supply chain (GV.SC) evidence is supplier contract clauses, third-party tiering and offboarding, held by procurement, legal and vendor management. A CISO's recollection isn't evidence, and the first real customer questionnaire contradicts it. See also third-party risk management.
The Core was restructured, not extended. IDENTIFY dropped from six categories to three. PR.AC became PR.AA. PR.IP, PR.MA, PR.PT, DE.DP, RS.RP, RS.IM and RC.IM are gone as categories, and their content was redistributed. ID.IM is new. NIST publishes a CSF 1.1 to 2.0 Core Transition Changes Overview spreadsheet because a simple remap leaves whole outcomes unassessed and counts others twice.
How an assessment runs
The steps are from Section 3.1 of CSWP 29. For a mid-sized organization, a first assessment usually takes eight to fourteen weeks. The slow part is getting answers from people outside security, such as procurement.
A scoping document records what the Profile covers and the assumptions behind it. Skipping it is the most common cause of a disputed assessment.
Evidence for all 106 outcomes, reusing whatever still holds.
The Current Profile, scored against its evidence, then the Target Profile and Tier workshops.
Current against Target, gap by gap, then the prioritized action plan.
Closing the gaps is a separate program, usually 12 to 24 months, paced by budget cycles and hiring. For help running it, see GRC as a Service.
Certificate or assessment
NIST doesn't certify, accredit, register or endorse anyone against the CSF. If someone told you to get NIST CSF compliant, they probably meant ISO 27001.
| NIST CSF 2.0 | ISO/IEC 27001:2022 | |
|---|---|---|
| What the document contains | 106 outcome statements across six functions. No "shalls", clauses or controls. | Management system requirements in clauses 4 to 10, plus 93 Annex A controls in four themes. |
| Question it answers | Where should next year's security budget go, and how do I defend that to the board? | Can I prove to a third party that a security management system exists and works? |
| Proof at the end | An assessment report, signed by us as the assessor. | A certificate, signed by an accredited certification body and no one else. |
| Can you fail it? | No. There's no threshold, only a Current Profile further from Target than you'd like. | Yes. Nonconformities are raised and must be closed. |
| Scopes you can hold | As many Profiles as you want: whole entity, one business line, ransomware only. | One certified scope per certificate. |
| Partial achievement | Expected. The Core is built to express it. | Not a category. A control is implemented or it isn't. |
| Cost of the document | Free, with the Quick-Start Guides and the CSF 2.0 Reference Tool. | Bought from ISO or a national standards body. |
If a contract demands a certificate, it wants ISO/IEC 27001, issued only by an accredited certification body, or a SOC 2 report, written only by a licensed CPA firm.
There is no accreditation body, auditor licensing scheme, register or expiry date. That fits NIST's role under the Cybersecurity Enhancement Act of 2014 as facilitator of a voluntary, industry-led framework, and CSWP 29 doesn't prescribe outcomes or how they may be achieved.
HITRUST CSF shares three letters with NIST CSF, but it is a separate, certifiable program with its own scoring and assessors. For health data, see our ePHI security controls.
What this work does not include. A certificate. We are not a certification body or a CPA firm, our report carries no NIST logo, and we hold no certificate of our own. We work remotely from India.
No, and neither can anyone else. NIST doesn't operate a conformity assessment scheme for the CSF, so there's no accreditation body standing behind any certificate you might be offered against it. What exists is a self-assessment you run yourself, which is legitimate and free, or an independent assessment report from a firm like ours. Private schemes such as HITRUST layer a certification on top of their own program and describe it as demonstrating alignment with CSF 2.0. Read the wording on that certificate carefully, because it certifies against that scheme rather than against NIST.
Eight to fourteen weeks for a mid-sized organization, roughly 200 to 2,000 staff with one or two regulated business lines. Scoping and stakeholder alignment, one to two weeks. Evidence gathering across all 106 subcategories, three to five. Scoring and Current Profile production, two. Target Profile and Tier workshops, one to two. Gap analysis and roadmap, two to three.
About half of it isn't duplicated at all. NIST finalized the official ISO/IEC 27001:2022 to CSF 2.0 Informative Reference in May 2025, and a working ISMS hands you most of the evidence for PROTECT, DETECT, RESPOND and RECOVER. Where the two genuinely diverge is GOVERN. Annex A won't make you state a risk appetite in a form a director can approve, and it won't hand you a Target Profile you can send to a supplier. That difference is the part worth paying for, and it's why we scope certified clients differently and charge less for evidence gathering.
No. CSWP 29 was published on 26 February 2024 and that's a publication date, not a compliance date. The framework is voluntary and there's no enforcement mechanism behind it, in any jurisdiction. For Indian firms the real deadline was SEBI CSCRF compliance: 31 August 2025 for all regulated entities except MIIs, KRAs and QRTAs, with no further blanket extension.
No. CMMC is built on NIST SP 800-171. FedRAMP and FISMA run on SP 800-53 with the Risk Management Framework. Different documents, different assessment objectives, different assessors, and CSF work doesn't advance any of them. The same answer applies to HIPAA: you're measured against the Security Rule itself, and the CSF can inform that work without satisfying it.
It feeds directly into CSCRF work, if CSCRF applies to you. SEBI's Cybersecurity and Cyber Resilience Framework, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024, is built on the same six CSF 2.0 functions and adds five resilience goals on top: Anticipate, Withstand, Contain, Recover, Evolve. Applicability is set by the circular's own annexure, which bands regulated entities into categories with graded obligations, so confirm your band first. Compliance dates closed on 31 August 2025 for all regulated entities except MIIs, KRAs and QRTAs. What's live now is the recurring cycle of periodic vulnerability assessment and testing, cyber audits and reporting.
Tier 3, almost always. Tier 4 Adaptive isn't the default destination, and CSWP 29 sets a justification bar for climbing that most organizations don't clear. Tiers describe the rigor of your risk governance, not the strength of your controls, so a Tier 4 target usually means somebody has read the table as a maturity ladder. If a regulator names a Tier for you, that settles it. Otherwise we'll ask what decision the Tier is supposed to inform, and if there isn't one, we'll leave it as context and put the Target Profile at the center of the report instead.
Yes, and you probably should. NIST explicitly allows an organization to hold several Profiles at different scopes: whole entity, financial systems, ransomware only. An enterprise-wide Profile takes roughly twice as long as one scoped to a business line. Where a published Community Profile exists we'll use it as the seed rather than starting from a blank Core, for instance NIST IR 8374 Revision 1 for ransomware, finalized on 11 June 2026.
Let's talk
Send us your intended scope and whatever exists: an ISO certificate, a SOC 2 report, an old 1.1 assessment or a spreadsheet. We'll tell you what's reusable, what needs fresh evidence, and which GOVERN outcomes need people outside security. We reply within one working day.