top of page
Blue Light Gradient

NIST Cybersecurity Framework (CSF 2.0) 

We turn NIST CSF 2.0 into an operating cybersecurity programme, from Current Profile and governance assessment through Target Profile, prioritised remediation and evidence, to board reporting and continuous maturity improvement. Delivered inside your existing security, risk and GRC environment.

Built by compliance practitioners

Expert Guidance Through Every Stage of Your NIST CSF 2.0 Programme

wired-gradient-457-shield-security (2).gif

Framework depth

CSF 2.0 is applied as NIST designed it: outcomes across Govern, Identify, Protect, Detect, Respond and Recover are assessed in the context of your risk strategy, current and target Profiles and organisational maturity. We do not turn a flexible risk framework into an artificial one-size-fits-all checklist.

wired-gradient-204-chat-message-heart.gif

One record, every output

Current Profile, Target Profile, gaps, risks, owners, evidence, decisions and remediation are maintained in one programme. Board reporting, customer assurance, ISO 27001 mapping, regulatory assessments and future maturity reviews can therefore draw from the same controlled record.

wired-gradient-1103-confetti (3).gif

No invented certification

NIST CSF is a voluntary cybersecurity risk-management framework, not a certification standard issued by NIST. We can provide independent assessment and implementation support, but we do not sell a meaningless NIST certificate. The value is a defensible Profile, prioritised risk treatment and evidence that the programme is operating.

Compliance practitioners since 2013

download (6).png
download.png
download (4).png
download (5).png
kpmg-logo.webp
download (2).png
download_edited.jpg
download (8).png
download (3).png
hryze pics6.jpg
unnamed.jpg
favicon2.png
pay-construct-logo_edited.jpg
mxxg7axrzaxavyb17cgh.webp
download (1).png
download (7).png
download.jpg
bai logo.png

Why firms use us for NIST CSF 2.0

The board needs one cybersecurity view

Security programmes often contain dozens of technical tools and control libraries without one clear view of business risk. CSF 2.0 gives leadership a common language for governance, current posture, target outcomes and prioritised investment.

The framework has been treated as a scorecard

A percentage score against a spreadsheet can create false precision. NIST CSF is outcome-based and should be used to understand and prioritise cybersecurity risk, not to chase 100 percent completion of controls that may not be equally relevant to the organisation.

Governance is now explicit

CSF 2.0 added Govern as a core Function and broadened the framework for organisations of all sizes and sectors. Cybersecurity strategy, risk appetite, roles, policy, oversight and supply-chain risk therefore sit visibly alongside technical protection and incident capabilities.

Multiple frameworks need one control environment

Many organisations need NIST CSF for customers or board governance while also operating ISO 27001, SOC 2, DORA, NIS2 or sector-specific requirements. Mapping the outcomes to one underlying control and evidence environment prevents parallel programmes from competing for the same teams.

One programme. Every output.

The Current Profile shows where you are. The Target Profile defines where you need to be. The gap between them becomes a risk-based roadmap rather than a generic security shopping list.

Current Profile

An evidence-based view of existing cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover, with strengths and gaps recorded.

Target Profile

The outcomes the organisation needs to achieve based on business objectives, threats, customer commitments, regulatory obligations and risk appetite.

Implementation Tier context

A view of the rigor of cybersecurity risk governance and management using the NIST Tiers as context, without misusing them as a simplistic maturity score.

Prioritised roadmap

Gaps converted into actions with risk rationale, owners, dependencies, milestones and evidence requirements so investment follows business importance.

Assurance record

A reusable set of mappings, evidence and management information supporting customer diligence, board oversight and cross-framework compliance.

Our simple three-step process

We help technology, financial services, regulated and enterprise organisations apply NIST CSF 2.0 as a practical cybersecurity governance framework.

Step 1: Current Profile and Risk Context

We understand the business, threat environment, obligations and existing control environment, then assess current outcomes across the six CSF Functions.

Step 2: Target Profile and Implementation

We agree the target outcomes, prioritise gaps and work with owners to implement governance, technical and operational improvements with evidence attached to each action.

Step 3: Assurance and Continuous Improvement

We re-assess outcomes, report progress to management and the board, maintain cross-framework mappings and refresh the Target Profile as the business and threat environment change.

Our NIST CSF 2.0 services

Full end-to-end support.

NIST CSF assessment

We assess current outcomes across all six Functions and produce an evidence-based Current Profile rather than an unsupported self-score.

Target Profile and roadmap

We define the target state against business risk and obligations, then prioritise the changes that matter most.

Governance implementation

We strengthen strategy, policy, roles, risk oversight, supply-chain governance and board information under the Govern Function.

Control and capability remediation

We work with security, technology and operational teams to close material gaps across Identify, Protect, Detect, Respond and Recover.

Cross-framework mapping

We map NIST CSF outcomes to ISO 27001, SOC 2 and relevant regulatory requirements so one control environment serves multiple assurance needs.

Continuous maturity assurance

We maintain Profiles, review evidence, measure remediation and update priorities as threats, systems and business objectives change.

Neon Lights_edited.jpg

Our People

Our security assurance team combines cybersecurity governance, information security, operational risk and regulatory compliance experience. The same practitioners who advise regulated firms understand that NIST CSF has to connect security engineering with business governance, supplier risk, resilience, incident management and board accountability.

When you work with us, you gain direct access to senior professionals rather than an account manager. The programme is run by people who can challenge the evidence behind a security outcome and translate technical gaps into decisions that management can fund and own.

Key information and requirements for
NIST Cybersecurity Framework (CSF 2.0)

Key information

What NIST CSF 2.0 is The NIST Cybersecurity Framework 2.0 is a voluntary framework published by the US National Institute of Standards and Technology to help organisations understand, assess, prioritise and communicate cybersecurity risk. It is designed for organisations of any size, sector or maturity. The framework is especially useful where the organisation needs a common language between security specialists and business leadership. It allows technical activity to be discussed as business outcomes and risk priorities rather than as disconnected tool metrics.

Six Core Functions. CSF 2.0 organises cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover. Govern was added as a distinct Function in version 2.0 to put cybersecurity strategy, policy, roles, oversight and supply-chain risk at the centre of the framework. The six Functions are intentionally connected. Weak governance can undermine every other Function, while lessons from incidents and recovery should feed back into identification, protection and future governance decisions.

Organisational Profiles. A Current Profile describes the cybersecurity outcomes the organisation is achieving today, while a Target Profile describes the outcomes it wants or needs to achieve. Comparing them provides a structured way to identify and prioritise gaps. Profiles should be sufficiently specific to guide action without becoming an unmanageable control catalogue. They can also incorporate sector or community Profiles where those provide useful shared outcomes for a particular environment.

Implementation Tiers. NIST defines four Tiers: Partial, Risk Informed, Repeatable and Adaptive. The Tiers characterise the rigor of cybersecurity risk governance and management practices and can provide context for Profiles. They should not be treated as a certification grade or a requirement that every organisation reach Tier 4. Tiers are best used to discuss how consistently and systematically risk is governed, including third-party risk. We use them as context for decision-making rather than converting them into an unsupported maturity number with false precision.

Outcome-based, not prescriptive. The CSF describes cybersecurity outcomes rather than mandating one technology stack or control implementation. Organisations can use NIST references and other control frameworks to determine how the outcomes will be achieved. Implementation Examples and Informative References can then help teams determine practical ways to achieve an outcome. This preserves the flexibility of CSF while allowing detailed technical standards and control catalogues to sit underneath it.

No NIST CSF certification. NIST does not certify organisations against CSF 2.0. A third party can assess alignment or maturity, but any such assurance should be described accurately rather than presented as an official NIST certification. Organisations should be cautious of providers advertising an official NIST CSF certification. Independent assurance can still be valuable, but the claim should accurately describe the assessment method, scope and evidence rather than imply endorsement by NIST.

Cross-framework use. CSF can be used as a strategic risk framework while ISO 27001, SOC 2, NIST SP 800-series controls or sector regulation provide more detailed requirements in particular areas. The mappings should support a single risk and control architecture rather than multiply paperwork. This makes CSF useful as the organising layer across a mixed assurance environment. The same risk and control evidence can be presented through the language of different frameworks without forcing security teams to maintain several separate realities.

Our services

Scoping and risk context. Business services, systems, threats, regulatory obligations and customer commitments identified so the Profile is grounded in actual risk.

Current Profile assessment. Outcomes assessed across all six Functions with evidence, observations and gaps recorded.

Target Profile design. Target outcomes set according to risk appetite, strategy, sector expectations and available resources.

Roadmap and implementation. Gaps prioritised and converted into governance, process and technical actions with owners, milestones and evidence.

Cross-framework mapping. NIST outcomes mapped to ISO 27001, SOC 2, regulatory requirements and existing control libraries where this reduces duplication.

Executive and board reporting. Cybersecurity posture translated into concise risk, progress and investment information for decision-makers.

Continuous assurance. Profile refresh, evidence review, control testing and reprioritisation as the threat and business environment changes.

What we provide

Current and Target Profiles. Evidence-based records showing current outcomes, target outcomes and the rationale behind the target state.

Gap and risk analysis. Prioritised gaps tied to business impact, threats and existing risk decisions.

Implementation roadmap. Actions, owners, dates, dependencies and evidence requirements across the six Functions.

Assurance and reporting. Management information, board reporting and evidence packs supporting customer and regulatory reviews.

Continuous improvement. Periodic reassessment, Profile refresh and integration of new risks, systems and obligations.

Other important information

CSF 2.0 is not only for US critical infrastructure. Version 2.0 explicitly broadened the framework for organisations of all sizes and sectors and is used internationally as a cybersecurity governance reference. This broader positioning makes CSF particularly useful for UK and European organisations with US customers or global cyber programmes. It can sit above local regulation without being limited to one jurisdiction.

Other important information

NIST CSF 2.0 is a framework, not a certification. NIST does not issue certificates to organisations using the CSF.

Govern is now a Core Function. Cybersecurity strategy, accountability, policy and supply-chain risk are explicitly part of the framework.

Profiles make the framework practical. Current and Target Profiles turn broad outcomes into an organisation-specific view of priorities and gaps.

Tiers provide context, not a universal score. The right target depends on risk and business need rather than automatically aiming for Tier 4 everywhere.

Our Security Assurance Publications

Frequently Asked Questions about NIST CSF 2.0

What is NIST CSF 2.0?

NIST CSF 2.0 is the current version of the Cybersecurity Framework published by the US National Institute of Standards and Technology. It provides a common language of cybersecurity outcomes that organisations can use to understand, assess, prioritise and communicate cyber risk. Version 2.0 is designed for organisations of any size and sector, not only critical infrastructure. Organisations can adopt only the parts and level of detail that help them manage their risks while still using the common CSF vocabulary. That flexibility is one of the reasons the framework works across very different sectors and organisational sizes.

What are the six NIST CSF 2.0 Functions?

The six Functions are Govern, Identify, Protect, Detect, Respond and Recover. Together they cover governance and risk strategy, understanding assets and risks, protective safeguards, detection of cybersecurity events, response activity and restoration of services. The new Govern Function in CSF 2.0 makes leadership, policy, accountability and supply-chain risk more explicit. Govern also creates a clearer line from cybersecurity activity to executive accountability. It asks organisations to make strategy, roles, policy and oversight visible rather than leaving cyber risk primarily with technical teams.

Is NIST CSF a certification?

No. NIST does not operate a certification scheme for organisations against the Cybersecurity Framework. Consultants and assessors can review alignment, produce a Current Profile or provide independent assurance over implementation, but that should not be marketed as an official NIST certificate. If a customer asks for NIST alignment, the better response is usually an evidence-based Profile, gap analysis and explanation of how the organisation uses the framework. That is more credible than presenting a certificate that NIST itself does not issue.

What is a NIST CSF Current Profile?

A Current Profile describes the CSF outcomes an organisation is currently achieving and the way those outcomes relate to its environment and priorities. A credible Current Profile should be evidence-based rather than an interview-only self-assessment. It becomes the baseline for deciding what needs to improve. We normally support each important judgement with evidence or a documented management decision. That allows the Current Profile to be challenged and updated later without relying on the memory of the people interviewed.

What is a NIST CSF Target Profile?

A Target Profile describes the cybersecurity outcomes the organisation wants or needs to achieve. It should reflect business objectives, risk appetite, threats, regulatory duties, customer commitments and resources. Comparing the Target Profile with the Current Profile identifies the gaps that form the implementation roadmap. The Target Profile should also be achievable and prioritised. A theoretical target containing every possible outcome at the highest maturity provides little help to management deciding what to fund first.

What are the NIST CSF Tiers?

The four Tiers are Partial, Risk Informed, Repeatable and Adaptive. They characterise the rigor of an organisation's cybersecurity risk governance and management practices. They are useful context for discussing maturity, but NIST does not require every organisation to reach the highest Tier and they should not be treated as a simple pass or fail score. The Tiers are also not a substitute for a Profile. Two organisations can operate at a similar Tier while needing very different cybersecurity outcomes because their services, threats and obligations differ.

How long does a NIST CSF assessment take?

The timetable depends on scope, organisation size, the availability of evidence and the depth of assessment. A focused assessment of one business unit or service can be completed relatively quickly, while an enterprise-wide Profile across multiple entities and technologies takes longer. We define the evidence set and stakeholders at scoping so the assessment is proportionate and does not become an endless interview exercise. For large environments, we can phase the work by business service, geography or entity and then consolidate the results. This gives management useful outputs early while preserving a consistent assessment method across the wider programme.

Can NIST CSF be used with ISO 27001?

Yes. They are complementary. NIST CSF provides a flexible set of cybersecurity outcomes and Profile mechanism, while ISO 27001 provides a certifiable Information Security Management System. Mapping both to a single risk, control and evidence environment gives the organisation strategic visibility through CSF without duplicating the operational work already supporting ISO certification. Cross-mapping also helps control owners understand why one security process is being tested by several assurance functions. It reduces repeated evidence requests and makes changes to a shared control easier to assess across frameworks.

Can NIST CSF help with regulatory compliance?

Yes, as a cybersecurity governance and risk framework, but it does not automatically satisfy every regulatory obligation. Financial services, critical infrastructure and other regulated organisations can map regulatory requirements to CSF outcomes and use the framework to organise evidence and improvement. The legal or regulatory rules still need to be assessed separately. The framework is most valuable when the regulatory mapping is explicit. If a regulation has a specific incident deadline, governance duty or control requirement, that requirement should remain visible even if it maps neatly to a CSF outcome.

What is the difference between NIST CSF and NIST SP 800-53?

NIST CSF is an outcome-based cybersecurity risk framework intended to help organisations organise and communicate their cybersecurity posture. NIST SP 800-53 is a much more detailed catalogue of security and privacy controls used heavily in US federal and other high-assurance contexts. An organisation can use detailed control catalogues to help achieve the outcomes described by the CSF. SP 800-53 is therefore often used beneath or alongside CSF where detailed controls are needed. The frameworks answer different questions and should not be treated as competing versions of the same document.

What do we receive from a NIST CSF consulting engagement?

A full engagement can include the Current Profile, Target Profile, evidence-based gap assessment, Tier context, prioritised roadmap, cross-framework mappings and management or board reporting. Where required, we also support implementation and periodic reassessment. The objective is a cybersecurity programme that can be governed and improved, not a decorative compliance score. We can also repeat the assessment periodically so the organisation can show whether remediation changed the underlying outcome. That produces much stronger board information than simply tracking whether project tasks were marked complete.

bottom of page