Information SecurityGlobal (US-led)

NIST CSF compliance

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework is a voluntary, outcome-based framework for managing cybersecurity risk. Its 2.0 revision added Govern as a core function, putting oversight and strategy alongside the operational work. Pelta helps you organise your program around the CSF functions and keep each outcome mapped to the evidence that demonstrates it.

Who it's for

Does NIST CSF apply to you?

  • Organisations wanting a flexible, risk-based way to structure a security program
  • Teams aligning multiple frameworks under one common language
  • US-market and global companies referencing NIST in contracts or policy

What NIST CSF is — and isn't

The CSF is not a certification and not a rigid checklist. It is a voluntary framework that describes cybersecurity outcomes in a common language, so organisations of any size can assess where they are, decide where they want to be, and communicate risk to leadership. Because it is outcome-based rather than prescriptive, it maps cleanly onto other frameworks you may already run.

The six CSF 2.0 functions

Govern

Strategy & oversight

Identify

Assets & risk

Protect

Safeguards

Detect

Find events

Respond

Act on incidents

Recover

Restore capability

What changed in CSF 2.0

The headline change is the addition of Govern as a sixth function, elevating governance — roles, policy, risk appetite and oversight — to sit alongside the original five. CSF 2.0 also broadened its audience beyond critical infrastructure to organisations of all sizes and sectors, and strengthened its treatment of supply-chain risk.

How to adopt it

  1. 1Create a current profile: assess which outcomes you achieve today across the six functions.
  2. 2Create a target profile: decide the outcomes you need, based on your risk and obligations.
  3. 3Gap and prioritise: the distance between current and target becomes your roadmap.
  4. 4Map to evidence: link each outcome to the artefacts that demonstrate it.
  5. 5Reassess on a cadence: profiles are living, not one-off.
CSF works best as the organising layer over your other frameworks — map ISO 27001, SOC 2 and your regulatory obligations to CSF outcomes so one evidence base serves them all.

Common pitfalls to avoid

  • Treating the tiers as a maturity score to maximise, rather than a risk-based choice.
  • Skipping Govern and jumping straight to technical controls.
  • Building profiles once and never revisiting them.
How Pelta helps

Run NIST CSF on one connected platform

Organised by the six functions

Manage your program around Govern, Identify, Protect, Detect, Respond and Recover in one place.

One base, many frameworks

Map ISO 27001, SOC 2 and regulatory controls to CSF outcomes so evidence is collected once.

Current vs target profiles

See where you are, set where you need to be, and track the gap as a roadmap.

Evidence-backed

Every outcome links to the evidence that demonstrates it.

NIST CSF FAQs

Is NIST CSF mandatory?+

No. The CSF is a voluntary framework. It is widely referenced in contracts, policy and other frameworks, but it is not itself a legal requirement or a certification.

What are the NIST CSF functions?+

CSF 2.0 has six: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 revision to elevate strategy and oversight.

What changed in CSF 2.0?+

The main change was adding the Govern function. CSF 2.0 also broadened its scope beyond critical infrastructure to organisations of all sizes and deepened its supply-chain risk guidance.

How does NIST CSF relate to ISO 27001?+

They complement each other. CSF gives outcome-based structure and a common language; ISO 27001 certifies a management system. Many organisations map ISO 27001 controls to CSF outcomes and reuse the evidence.

What are CSF tiers?+

Tiers describe how rigorous and risk-informed your practices are, from Partial to Adaptive. They are a risk-based choice, not a score to maximise.

See NIST CSF compliance on Pelta

Adopt the NIST Cybersecurity Framework (CSF 2.0) on Pelta — organise your program around Govern, Identify, Protect, Detect, Respond and Recover, mapped to evidence.