The NIST Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for managing cyber risk. It doesn't prescribe specific controls — it describes the outcomes a good program achieves, in a common language your whole organisation can use. That flexibility is why it's often adopted as the organising layer over other frameworks rather than instead of them.
The six functions of CSF 2.0
The 2.0 revision added Govern as a sixth function, elevating strategy and oversight to sit alongside the operational work.
Govern
Strategy & oversight
Identify
Assets & risk
Protect
Safeguards
Detect
Find events
Respond
Act on incidents
Recover
Restore capability
Profiles and tiers
Two concepts make the CSF actionable. A profile is your set of outcomes; you create a current profile (where you are) and a target profile (where you need to be), and the gap becomes your roadmap. Tiers describe how rigorous and risk-informed your practices are — from Partial to Adaptive — and are a risk-based choice, not a score to maximise.
How to adopt the CSF
- 1Assess your current profile across the six functions.
- 2Define a target profile based on your risk and obligations.
- 3Prioritise the gap between current and target as a roadmap.
- 4Map each outcome to the evidence that demonstrates it.
- 5Reassess on a cadence — profiles are living, not one-off.
ISO 27001
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding NIST CSF
~65% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
CSF vs ISO 27001
They complement rather than compete. The CSF gives outcome-based structure and a shared vocabulary; ISO 27001 certifies a management system. Many organisations run ISO 27001 for certification and use the CSF to communicate posture to leadership — reusing the same evidence across both.
Frequently asked questions
Is NIST CSF mandatory?+
No. The CSF is voluntary. It is widely referenced in contracts and policy, but it is not itself a legal requirement or a certification.
What are the NIST CSF functions?+
CSF 2.0 has six: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 revision.
What is a CSF profile?+
A profile is your set of cybersecurity outcomes. A current profile shows where you are; a target profile shows where you need to be; the gap is your roadmap.
How does NIST CSF relate to ISO 27001?+
They complement each other — CSF gives outcome-based structure and a common language, ISO 27001 certifies a management system. Their controls overlap, so evidence can be reused.