Compliance

NIST CSF Explained: The Six Functions and How to Adopt It

The NIST Cybersecurity Framework is the flexible, outcome-based way to structure a security program. Here's what the six functions mean and how to adopt it.

The Pelta Team8 min readUpdated Part of NIST CSF

The NIST Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for managing cyber risk. It doesn't prescribe specific controls — it describes the outcomes a good program achieves, in a common language your whole organisation can use. That flexibility is why it's often adopted as the organising layer over other frameworks rather than instead of them.

The six functions of CSF 2.0

The 2.0 revision added Govern as a sixth function, elevating strategy and oversight to sit alongside the operational work.

The six CSF 2.0 functions

Govern

Strategy & oversight

Identify

Assets & risk

Protect

Safeguards

Detect

Find events

Respond

Act on incidents

Recover

Restore capability

Profiles and tiers

Two concepts make the CSF actionable. A profile is your set of outcomes; you create a current profile (where you are) and a target profile (where you need to be), and the gap becomes your roadmap. Tiers describe how rigorous and risk-informed your practices are — from Partial to Adaptive — and are a risk-based choice, not a score to maximise.

How to adopt the CSF

  1. 1Assess your current profile across the six functions.
  2. 2Define a target profile based on your risk and obligations.
  3. 3Prioritise the gap between current and target as a roadmap.
  4. 4Map each outcome to the evidence that demonstrates it.
  5. 5Reassess on a cadence — profiles are living, not one-off.
The CSF works best as the layer over your other frameworks. Map ISO 27001, SOC 2 and your regulatory obligations to CSF outcomes so one evidence base serves them all — which is exactly how Pelta approaches overlapping frameworks.
Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

ISO 27001

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding NIST CSF

~65% carried over
Carried over from ISO 27001 New work for your team

Auto-completed from your existing program

GovernIdentifyProtectDetectRespondRecover

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

CSF vs ISO 27001

They complement rather than compete. The CSF gives outcome-based structure and a shared vocabulary; ISO 27001 certifies a management system. Many organisations run ISO 27001 for certification and use the CSF to communicate posture to leadership — reusing the same evidence across both.

Frequently asked questions

Is NIST CSF mandatory?+

No. The CSF is voluntary. It is widely referenced in contracts and policy, but it is not itself a legal requirement or a certification.

What are the NIST CSF functions?+

CSF 2.0 has six: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 revision.

What is a CSF profile?+

A profile is your set of cybersecurity outcomes. A current profile shows where you are; a target profile shows where you need to be; the gap is your roadmap.

How does NIST CSF relate to ISO 27001?+

They complement each other — CSF gives outcome-based structure and a common language, ISO 27001 certifies a management system. Their controls overlap, so evidence can be reused.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.