Compliance

NIST CSF Compliance: The Six Functions and How to Comply

NIST CSF is voluntary, but it has become the common yardstick for demonstrating a mature security program. Here's what NIST CSF compliance actually involves, function by function, and how to prove it.

Nilesh Wagh · Co-Founder, Pelta Technologies11 min readUpdated Part of NIST CSF

The NIST Cybersecurity Framework (CSF) is a voluntary, outcome-based framework for managing cyber risk, and it has quietly become the common yardstick organisations use to show they run a mature security program. It does not prescribe a fixed list of controls; it describes the outcomes a good program achieves, in a shared language your whole organisation and your customers can understand. This guide explains what NIST CSF compliance actually means in practice: whether it is mandatory, the six functions of CSF 2.0, how profiles and tiers work, how to demonstrate compliance with evidence, and how it maps onto the ISO 27001 and SOC 2 work you may already do. For the framework overview, see the NIST CSF framework page.

NIST CSF is a voluntary framework, not a law or a certification, so 'compliance' here means conforming your program to the outcomes it defines and being able to evidence that. Adapt it to your own risk and obligations, and confirm any contractual or sector-specific expectations that reference it.

Is NIST CSF compliance mandatory?

Not by itself. There is no law that says 'comply with the NIST CSF', and there is no certificate to earn. But compliance is increasingly expected in practice: US federal agencies and many critical-infrastructure sectors are directed to use it, enterprise customers ask vendors to align to it, and cyber-insurance and contracts frequently reference it. So while it is voluntary, 'we are aligned to NIST CSF' has become a credential buyers trust, which is why so many organisations pursue CSF compliance even without a mandate.

The six functions of CSF 2.0

The 2.0 revision (2024) added Govern as a sixth function, elevating strategy, roles and oversight to sit alongside the operational work. The six functions are the backbone of any CSF compliance effort.

The six CSF 2.0 functions

Govern

Strategy & oversight

Identify

Assets & risk

Protect

Safeguards

Detect

Find events

Respond

Act on incidents

Recover

Restore capability

  • Govern: establish and monitor the cyber risk strategy, roles, policy and oversight (the function added in 2.0).
  • Identify: understand your assets, data, suppliers and the risks to them.
  • Protect: put safeguards in place, access control, training, data security, secure configuration.
  • Detect: find anomalies and security events, through monitoring and analysis.
  • Respond: contain, analyse and communicate when an incident occurs.
  • Recover: restore capabilities and services affected by an incident.

Profiles and tiers

Two concepts make the CSF actionable, and both matter for compliance. A profile is your set of outcomes: you create a current profile (where you are) and a target profile (where you need to be), and the gap between them becomes your compliance roadmap. Tiers (from Partial to Adaptive) describe how rigorous and risk-informed your practices are. Tiers are a risk-based choice, not a score to maximise, aim for the tier your risk justifies, not the highest one.

What NIST CSF compliance actually looks like

Because there is no certificate, CSF compliance is demonstrated, not awarded. In practice it means you can show, function by function, that you have defined the outcomes you need and have evidence they are met.

  1. 1Assess your current profile across all six functions, honestly.
  2. 2Define a target profile based on your risk, customers and obligations.
  3. 3Prioritise the gap between current and target as a remediation roadmap.
  4. 4Map each outcome to the evidence that demonstrates it (policies, configurations, logs, test results).
  5. 5Reassess on a cadence, profiles are living, not a one-off exercise.
The CSF works best as the layer over your other frameworks. Map ISO 27001, SOC 2 and your regulatory obligations to CSF outcomes so one evidence base serves them all, which is exactly how Pelta approaches overlapping frameworks.
Comply once, reuse everywhere, in PeltaSee how the crosswalk works
Compliant

ISO 27001

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding NIST CSF

~65% carried over
Carried over from ISO 27001 New work for your team

Auto-completed from your existing program

GovernIdentifyProtectDetectRespondRecover

Overlap shown is illustrative, the actual carry-over depends on the maturity of your existing program.

That overlap is the practical shortcut to CSF compliance: if you already run ISO 27001 or SOC 2, most of the evidence CSF outcomes need already exists, it just has to be mapped to the six functions rather than recreated.

NIST CSF vs ISO 27001 and SOC 2

They complement rather than compete. The CSF gives outcome-based structure and a shared vocabulary but no certificate; ISO 27001 certifies a management system; SOC 2 produces an attestation report for customers. Many organisations run ISO 27001 or SOC 2 for the external credential and use the CSF to organise the whole program and communicate posture to leadership, reusing the same evidence across all of them. See our ISO 27001 vs SOC 2 and SOC 2 compliance checklist guides for those.

Common NIST CSF compliance pitfalls

  • Chasing the highest tier instead of the tier your risk justifies.
  • Treating the profile as a one-time assessment rather than a living roadmap.
  • Documenting outcomes with no evidence to back them at review time.
  • Ignoring the new Govern function and treating CSF as purely operational.
  • Rebuilding evidence from scratch instead of reusing ISO 27001 / SOC 2 work.

Putting it together

NIST CSF compliance is less about a badge and more about being able to demonstrate, across govern, identify, protect, detect, respond and recover, that you have the right outcomes and the evidence to prove them. Set a target profile that matches your risk, close the gaps, keep each outcome tied to live evidence, and reuse what you already have from ISO 27001 or SOC 2. Done that way, CSF becomes the organising layer that makes every other framework easier to run.

Frequently asked questions

Is NIST CSF compliance mandatory?+

Not by law for most organisations, and there is no certificate. But it is widely expected in practice: US federal agencies and critical-infrastructure sectors are directed to use it, and enterprise customers, contracts and cyber-insurers frequently reference it. Alignment to NIST CSF has become a credential buyers trust.

How do you demonstrate NIST CSF compliance?+

Because there is no certification, you demonstrate it: assess your current profile across the six functions, define a risk-based target profile, close the gap, and keep each outcome tied to evidence (policies, configurations, logs, test results) that you can produce on demand.

What are the NIST CSF functions?+

CSF 2.0 has six: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in the 2.0 revision to elevate strategy, roles and oversight.

What changed in NIST CSF 2.0?+

The headline change was adding Govern as a sixth function, alongside broadening the framework's audience beyond critical infrastructure to organisations of all sizes and strengthening its treatment of supply-chain risk.

What is a CSF profile?+

A profile is your set of cybersecurity outcomes. A current profile shows where you are; a target profile shows where you need to be; the gap between them is your compliance roadmap.

How does NIST CSF relate to ISO 27001?+

They complement each other: CSF gives outcome-based structure and a common language, ISO 27001 certifies a management system. Their controls overlap heavily, so most evidence can be reused across both rather than recreated.

About the author

N

Nilesh Wagh

Co-Founder, Pelta Technologies

Former CISO · 10+ years in information security & GRC

Nilesh Wagh is Co-Founder of Pelta Technologies, where he leads its information security, privacy, AI governance and GRC advisory. With over a decade in cyber and information security (including years as a Chief Information Security Officer) he helps regulated organisations move from fragmented compliance to connected, evidence-driven assurance.

Connect on LinkedIn →

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.