Risk-based program

NIST Cybersecurity Framework

The right starting point when a questionnaire has arrived and there is no program to point at yet.

Who this applies to. Organizations building a defensible security program without a specific certification driving the schedule.

What NIST CSF actually asks of you

CSF is not certifiable and nobody audits you against it. That is the point. It gives you a structure for deciding what to do and in what order, expressed as outcomes rather than as prescribed controls, which means it adapts to organizations of very different sizes and shapes.

We reach for it most often when there is no forcing function yet. A customer questionnaire has arrived, or leadership has decided security needs to be managed rather than assumed, and the organization needs a defensible answer to "what is your program" before it needs a certificate.

It also works well as a layer above a certification. If you are doing ISO 27001 or SOC 2 for commercial reasons, CSF gives leadership a view of the whole picture that a scoped certificate does not.

NIST published version 2.0 in February 2024. The most significant change for most organizations is its increased emphasis on governance, which pushes security decisions up to the people who own the risk.

The engagement

What readiness covers

Current profile

An honest assessment of where the organization is now, expressed as outcomes achieved rather than as a score.

Target profile

Where the organization needs to be, driven by its actual risk and obligations rather than by an aspiration to do everything.

Gap and roadmap

The distance between the two, sequenced by risk and budget, with the work broken into pieces a real team can absorb.

Governance structure

Who owns security decisions, what gets escalated, and how leadership sees enough to be accountable for it.

Framework mapping

Mapping the program to whichever certification is likely next, so the work counts twice rather than being redone.

What you are left holding

Deliverables

  • Current and target profiles
  • Prioritised roadmap tied to risk and budget
  • Governance model with named owners
  • Risk register in terms leadership can act on
  • Mapping to the certification most likely to be asked for next

FAQ

NIST CSF questions we get asked

Can we get certified against CSF?

No. There is no certification scheme for the Cybersecurity Framework and no body issues one. If you need something to hand a customer, ISO 27001 or SOC 2 is the answer, and CSF is a good way to organize the work that gets you there.

Is CSF enough on its own?

For an organization with no specific obligation, often yes. It gives you a defensible program and a story you can tell. The moment a contract names a standard, that standard governs and CSF becomes the structure underneath rather than the answer.

Start with scope, not with a proposal

The first conversation is about what is actually in scope, because that governs the cost of everything after it.

Talk to an expert