Current profile
An honest assessment of where the organization is now, expressed as outcomes achieved rather than as a score.
Risk-based program
The right starting point when a questionnaire has arrived and there is no program to point at yet.
Who this applies to. Organizations building a defensible security program without a specific certification driving the schedule.
CSF is not certifiable and nobody audits you against it. That is the point. It gives you a structure for deciding what to do and in what order, expressed as outcomes rather than as prescribed controls, which means it adapts to organizations of very different sizes and shapes.
We reach for it most often when there is no forcing function yet. A customer questionnaire has arrived, or leadership has decided security needs to be managed rather than assumed, and the organization needs a defensible answer to "what is your program" before it needs a certificate.
It also works well as a layer above a certification. If you are doing ISO 27001 or SOC 2 for commercial reasons, CSF gives leadership a view of the whole picture that a scoped certificate does not.
NIST published version 2.0 in February 2024. The most significant change for most organizations is its increased emphasis on governance, which pushes security decisions up to the people who own the risk.
The engagement
An honest assessment of where the organization is now, expressed as outcomes achieved rather than as a score.
Where the organization needs to be, driven by its actual risk and obligations rather than by an aspiration to do everything.
The distance between the two, sequenced by risk and budget, with the work broken into pieces a real team can absorb.
Who owns security decisions, what gets escalated, and how leadership sees enough to be accountable for it.
Mapping the program to whichever certification is likely next, so the work counts twice rather than being redone.
What you are left holding
FAQ
No. There is no certification scheme for the Cybersecurity Framework and no body issues one. If you need something to hand a customer, ISO 27001 or SOC 2 is the answer, and CSF is a good way to organize the work that gets you there.
For an organization with no specific obligation, often yes. It gives you a defensible program and a story you can tell. The moment a contract names a standard, that standard governs and CSF becomes the structure underneath rather than the answer.
Reviewed July 31, 2026. Primary sources: NIST Cybersecurity Framework 2.0 , NIST CSF resource center .
The first conversation is about what is actually in scope, because that governs the cost of everything after it.