HomeFrameworksInformation Security & PrivacyNIST CSF

Framework  Information Security & Privacy

NIST CSF

The NIST Cybersecurity Framework (CSF) 2.0, released February 26, 2024, is a voluntary framework of cybersecurity outcomes that any organization can use to understand, assess, prioritize and communicate its cybersecurity risk. It is organized into six functions: Govern (new in 2.0), Identify, Protect, Detect, Respond and Recover, each broken into categories and subcategories.

Version 2.0 widened the audience from critical infrastructure to all organizations and added quick-start guides, implementation examples and informative references that map the outcomes to controls in NIST SP 800-53, ISO 27001 and other catalogs.

The CSF does not prescribe controls or require certification. What it asks an organization to write down is a Current Profile (where it is), a Target Profile (where it wants to be), a prioritized action plan, and the governance artifacts the Govern function calls for: risk management strategy, roles and responsibilities, policies, and supply chain risk management expectations.

Many regulators and insurers accept a CSF profile as evidence of a reasonable security program, and several state laws and federal programs reference it.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedCyber policy v2by name, on record
GV.PO Handledwith AllyMatter
Govern, the Modern WayThe written policies behind the Govern function, acknowledged
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every name on record
Who read which version, and when
03
Show the board the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary for everyone. Used across private industry, state and local government and nonprofits; some regulators, contracts and cyber insurance questionnaires ask for a CSF-based program, and some federal agencies use it internally. No certification exists.

What the assessor asks to see

Current and Target Organizational Profiles; governance documents (risk management strategy, policies, roles); asset inventory; risk assessment; control mapping to informative references; incident response and recovery plans; supply chain risk management documentation; action plan and progress tracking.

Where the requirement sits: CSF 2.0 GV.PO (policy), GV.RR (roles); ID/PR/DE/RS/RC largely operational

What AllyMatter does here

Organise governance policies against CSF categories using Package line items.

AllyMatter publishes this site.

Assessors

Who assesses NIST CSF

None. There is no NIST or government assessor. Organizations self-assess or hire consultants for an independent CSF assessment; some CPA firms offer a SOC for Cybersecurity examination using the CSF as control criteria.

No firm has claimed a NIST CSF assessor listing yet. Claim yours →

Consultants

Who helps with NIST CSF

A large ecosystem: security consultancies, virtual CISO services and GRC platforms perform CSF maturity assessments, build current and target profiles, and map controls. Engagements are usually a few weeks for an assessment and roadmap, repeated annually.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST CSF consultant listing yet. Claim yours →

Related reading

  1. Unpacking the NIST cybersecurity framework 2.0Explains the new Govern function, how profiles and tiers are meant to be used, and what changed from version 1.1.IBM
  2. NIST unveils Cybersecurity Framework 2.0A law firm's take on why the voluntary framework matters in regulatory and contractual settings after the 2.0 rewrite.Cooley

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NIST CSF

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of NIST CSF in AllyMatter

Approve the policies NIST CSF asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.