All frameworks
NISCSWP 29 · 2024

NIST CSF compliance

The outcome-based baseline for managing cyber risk.

The NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based framework from the US National Institute of Standards and Technology (NIST CSWP 29, 2024). It organises cybersecurity around six Functions — Govern, Identify, Protect, Detect, Respond and Recover — broken into 22 Categories and 106 Subcategory outcomes, and helps any organisation understand, assess, prioritise and communicate its cyber-risk posture in a common language.

Start from the basics

The standard

NIST Cybersecurity Framework 2.0 (NIST CSWP 29)

Who needs it

Any organisation that wants a common, board-readable way to understand and communicate cyber risk — US companies whose customers or federal contracts reference NIST, and any team that wants a flexible framework to structure a security programme without committing to a formal certification.

106

Subcategory outcomes

The basics

What is NIST CSF?

NIST CSF 2.0 is not a checklist of technologies or a certification you pass. It is a taxonomy of cybersecurity outcomes — statements of what good looks like — that you map to your own controls, risks and priorities. The 2024 revision widened its audience from critical infrastructure to organisations of every size and sector, and added a whole new Function, Govern, that puts cyber-risk strategy, roles, policy and oversight at the centre alongside the technical work.

You measure where you are using four Implementation Tiers, from Tier 1 (Partial) to Tier 4 (Adaptive), which describe how rigorous and risk-informed your practices are. Then you capture a Current Profile (what you do today) and a Target Profile (what you need), and the gap between them becomes your prioritised action plan. Because the Subcategories are outcomes rather than prescriptions, the framework crosswalks cleanly to ISO/IEC 27001:2022 and other standards you may already run.

Why it matters

What NIST CSF does for your business

It speaks to the board

The new Govern Function turns cybersecurity into a business-risk conversation leadership can actually own — strategy, roles, policy and oversight, not just firewalls. Current-vs-Target Profiles make progress legible to non-technical stakeholders.

It's the common language

NIST CSF is the reference point US buyers, insurers and regulators reach for. Being able to express your posture in its Functions and Subcategories shortcuts a lot of security-questionnaire back-and-forth.

It reuses what you have

It's a mapping, not a rebuild. The 106 outcomes crosswalk to ISO 27001:2022 and other frameworks, so the evidence you already collect can be pointed straight at CSF.

What it covers

Six Functions

Govern (new in 2.0), Identify, Protect, Detect, Respond and Recover — the top-level outcomes that organise the whole framework.

Categories & Subcategories

22 Categories break the Functions down into 106 Subcategory outcomes — the concrete, mappable statements of what good looks like.

Implementation Tiers

Four tiers, Partial → Risk-Informed → Repeatable → Adaptive, describe how rigorous and risk-informed your practices are.

Organizational Profiles

A Current and a Target Profile turn the gap between where you are and where you need to be into a prioritised action plan.

The hard way

Done by hand, CSF becomes a giant spreadsheet: 106 Subcategories scored twice (Current and Target), each cross-referenced to your real controls and evidence, then re-scored every review cycle. Keeping that mapping current — and turning it into a plan leadership can read — is exactly the repetitive work software should carry.

The easier way, with Compliance One

  • Ships the full NIST CSF 2.0 outcome library — all six Functions, 22 Categories and 106 Subcategories — ready to score against Current and Target Profiles.
  • Turns the Profile gap into a prioritised, owned action plan, and tracks your Implementation Tier over time.
  • Cross-maps every Subcategory to your ISO 27001:2022 controls, so evidence you already collect counts toward CSF automatically.
  • Produces board-ready posture summaries built around the Functions, so leadership can see progress at a glance.

Do it once, reuse it everywhere. Evidence you collect for NIST CSF is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is NIST CSF a certification?
No — it's a voluntary, self-assessment framework, not a certifiable scheme. You assess yourself against its outcomes (or bring in an assessor), and there's no certificate to 'pass'. Compliance One keeps the assessment and evidence audit-ready all the same.
What's new in version 2.0?
The headline change is the sixth Function, Govern, which elevates cyber-risk strategy, roles, policy and oversight. Version 2.0 (NIST CSWP 29, 2024) also broadened the scope from critical infrastructure to organisations of every size and sector.
We already have ISO 27001 — does that help?
A lot. The 106 CSF Subcategories crosswalk to ISO 27001:2022, so Compliance One maps them for you and your existing evidence carries straight over — CSF becomes a way to express and communicate work you've largely already done.

Ready to tackle NIST CSF?

See exactly how Compliance One maps NIST CSF to your environment in a 30-minute walkthrough — and how much of it we handle for you.