NIST CSF vs ISO 27001: how they map
People treat NIST CSF and ISO 27001 as an either-or choice. They are not. They answer different questions and, because they overlap heavily, doing one gets you most of the way to the other. The confusion is worth clearing up, because picking a lane you did not need to pick wastes months.
The core difference in one line
ISO 27001 is a certifiable management system that proves you run security properly. NIST CSF 2.0 is a voluntary, outcome-based language for understanding and communicating cyber risk. One you get audited against, the other you assess yourself with.
Where they differ
- Certification: ISO 27001 is certified by an accredited body with Stage 1 and Stage 2 audits and annual surveillance. CSF has no certificate, you self-assess (or bring in an assessor).
- Structure: ISO 27001 is a clause 4 to 10 management system plus 93 Annex A controls. CSF is six Functions, 22 Categories and 106 Subcategory outcomes, with Implementation Tiers and Current and Target Profiles.
- Origin and reach: ISO 27001 is an international standard recognised in over 150 countries. CSF is a US framework (NIST CSWP 29, 2024) that US buyers, insurers and federal programmes reach for by name.
Where they overlap (which is a lot)
NIST publishes informative references that crosswalk CSF Subcategories to ISO 27001 and other standards, and the alignment is strong. CSF's new Govern Function maps onto ISO 27001's leadership, planning and policy clauses. Its Protect, Detect and Respond Functions map onto the Annex A control themes you already implement. Access control, cryptography, logging, incident management: the same work satisfies both.
So which do you need?
If a customer, insurer or contract wants a certificate, you want ISO 27001. If you want a flexible way to understand your posture and talk about it with your board and your US buyers, you want CSF. Most mature teams end up using both: 27001 as the certified backbone, CSF as the risk-communication layer on top. Compliance One cross-maps the 106 CSF Subcategories to your 27001 controls automatically, so you run one control set and express it two ways, with the evidence counting for both.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.