FramewiseCOMPLIANCE
Practice

NIST CSF

The risk-management framework that underpins most other programs and satisfies buyers who want structure without certification.

What it is

The NIST Cybersecurity Framework organizes security activity into six functions — Govern, Identify, Protect, Detect, Respond, Recover — and expresses maturity as current and target profiles rather than a pass or fail. Version 2.0 added the Govern function and broadened applicability beyond critical infrastructure. There is no certification, which makes it a common foundation layer beneath certifiable frameworks.

Who typically needs it

  • Companies whose customers ask for a security program but not a specific certificate
  • Organizations preparing for CMMC who need the underlying 800-171 foundation
  • Boards and investors asking for a defensible maturity measure over time
  • Firms running several certifiable frameworks who want one common control spine
  • Companies in regulated sectors where CSF alignment is named in guidance

What the engagement looks like

Baseline. We assess current profile across all six functions, define a target profile appropriate to your risk and sector, and produce the gap analysis between them. The output is a maturity trajectory, not a score.

Build. We implement toward the target profile and author the governance artifacts the Govern function now expects — roles, risk appetite, supply chain risk management, and policy structure.

Build, continued. Where CSF sits beneath a certifiable framework, we map controls once and reuse them. A single control implementation should satisfy CSF, ISO 27001 Annex A, and the relevant 800-171 requirement without three separate evidence sets.

Audit Sprint. Used here for customer diligence, board reporting, or as preparation for the certifiable framework layered on top.

Steady State. Profiles are meant to move. We reassess on cadence, report the trajectory to your board or investors, and adjust the target as the business changes.

Common failure modes

  • Adopting a target profile copied from a reference rather than derived from actual risk
  • Treating CSF as a checklist and losing the profile-to-profile trajectory that makes it useful
  • Skipping the Govern function, which is where most 2.0 gap findings now concentrate
  • Duplicating evidence across CSF and the certifiable framework sitting on top of it

Price range

Programs typically run between $20,000 and $50,000 for the Build phase, and are often priced as a wrapper around a certifiable framework.

Related frameworks

Talk to us about your NIST CSF.

Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.

Book a consultation