NIST CYBERSECURITY FRAMEWORK
Where your company stands today and where the board decided it needs to stand. That difference, measured with method and revisited over time, is the only honest answer to the question every board asks and almost no security function can answer without a forty-page deck.
The NIST CSF is a public framework adopted voluntarily. What DM11 delivers is the assessment, both profiles, the plan and the tracking routine, which is what answers the board. Where the goal also includes a document to send a customer, the ISO 27001 or SOC 2 pages explain that route, and the two pieces of work support each other.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
CISA, information systems auditing
Specialists in risk management and business continuity
17 years of governance, risk and compliance
WHAT IT IS
The Cybersecurity Framework is published by the United States standards and technology institute, and has been at version 2.0 since 26 February 2024. It organises security into functions, categories and subcategories, and each subcategory describes an outcome to reach. It is neither a certifiable standard nor a technical manual: it is the structure that lets you track security over time in vocabulary a board understands.
Identify, protect, detect, respond and recover already existed. Version 2.0 added govern, and placed it at the centre of the other five. The change has a practical consequence: govern deals with who decides, who answers and what the company's risk appetite is, which is precisely what was missing while the framework described activity without describing accountability. If the material you hold shows five functions, it belongs to the previous version.
There are 22 categories and 106 subcategories, and each describes what has to be true without saying which technology gets you there. That is deliberate and it is the framework's greatest strength: it does not age alongside the tooling market, and no vendor can use it to argue that their product is mandatory.
The current profile records where the company stands, subcategory by subcategory. The target profile records where it decided to stand, which is not the same as the maximum available. The distance between the two is the plan, the budget and the thing you put in front of the board. No other reference on this page produces that artefact.
The four tiers describe how rigorously a company governs and manages risk, and choosing a tier is a decision about risk appetite and resources, not a ladder to climb for sport. Most companies cannot justify the highest tier, and treating it as the target is the most common misreading. Because the framework is adopted voluntarily, it produces no certificate of conformity, which is why its value shows in the tracking over time.
WHO USUALLY NEEDS IT
Note that none of them ends in a certificate. The CSF solves tracking and conversation; where the problem is proving something to a third party, the route is a different standard.
And today the answer is a long presentation nobody can turn into a decision. With both profiles built, the question gets a one-page answer, with a measured distance and a cost attached to closing it, which is the format boards decide in.
Penetration testing on one side, data protection work on another, a continuity project stalled somewhere in the middle and tools bought at different moments. The CSF is the umbrella that shows what those efforts cover together, and above all what none of them covers.
Common in subsidiaries of US companies and among suppliers to regulated sectors. The request usually arrives without detail, and the first useful deliverable is translating what it means: almost always a documented current profile, not a promise of Tier 4.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
Financial services
Each quarter the board asked whether the company was secure, and the technology function answered with a long pack full of tool metrics and no thread running through it. The question returned identical the following quarter, because the answer never turned into an investment decision.
We built the current CSF profile and ran a session with the executive team to define the target profile, function by function. The discussion was about risk appetite rather than technology, and it was the first time that group had explicitly stated how far it wanted to go on each front.
The distance between the two profiles became a single page with a cost attached. The board started discussing how much of the gap to close instead of asking whether it was secure, and the technology function stopped defending a budget with no reference point.
Subsidiary of a multinational
The parent company asked for CSF alignment. The Brazilian operation held a current ISO 27001 certificate, and the internal reading was that the request was already satisfied: send the certificate and close the matter.
We mapped the existing controls against the six functions. Identify, protect and detect came out strong, as you would expect from a certified management system. Respond looked reasonable on paper and had never been exercised, and recover was practically empty: there were backups and there was no business resumption plan.
The certificate did not answer the request, and that became clear in two weeks rather than after six months of misunderstanding with the parent company. The project that came out of it was continuity, which was the real gap, rather than one more security control.
Logistics
The company suffered a serious incident and reacted by investing heavily in detection tooling, which was where the pain had been felt. A year later, with the money spent, nobody could say whether the company would hold up better against the same event.
We ran the assessment across the six functions and the wheel came out visibly lopsided: detect well above everything else, respond with no tested procedure, and recover with no defined timeframe for anything. We showed that the next unit of budget bought more outside detection than inside it.
The incident had bought the right tool for the wrong problem. The company carried on detecting well and gained an answer for what to do after detecting, which was exactly what had been missing the first time.
HOW WE RUN IT
The step that separates this from an ordinary assessment is the second one. The target profile is not set by technology: it is an executive decision about risk appetite, and running that conversation is part of the delivery, because a target profile set by IT alone does not survive the first budget cut.
We define what enters the assessment and start with govern, which is where version 2.0 placed the centre. Who decides on risk, who answers for each front, what has been formally decided and what exists only by habit. Without that, the rest of the assessment becomes a picture with no owner.
Assessment scope defined, with the units included
A map of who decides and who answers for each front
A record of what is a formal decision and what is informal practice
Stakeholders identified, inside and outside the company
Delivery milestoneScope approved and accountability defined for each of the six functions.
We assess the 106 subcategories against evidence, through interviews and verification, accepting no positive answer without proof. The result is a picture of the current state by function and by category, in the form that allows comparison later.
A documented current profile, subcategory by subcategory
Evidence attached to every positive assessment
A reading by function, with the asymmetries visible
Reuse of whatever exists from ISO 27001, CIS or earlier projects
Delivery milestoneCurrent profile closed, with evidence for every subcategory assessed as met.
We run the session where leadership defines where it wants to be, function by function, against risk appetite, contractual obligation and available resources. We bring sector reference points into the conversation, but the decision belongs to the company, and it has to be taken by whoever signs the budget.
A target profile defined and signed off by leadership
A tier chosen per category, with the rationale recorded
The distance between the two profiles quantified
Priorities set against risk and against cost
Delivery milestoneTarget profile approved by leadership, with a recorded rationale for every choice.
We turn the distance into a plan with owners and dates, executed with your team. And we set the reassessment cadence, because the CSF's value shows up on the second measurement rather than the first: an isolated picture shows no direction at all.
A closure plan with an owner and a date per item
Execution supported, with periodic progress review
Board-facing tracking material, free of jargon
A reassessment cadence defined, with who runs it and when
Delivery milestoneSecond measurement completed with the same method, showing the direction of travel.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. There is a particularity here worth saying up front: gathering the current profile takes a predictable amount of time, and what stretches the project is almost always the executive calendar for deciding the target profile. These are the three factors that move the clock most.
A single operation is one profile. A group with businesses of different kinds usually needs more than one, because the risk appetite of a manufacturer and of a finance arm in the same group are not the same, and forcing a single profile produces a number that serves neither.
With calendar time secured, that stage takes weeks. When it is delegated to IT, the project moves faster and delivers less, because the target profile becomes a technical opinion rather than a business decision, and it will not carry a budget.
A company holding a current ISO 27001 certificate, or with the CIS Controls implemented, assembles the current profile far faster, because the evidence already exists and only needs rereading in the CSF's structure. With nothing measured, the gathering is the longest stretch.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No. The framework is voluntary, NIST issues no certificate of conformity and accredits nobody to issue one. There is a market selling what it calls NIST CSF certification: what gets delivered there is a third-party assessment report, which is legitimate and useful, and is not a recognised certificate. If your customer needs a document carrying third-party weight, the route is ISO 27001 or SOC 2.
The assessment across the six functions shows where your company stands and where the gaps concentrate. The next conversation, with your leadership, sets where it needs to stand. The distance between those two things is what becomes the plan.
Comparisons on this subject
See all 13 comparisons