NIST CSF
The risk-management framework that underpins most other programs and satisfies buyers who want structure without certification.
What it is
The NIST Cybersecurity Framework organizes security activity into six functions — Govern, Identify, Protect, Detect, Respond, Recover — and expresses maturity as current and target profiles rather than a pass or fail. Version 2.0 added the Govern function and broadened applicability beyond critical infrastructure. There is no certification, which makes it a common foundation layer beneath certifiable frameworks.
Who typically needs it
- Companies whose customers ask for a security program but not a specific certificate
- Organizations preparing for CMMC who need the underlying 800-171 foundation
- Boards and investors asking for a defensible maturity measure over time
- Firms running several certifiable frameworks who want one common control spine
- Companies in regulated sectors where CSF alignment is named in guidance
What the engagement looks like
Common failure modes
- Adopting a target profile copied from a reference rather than derived from actual risk
- Treating CSF as a checklist and losing the profile-to-profile trajectory that makes it useful
- Skipping the Govern function, which is where most 2.0 gap findings now concentrate
- Duplicating evidence across CSF and the certifiable framework sitting on top of it
Price range
Programs typically run between $20,000 and $50,000 for the Build phase, and are often priced as a wrapper around a certifiable framework.
Talk to us about your NIST CSF.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.