Governance, Risk & Compliance

A maturity number your board can actually defend.

NIST CSF is not a certification and nobody can sell you one. It is a maturity model — which makes it the right tool when you need a defensible answer to "how mature are we, and what should we fix first" rather than a certificate for a procurement portal.

GOVERN added in 2.0 Identify Protect Detect Respond Recover A maturity model — there is no CSF certificate
6Functions in CSF 2.0
4Implementation tiers
2024Year GOVERN was added
0Certificates in existence

What CSF 2.0 is for, and what it is not

NIST released Cybersecurity Framework 2.0 in February 2024. The headline change from the 2014 version is a sixth function, GOVERN, which wraps risk strategy, roles, policy and oversight around the original five — Identify, Protect, Detect, Respond and Recover. The second change is scope: CSF 2.0 is explicitly written for organisations of any size and sector, not just critical infrastructure.

Here is the part vendors tend not to volunteer: there is no such thing as NIST CSF certification. It is a voluntary framework, not an auditable standard, and no body accredits assessors or issues certificates against it. Anyone offering you one is describing something that does not exist. What CSF gives you instead is more useful to a board than a badge — a repeatable, defensible picture of where you are, where you should be, and what moving between the two would cost.

The weakness of most CSF assessments is that they are self-attested. Someone is asked whether the organisation detects anomalous activity, they say yes, and a score is recorded. We check the Detect and Respond functions against actual telemetry, because a maturity score that rests on an optimistic interview is worse than no score at all — it produces confidence without capability.

Coverage

The six functions, assessed to subcategory level

Scored against the four Implementation Tiers, with a current profile and a target profile aligned to your risk appetite and sector rather than to a generic ideal.

Govern (GV)

The 2.0 addition. Organisational context, risk management strategy, roles and responsibilities, policy, oversight and supply-chain risk management. Forces the question of who actually owns cyber risk.

Identify (ID)

Asset management, risk assessment and improvement. What you have, what could go wrong with it, and how you learn from what already has.

Protect (PR)

Identity management and access control, awareness and training, data security, platform security and the resilience of technology infrastructure.

Detect (DE)

Continuous monitoring and adverse event analysis — assessed against real telemetry rather than an assertion that monitoring exists.

Respond (RS)

Incident management, analysis, reporting and mitigation. Tested against what actually happened the last time something went wrong.

Recover (RC)

Incident recovery plan execution and communication. Routinely the weakest function, and routinely the one nobody has exercised.

Approach

How a CSF assessment runs

The output is a profile and a roadmap, not a pass or a fail. That is a feature: it gives leadership something to sequence and fund rather than a binary they can only argue with.

  1. 01 · Scope

    The systems, business units and risk appetite in play, and what a realistic target profile looks like for your sector and size.

  2. 02 · Assess

    Interviews and evidence review across all six functions, down to category and subcategory level.

  3. 03 · Validate

    Detect and Respond claims checked against live telemetry and control tests, so scores reflect capability rather than intent.

  4. 04 · Profile and score

    A current profile, a target profile and a tier rating with the reasoning recorded — so the score can be defended when someone challenges it.

  5. 05 · Roadmap

    A prioritised uplift plan that moves named subcategories toward the target, sequenced by risk reduction per unit of effort.

  6. 06 · Re-score and sustain

    Re-assessment after uplift so movement is measurable, plus a reporting rhythm your board can actually follow.

Run against recognised standards

  • NIST CSF 2.0Released February 2024, six functions
  • NIST SP 800-53Control catalogue behind the subcategories
  • NIST SP 800-171Where controlled unclassified information applies
  • ISO/IEC 27001:2022Cross-mapped where certification is also required
  • MITRE ATT&CKTechnique coverage behind Detect and Respond scoring

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Function-by-function maturity scorecard

All six functions to subcategory level, scored with the evidence that supports each rating.

Current and target profiles

Where you are and where you should be, with the gap between them expressed as work rather than as a number.

Tier rating with rationale

Partial, Risk Informed, Repeatable or Adaptive — and why, in terms you can defend to an auditor, insurer or board member.

Prioritised uplift roadmap

Sequenced by risk reduction per unit of effort, with owners and realistic dates.

Board-ready summary

One page that says where you stand and what you are asking for, without requiring a security background to read.

Framework cross-mapping

Mapped to ISO 27001 and SOC 2 where relevant, so one assessment feeds more than one programme.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • Your board or insurer has asked how mature your security programme is and you do not have a defensible answer.
  • You want a roadmap and a score rather than a certificate nobody internally will use.
  • You were assessed against the old five functions and GOVERN has never been examined.
  • Your last maturity assessment was entirely self-attested.
  • You need to sequence security spend and have no agreed basis for prioritising it.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

NIST CSF — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Can we get NIST CSF certified?

No. CSF is a voluntary maturity framework, not a certifiable standard. There is no accreditation body, no certificate and no auditor register. Anyone offering NIST CSF certification is selling something that does not exist — which is worth knowing before you buy it. What we deliver is a defensible maturity assessment, a target profile and a roadmap.

What changed in CSF 2.0?

The main change is the addition of a sixth function, GOVERN, in the February 2024 release, covering risk strategy, roles and responsibilities, policy, oversight and supply-chain risk. The other significant change is scope: 2.0 is written for organisations of all sizes and sectors rather than being framed around critical infrastructure. Assessments still written around five functions are working from the previous version.

What are the implementation tiers?

Four: Partial, Risk Informed, Repeatable and Adaptive. They describe the rigour and consistency of your risk management practices, not a grade. Tier 4 is not the right target for every organisation — the appropriate tier depends on your risk appetite, sector and threat exposure, and part of the assessment is agreeing which one you should be aiming at.

How does this relate to ISO 27001?

CSF is a maturity lens; ISO 27001 is a certifiable management system. They answer different questions — "how good are we" versus "can we prove we run a system". They map onto each other well, so a CSF assessment is a sensible precursor to an ISO 27001 programme, and the evidence gathered for one substantially serves the other. We cross-map deliberately so the work is not duplicated.

Do you back the scores with real data?

Yes, and it is the main reason to have someone external do this. Detect and Respond are validated against actual telemetry and control tests rather than accepted on interview. A self-attested maturity score is a statement of intent, and it tends to be optimistic in exactly the functions where optimism is most expensive.

Who is this for, if there is no certificate at the end?

Organisations reporting to a board, an insurer or a parent company rather than to a certification body. It is also the right first engagement when you know you need to improve but cannot yet articulate what to do first — the roadmap is the deliverable, and it is what makes the security budget conversation a planning exercise rather than an argument.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.