Enquire Us

NIST CSF Implementation

The NIST Cybersecurity Framework is voluntary guidance published by an agency of the United States Department of Commerce. NIST does not certify anyone against it, so implementation and independent assessment are what actually produce evidence.

What the CSF Is and Who Publishes It

The Cybersecurity Framework is published by the National Institute of Standards and Technology, a non regulatory agency of the United States Department of Commerce. Version 1.0 appeared in February 2014 in response to an executive order on improving critical infrastructure cybersecurity, and version 1.1 followed in April 2018.

The current release is CSF 2.0, published on 26 February 2024 as NIST Cybersecurity White Paper 29. Two changes matter most. The framework is no longer aimed only at critical infrastructure; NIST states that it is intended for organisations of all sizes and sectors. And a sixth Function, Govern, was added, moving cybersecurity risk from a technical concern to an enterprise risk management one.

The Six Functions

CSF 2.0 organises outcomes into six Functions. Each Function contains Categories, and each Category contains Subcategories that describe outcomes rather than prescribing how to achieve them.

  • Govern. The organisation’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored. This covers roles and responsibilities, oversight, and risk in the supply chain.
  • Identify. Current cybersecurity risks to assets, suppliers and the wider organisation are understood.
  • Protect. Safeguards are used to manage those risks, covering identity and access, awareness and training, data security, platform security and technology resilience.
  • Detect. Possible cybersecurity attacks and compromises are found and analysed.
  • Respond. Action is taken on a detected incident, including management, analysis, reporting, communication and mitigation.
  • Recover. Assets and operations affected by an incident are restored, and recovery is communicated.

The framework is applied through Organisational Profiles. A Current Profile records the outcomes an organisation is achieving today. A Target Profile records the outcomes it needs. The gap between them is the action plan. Tiers, from Partial through Risk Informed and Repeatable to Adaptive, describe how rigorous the organisation’s cybersecurity risk governance and management practices are. Tiers are a characterisation, not a grade to be pursued for its own sake.

There Is No NIST CSF Certification

NIST publishes the framework. It runs no certification programme, accredits no certification bodies and issues no certificates. NIST describes the CSF as a foundational resource that may be adopted voluntarily and through governmental policies and mandates. Nothing in it creates an audit scheme.

What organisations use as evidence instead:

  • An independent CSF assessment report from a qualified assessor, stating Current Profile achievement outcome by outcome with the evidence reviewed.
  • ISO/IEC 27001 certification of the information security management system, which is genuinely certifiable and maps well onto CSF outcomes.
  • A SOC 2 report from a licensed CPA firm where the buyer is in the United States.
  • Contract specific attestations, for example where a federal contract references NIST SP 800-171 for controlled unclassified information. That is a separate requirement set from the CSF and should not be conflated with it.

If a provider offers you NIST CSF certification with an accreditation mark, ask which accreditation body issued it and under which scheme. There is no correct answer to that question.

How Univate Implements the CSF

  1. Scope and drivers. Establish what is prompting the work, which systems and business lines are in scope, and which Tier is realistic for the organisation.
  2. Current Profile. Assess achievement of each relevant Subcategory outcome against evidence, not against opinion, and record what was examined.
  3. Target Profile. Agree the outcomes that the organisation’s risk appetite, customers and regulators actually require, including supply chain expectations under Govern.
  4. Roadmap and remediation. Sequence the gap closure by risk reduction and dependency, with owners and dates, and implement the technical and process changes.
  5. Measurement and reassessment. Metrics tied to outcomes, incident exercises and periodic reassessment of the Current Profile so progress is demonstrable.

Points Worth Being Careful About

  • The CSF describes outcomes, not controls. Implementation always requires a control set beneath it, whether that is ISO/IEC 27002, NIST SP 800-53 or your own.
  • Tiers are not maturity scores and are not comparable between organisations. Reporting a Tier to a board as if it were a rating misleads them.
  • The CSF and NIST SP 800-171 are different documents with different purposes. Federal contract obligations follow the contract, not the framework.
  • Govern is where most organisations have the largest gap, because it demands named accountability and supply chain oversight rather than tooling.
  • A Current Profile assembled from a self assessment questionnaire, with no evidence review, will not survive contact with a customer’s security team.

NIST CSF Questions We Are Asked Most Often

Can an organisation be certified against the NIST Cybersecurity Framework?

No. The National Institute of Standards and Technology publishes the framework but operates no certification programme and accredits no certification bodies. Organisations demonstrate adoption through an independent assessment report, or through a genuinely certifiable standard such as ISO/IEC 27001.

What is the current version of the CSF?

CSF 2.0, published on 26 February 2024. It replaced CSF 1.1 from April 2018 and added the Govern Function, bringing the total to six Functions.

What are the six CSF Functions?

Govern, Identify, Protect, Detect, Respond and Recover. Govern was introduced in version 2.0 and covers cybersecurity risk management strategy, expectations, policy, roles, oversight and supply chain risk.

Is the NIST CSF mandatory?

It is voluntary in itself. NIST describes it as a resource that may be adopted voluntarily and through governmental policies and mandates, so a specific contract, sector regulator or jurisdiction may make it compulsory for you even though the framework does not.

How does the CSF relate to ISO/IEC 27001?

They complement each other. The CSF describes cybersecurity outcomes across six Functions and is not certifiable. ISO/IEC 27001 specifies requirements for an information security management system and is certifiable by accredited certification bodies. Many organisations use the CSF to structure risk conversations and ISO/IEC 27001 to obtain the certificate customers ask for.

Tell us which contract, regulator or board requirement is pointing you at the CSF. We will build a Current Profile, agree a Target Profile with you and set out the work between the two.

Related Services & Resources

Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.