ISO 27001 vs NIST CSF
ISO/IEC 27001 and the NIST Cybersecurity Framework are both used to organise information security work, but only one of them can be certified. ISO/IEC 27001 is published jointly by the International Organization for Standardization and the International Electrotechnical Commission, and an accredited certification body issues a certificate after a Stage 1 and Stage 2 audit. The NIST Cybersecurity Framework is published by the National Institute of Standards and Technology, an agency of the United States Department of Commerce. It is a voluntary framework of outcomes, it is free to download, and NIST does not run a certification scheme against it.
What is ISO/IEC 27001?
ISO/IEC 27001:2022, the third edition, is titled Information security, cybersecurity and privacy protection, Information security management systems, Requirements. It specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, or ISMS.
- Management system clauses. Context, leadership, planning, support, operation, performance evaluation and improvement, following the harmonised structure common to ISO management system standards.
- Annex A. 93 controls arranged in four themes: 37 organisational controls, 8 people controls, 14 physical controls and 34 technological controls.
- Statement of Applicability. The organisation must justify which Annex A controls apply and which are excluded, driven by its own risk assessment and risk treatment plan.
- Certification. A certification body accredited by a national accreditation body carries out a Stage 1 readiness review and a Stage 2 audit. The certificate is normally valid for three years, subject to annual surveillance audits, with recertification before expiry.
What is the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework version 2.0 was released on 26 February 2024. NIST states that the framework describes desirable outcomes an organisation can aspire to achieve, and that it does not prescribe outcomes nor how they may be achieved. NIST also describes it as a foundational resource that may be adopted voluntarily and through governmental policies and mandates. CSF 2.0 widened its scope beyond critical infrastructure to organisations of any size in any sector.
- Functions. The Core is organised into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in version 2.0.
- Categories and Subcategories. Each Function breaks down into Categories and then into Subcategories, which are the outcome statements an organisation works against.
- Tiers. Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable and Tier 4 Adaptive characterise the rigour of cybersecurity risk governance and management practices.
- Profiles. A Current Profile and a Target Profile describe where the organisation is and where it intends to be, which is how the framework is used to prioritise work.
There is no NIST audit, no accredited assessor, no certificate and no expiry date. Any assurance is either self assessment or an assessment a client or third party chooses to commission.
ISO 27001 vs NIST CSF compared
| Attribute | ISO/IEC 27001 | NIST Cybersecurity Framework |
|---|---|---|
| What it is | A certifiable management system standard | A voluntary framework of cybersecurity outcomes |
| Publisher | ISO and IEC jointly | National Institute of Standards and Technology (NIST), United States Department of Commerce |
| Current version | ISO/IEC 27001:2022, third edition | CSF 2.0, released 26 February 2024 |
| Structure | Management system clauses plus Annex A, 93 controls in four themes | Six Functions: Govern, Identify, Protect, Detect, Respond, Recover, broken into Categories and Subcategories |
| Maturity model | None built in, conformity is pass or fail | Tiers 1 to 4, from Partial to Adaptive |
| Scoping instrument | Statement of Applicability, driven by risk assessment | Current Profile and Target Profile |
| Assessment | Stage 1 and Stage 2 audit by an accredited certification body | Self assessment or a third party assessment, at the organisation’s choice |
| Result | A certificate | No certificate, an alignment or assessment statement |
| Validity | Three years, with annual surveillance audits | Not applicable |
| Cost of the document | The standard is purchased from ISO or a national member body | The framework is published free of charge by NIST |
| Common demand driver | International tenders, customer security questionnaires, regulators | United States federal supply chains, board level risk reporting, programme prioritisation |
Using both together
They are not alternatives so much as different layers. The NIST framework is good at organising a conversation about risk with executives, because Functions, Tiers and Profiles map neatly to where you are, where you want to be and what it will cost. ISO/IEC 27001 is good at proving the result to a third party, because the certificate carries accreditation behind it.
In practice, organisations often use the CSF Functions to run gap analysis and prioritisation, then implement the resulting controls inside an ISMS built to ISO/IEC 27001 so that the work is certifiable. Much of the evidence serves both: asset inventories, risk assessments, access control records, logging and monitoring, incident response records, business continuity tests and supplier assessments. What does not carry across is the assurance itself, since no amount of CSF alignment produces an ISO certificate.
Which one applies to you?
- ISO/IEC 27001 if a customer, tender or regulator asks for a certificate, if you sell internationally, or if you need a single artefact that a procurement team can verify with the certification body and its accreditation body.
- NIST CSF if you need a risk led way to structure and prioritise a security programme, if you work with United States federal agencies or their supply chains where the framework is a common reference, or if you want to start improving without committing to an audit cycle.
- Both if you want the internal clarity of the CSF and the external proof of certification. The usual sequence is CSF for assessment and roadmap, ISO/IEC 27001 for the management system and the certificate.
- Do not claim to be NIST CSF certified. No such certificate exists. The accurate wording is aligned to, or assessed against, the NIST Cybersecurity Framework.
Frequently Asked Questions
Can an organisation be certified against the NIST Cybersecurity Framework?
No. The framework is a voluntary set of outcomes published by NIST, and NIST does not operate a certification scheme, accredit assessors or issue certificates against it. Organisations can be assessed against it or state that they are aligned to it, but there is no certificate.
Who publishes each one?
ISO/IEC 27001 is published jointly by the International Organization for Standardization and the International Electrotechnical Commission. The Cybersecurity Framework is published by the National Institute of Standards and Technology, part of the United States Department of Commerce.
How many controls does ISO/IEC 27001:2022 have?
Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. Which of them apply to a given organisation is determined by its risk assessment and recorded in the Statement of Applicability.
What are the six Functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond and Recover. Govern was introduced in version 2.0, which was released on 26 February 2024, and it covers cybersecurity risk management strategy, roles, policy and oversight.
How long is an ISO 27001 certificate valid?
Normally three years, subject to annual surveillance audits by the certification body, with a recertification audit before the certificate expires. The NIST framework has no equivalent, because there is nothing to expire.
If we already follow the NIST CSF, how much shorter is our route to ISO 27001?
Usually a good deal shorter on controls and evidence, because risk assessment, asset management, access control, logging, incident response and continuity work all carry across. What still has to be built is the management system itself: scope, information security policy, risk treatment plan, Statement of Applicability, internal audit and management review, followed by the Stage 1 and Stage 2 audits.
Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.
Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.








