What Is NIST CSF (NIST Cybersecurity Framework)?

Related problems: The board wants a clear picture of our cybersecurity maturity; No common structure for our security roadmap and budget; Customers or partners ask which framework we follow; Not sure where to start with a security program

The NIST Cybersecurity Framework (NIST CSF) is a voluntary framework from the US National Institute of Standards and Technology that describes the outcomes a good cybersecurity program should achieve. It was created for critical infrastructure but is written for organizations of any size or sector. Rather than prescribing specific tools or controls, it gives a common structure and vocabulary for assessing where security stands today, deciding where it should be, and explaining the gap to leadership.

At a glance

  • The CSF is guidance, not a regulation, and there is no official certification against it.
  • The current version groups outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
  • Organizations compare a current profile with a target profile to set priorities and a roadmap.
  • It maps to more detailed standards and control catalogs, so it works as a common language across frameworks.
  • Boards, insurers and customers often recognize it, which makes it useful for reporting.

What problem it solves

Many mid-sized companies have security tools but no shared picture of whether the program as a whole is working. Budget requests become lists of products, board updates lack context, and it is hard to tell whether the next dollar should go to identity, backups, monitoring or training.

The CSF offers a neutral, widely understood structure for that conversation. It helps leadership and technical teams agree on what good looks like, see gaps clearly, and explain priorities in business terms. Because it is free, flexible and not tied to any vendor, it is a common starting point for organizations building or reorganizing a cybersecurity program.

How it works

Functions, categories and subcategories. The core of the framework is a hierarchy of outcomes. The six functions cover governance and risk strategy, understanding assets and risks, protecting systems and data, detecting attacks, responding to incidents and recovering from them. Each function breaks into categories and more specific subcategories.

Profiles and tiers. An organization describes where it is and where it wants to be using profiles, and can use tiers to describe how rigorous its risk management is. Both are covered in the next section.

Informative references. The framework points to related standards and control catalogs, including other NIST publications and international standards, so outcomes can be traced to detailed controls.

Using it in practice. Most organizations begin with a risk assessment and a gap assessment against the CSF, often led by an internal security leader or a virtual CISO, then build a prioritized roadmap and report progress against it.

Tiers and profiles

The CSF has no compliance levels and nothing to pass. Its two structures are Implementation Tiers, which describe how rigorous an organization’s cybersecurity risk governance and management are, and Profiles, which describe which outcomes it achieves now and which it is aiming for. Tiers are optional and self-selected; NIST frames them as context for setting the target, not as a maturity score or a goal everyone should push to the top of.

Tier What it looks like in practice How it is set Typical evidence
Tier 1: Partial Security handled case by case; limited awareness of cyber risk and supplier risk at the organization level Self-assessed, or with an advisor Internal or advisor assessment
Tier 2: Risk Informed Management approves risk practices and priorities reflect business risk, but there is no organization-wide policy Self-assessed, or with an advisor Internal or advisor assessment
Tier 3: Repeatable Risk practices are formal policy, applied consistently across the organization and updated as threats and the business change Self-assessed, or with an advisor Approved policies, risk register, regular reporting
Tier 4: Adaptive Security practices adapt continuously from lessons learned and predictive indicators; cyber risk is managed alongside financial and other business risks Self-assessed, or with an advisor Ongoing metrics and executive risk reporting

Profiles. A Current Profile records which outcomes the organization achieves today and how well; a Target Profile sets the outcomes it has chosen to reach, given its risks, obligations and resources. The gap between them becomes a prioritized action plan. NIST and industry groups also publish Community Profiles, shared baselines for a sector, technology or threat that an organization can adopt as the starting point for its Target Profile.

Higher tiers cost more to reach and run, so the right target depends on risk, regulation and budget. Because none of this is certified, a vendor claiming “Tier 3” or “CSF compliant” is describing its own or an advisor’s assessment; ask to see it. This is an overview, not legal advice; contracts and regulators that reference the CSF may set their own expectations.

When it matters for buyers

  • When the board asks how secure the company is. CSF-based reporting gives a consistent, recognizable view.
  • When building a security roadmap or budget. The gap between current and target profiles shows where to invest.
  • When a regulator, insurer or customer asks about your framework. Alignment with the CSF is a common answer.
  • When choosing security services. Mapping offers to CSF functions shows overlaps and gaps.
  • When preparing for a formal audit later. The CSF work carries over to certifications and reports.

Our governance, risk and compliance overview covers advisors and platforms that run CSF assessments and track progress.

Questions to ask vendors

  • Which CSF functions and categories does your product or service address, and which does it not?
  • Can you show how your controls or reports map to the framework?
  • For assessments: what method do you use, who performs it, and what do we receive at the end?
  • Do you score maturity, and how do you avoid the score becoming the goal?
  • Can your platform track our current and target profiles over time?
  • How do you map the CSF to other frameworks we must meet, such as ISO/IEC 27001 or customer requirements?

How it differs from ISO/IEC 27001

ISO/IEC 27001 is an international standard with mandatory requirements for an information security management system, and organizations can be certified against it. The NIST CSF is voluntary guidance describing outcomes, with no certification, and is used mainly to assess, plan and communicate. Many organizations use both: the CSF to structure their roadmap and board reporting, and ISO/IEC 27001 or a SOC 2 report to give customers independent assurance. A governance, risk and compliance (GRC) platform can map one set of controls to all of them.

Frequently Asked Questions

Is the NIST CSF mandatory?
For most private companies, no. It is voluntary guidance from the US National Institute of Standards and Technology. Some regulators, contracts, insurers and industry programs reference it or expect alignment with it, so check what applies to your sector.
Can we be certified against the NIST CSF?
No. There is no official CSF certification. Organizations assess themselves or hire an advisor to assess them, and some auditors issue reports describing alignment. If you need a certificate, look at ISO/IEC 27001.
What are the CSF functions?
The current version organizes outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Each breaks down into categories and subcategories that describe specific outcomes, such as managing access or recovering from incidents.
Are CSF tiers the same as maturity levels?
Not exactly. The four tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous an organization's cybersecurity risk governance and management are. NIST presents them as optional context for choosing a target, not a score to maximize, and the right tier depends on your risks and resources.
How is the CSF different from NIST SP 800-53 and 800-171?
The CSF describes outcomes at a high level for any organization. SP 800-53 is a detailed catalog of security and privacy controls used mainly by US federal systems, and SP 800-171 sets requirements for protecting certain sensitive government information held by contractors. They are separate publications, though they can be mapped to each other.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.