The NIST Cybersecurity Framework (NIST CSF) is a voluntary framework from the US National Institute of Standards and Technology that describes the outcomes a good cybersecurity program should achieve. It was created for critical infrastructure but is written for organizations of any size or sector. Rather than prescribing specific tools or controls, it gives a common structure and vocabulary for assessing where security stands today, deciding where it should be, and explaining the gap to leadership.
At a glance
- The CSF is guidance, not a regulation, and there is no official certification against it.
- The current version groups outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
- Organizations compare a current profile with a target profile to set priorities and a roadmap.
- It maps to more detailed standards and control catalogs, so it works as a common language across frameworks.
- Boards, insurers and customers often recognize it, which makes it useful for reporting.
What problem it solves
Many mid-sized companies have security tools but no shared picture of whether the program as a whole is working. Budget requests become lists of products, board updates lack context, and it is hard to tell whether the next dollar should go to identity, backups, monitoring or training.
The CSF offers a neutral, widely understood structure for that conversation. It helps leadership and technical teams agree on what good looks like, see gaps clearly, and explain priorities in business terms. Because it is free, flexible and not tied to any vendor, it is a common starting point for organizations building or reorganizing a cybersecurity program.
How it works
Functions, categories and subcategories. The core of the framework is a hierarchy of outcomes. The six functions cover governance and risk strategy, understanding assets and risks, protecting systems and data, detecting attacks, responding to incidents and recovering from them. Each function breaks into categories and more specific subcategories.
Profiles and tiers. An organization describes where it is and where it wants to be using profiles, and can use tiers to describe how rigorous its risk management is. Both are covered in the next section.
Informative references. The framework points to related standards and control catalogs, including other NIST publications and international standards, so outcomes can be traced to detailed controls.
Using it in practice. Most organizations begin with a risk assessment and a gap assessment against the CSF, often led by an internal security leader or a virtual CISO, then build a prioritized roadmap and report progress against it.
Tiers and profiles
The CSF has no compliance levels and nothing to pass. Its two structures are Implementation Tiers, which describe how rigorous an organization’s cybersecurity risk governance and management are, and Profiles, which describe which outcomes it achieves now and which it is aiming for. Tiers are optional and self-selected; NIST frames them as context for setting the target, not as a maturity score or a goal everyone should push to the top of.
| Tier | What it looks like in practice | How it is set | Typical evidence |
|---|---|---|---|
| Tier 1: Partial | Security handled case by case; limited awareness of cyber risk and supplier risk at the organization level | Self-assessed, or with an advisor | Internal or advisor assessment |
| Tier 2: Risk Informed | Management approves risk practices and priorities reflect business risk, but there is no organization-wide policy | Self-assessed, or with an advisor | Internal or advisor assessment |
| Tier 3: Repeatable | Risk practices are formal policy, applied consistently across the organization and updated as threats and the business change | Self-assessed, or with an advisor | Approved policies, risk register, regular reporting |
| Tier 4: Adaptive | Security practices adapt continuously from lessons learned and predictive indicators; cyber risk is managed alongside financial and other business risks | Self-assessed, or with an advisor | Ongoing metrics and executive risk reporting |
Profiles. A Current Profile records which outcomes the organization achieves today and how well; a Target Profile sets the outcomes it has chosen to reach, given its risks, obligations and resources. The gap between them becomes a prioritized action plan. NIST and industry groups also publish Community Profiles, shared baselines for a sector, technology or threat that an organization can adopt as the starting point for its Target Profile.
Higher tiers cost more to reach and run, so the right target depends on risk, regulation and budget. Because none of this is certified, a vendor claiming “Tier 3” or “CSF compliant” is describing its own or an advisor’s assessment; ask to see it. This is an overview, not legal advice; contracts and regulators that reference the CSF may set their own expectations.
When it matters for buyers
- When the board asks how secure the company is. CSF-based reporting gives a consistent, recognizable view.
- When building a security roadmap or budget. The gap between current and target profiles shows where to invest.
- When a regulator, insurer or customer asks about your framework. Alignment with the CSF is a common answer.
- When choosing security services. Mapping offers to CSF functions shows overlaps and gaps.
- When preparing for a formal audit later. The CSF work carries over to certifications and reports.
Our governance, risk and compliance overview covers advisors and platforms that run CSF assessments and track progress.
Questions to ask vendors
- Which CSF functions and categories does your product or service address, and which does it not?
- Can you show how your controls or reports map to the framework?
- For assessments: what method do you use, who performs it, and what do we receive at the end?
- Do you score maturity, and how do you avoid the score becoming the goal?
- Can your platform track our current and target profiles over time?
- How do you map the CSF to other frameworks we must meet, such as ISO/IEC 27001 or customer requirements?
How it differs from ISO/IEC 27001
ISO/IEC 27001 is an international standard with mandatory requirements for an information security management system, and organizations can be certified against it. The NIST CSF is voluntary guidance describing outcomes, with no certification, and is used mainly to assess, plan and communicate. Many organizations use both: the CSF to structure their roadmap and board reporting, and ISO/IEC 27001 or a SOC 2 report to give customers independent assurance. A governance, risk and compliance (GRC) platform can map one set of controls to all of them.
