Govern (GV)
The 2.0 addition. Organisational context, risk management strategy, roles and responsibilities, policy, oversight and supply-chain risk management. Forces the question of who actually owns cyber risk.
Governance, Risk & Compliance
NIST CSF is not a certification and nobody can sell you one. It is a maturity model — which makes it the right tool when you need a defensible answer to "how mature are we, and what should we fix first" rather than a certificate for a procurement portal.
NIST released Cybersecurity Framework 2.0 in February 2024. The headline change from the 2014 version is a sixth function, GOVERN, which wraps risk strategy, roles, policy and oversight around the original five — Identify, Protect, Detect, Respond and Recover. The second change is scope: CSF 2.0 is explicitly written for organisations of any size and sector, not just critical infrastructure.
Here is the part vendors tend not to volunteer: there is no such thing as NIST CSF certification. It is a voluntary framework, not an auditable standard, and no body accredits assessors or issues certificates against it. Anyone offering you one is describing something that does not exist. What CSF gives you instead is more useful to a board than a badge — a repeatable, defensible picture of where you are, where you should be, and what moving between the two would cost.
The weakness of most CSF assessments is that they are self-attested. Someone is asked whether the organisation detects anomalous activity, they say yes, and a score is recorded. We check the Detect and Respond functions against actual telemetry, because a maturity score that rests on an optimistic interview is worse than no score at all — it produces confidence without capability.
Coverage
Scored against the four Implementation Tiers, with a current profile and a target profile aligned to your risk appetite and sector rather than to a generic ideal.
The 2.0 addition. Organisational context, risk management strategy, roles and responsibilities, policy, oversight and supply-chain risk management. Forces the question of who actually owns cyber risk.
Asset management, risk assessment and improvement. What you have, what could go wrong with it, and how you learn from what already has.
Identity management and access control, awareness and training, data security, platform security and the resilience of technology infrastructure.
Continuous monitoring and adverse event analysis — assessed against real telemetry rather than an assertion that monitoring exists.
Incident management, analysis, reporting and mitigation. Tested against what actually happened the last time something went wrong.
Incident recovery plan execution and communication. Routinely the weakest function, and routinely the one nobody has exercised.
Approach
The output is a profile and a roadmap, not a pass or a fail. That is a feature: it gives leadership something to sequence and fund rather than a binary they can only argue with.
The systems, business units and risk appetite in play, and what a realistic target profile looks like for your sector and size.
Interviews and evidence review across all six functions, down to category and subcategory level.
Detect and Respond claims checked against live telemetry and control tests, so scores reflect capability rather than intent.
A current profile, a target profile and a tier rating with the reasoning recorded — so the score can be defended when someone challenges it.
A prioritised uplift plan that moves named subcategories toward the target, sequenced by risk reduction per unit of effort.
Re-assessment after uplift so movement is measurable, plus a reporting rhythm your board can actually follow.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
All six functions to subcategory level, scored with the evidence that supports each rating.
Where you are and where you should be, with the gap between them expressed as work rather than as a number.
Partial, Risk Informed, Repeatable or Adaptive — and why, in terms you can defend to an auditor, insurer or board member.
Sequenced by risk reduction per unit of effort, with owners and realistic dates.
One page that says where you stand and what you are asking for, without requiring a security background to read.
Mapped to ISO 27001 and SOC 2 where relevant, so one assessment feeds more than one programme.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. CSF is a voluntary maturity framework, not a certifiable standard. There is no accreditation body, no certificate and no auditor register. Anyone offering NIST CSF certification is selling something that does not exist — which is worth knowing before you buy it. What we deliver is a defensible maturity assessment, a target profile and a roadmap.
The main change is the addition of a sixth function, GOVERN, in the February 2024 release, covering risk strategy, roles and responsibilities, policy, oversight and supply-chain risk. The other significant change is scope: 2.0 is written for organisations of all sizes and sectors rather than being framed around critical infrastructure. Assessments still written around five functions are working from the previous version.
Four: Partial, Risk Informed, Repeatable and Adaptive. They describe the rigour and consistency of your risk management practices, not a grade. Tier 4 is not the right target for every organisation — the appropriate tier depends on your risk appetite, sector and threat exposure, and part of the assessment is agreeing which one you should be aiming at.
CSF is a maturity lens; ISO 27001 is a certifiable management system. They answer different questions — "how good are we" versus "can we prove we run a system". They map onto each other well, so a CSF assessment is a sensible precursor to an ISO 27001 programme, and the evidence gathered for one substantially serves the other. We cross-map deliberately so the work is not duplicated.
Yes, and it is the main reason to have someone external do this. Detect and Respond are validated against actual telemetry and control tests rather than accepted on interview. A self-attested maturity score is a statement of intent, and it tends to be optimistic in exactly the functions where optimism is most expensive.
Organisations reporting to a board, an insurer or a parent company rather than to a certification body. It is also the right first engagement when you know you need to improve but cannot yet articulate what to do first — the roadmap is the deliverable, and it is what makes the security budget conversation a planning exercise rather than an argument.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.