NIST CSF 2.0

Align to NIST CSF 2.0 without building a security team first.

The NIST Cybersecurity Framework is the common language many boards, regulators, and enterprise buyers use to describe a security program. A dedicated SecureSlate compliance lead assesses your Current Profile, sets a Target Profile and tier that fit your risk, and builds the program to close the gap, while our compliance automation platform keeps the evidence current. One fixed price covers the work.

NIST CSF 2.022 categories

NIST CSF 2.0: 22 categories, 6 Govern, 3 Identify, 5 Protect, 2 Detect, 4 Respond, 2 Recover. 5 highlighted: Evidenced by included security scanning.

Evidenced by included security scanningScoped with your compliance lead
Current version
CSF 2.0, released February 2024
Structure
6 Functions, 22 Categories, 106 Subcategories
Certification
None, NIST does not certify
The standard

NIST CSF alignment is measured in outcomes and profiles, not a certificate.

NIST CSF 2.0 is a voluntary framework from the US National Institute of Standards and Technology. It describes cybersecurity outcomes any organization can use, and version 2.0 widened its scope well beyond critical infrastructure.

Six Functions, now including Govern

CSF 2.0 organizes outcomes into Govern, Identify, Protect, Detect, Respond, and Recover, with 22 Categories and 106 Subcategories beneath them. Govern, added in 2.0, covers strategy, roles, policy, oversight, and supply chain risk.

Profiles show where you are and where you are going

A Current Profile records the outcomes you achieve today, and a Target Profile records the outcomes your risk calls for. The gap between them becomes your plan, which is what boards and buyers actually ask to see.

Tiers describe how rigorous your practices are

Implementation Tiers run from Partial through Risk Informed and Repeatable to Adaptive. They are not a maturity score to maximize, but a way to decide how formal your governance and risk management should be.
How it works

We turn NIST CSF into a program you can show a board or a buyer.

Four stages from the scoping call to a measured program, with a named compliance lead accountable at every one.

Scope and Current Profile

We agree which business units, systems, and risks are in scope, then assess how your current practices map to each CSF Category and Subcategory to build your Current Profile.

Target Profile and tier

Your compliance lead works with leadership to set a Target Profile and Implementation Tier that match your risk appetite, regulatory exposure, and customer expectations.

Close the gaps

Policies, controls, and processes implemented in priority order, from governance and supply chain risk to monitoring and incident response, with integrations and scanning collecting evidence continuously.

Measure, report, and repeat

Progress tracked against the Target Profile and reported in terms leadership understands, then reassessed as threats and the business change, so alignment stays current rather than a one-time exercise.
What is included

Everything a NIST CSF assessment looks at, prepared before they ask.

NIST CSF compliance software and the expert who runs it arrive together under one fixed price, so the program does not land on your engineers.

A dedicated compliance lead

One experienced practitioner owns your NIST CSF program end to end. They build the Current and Target Profiles, prioritize the gaps, write the policies, and report progress to leadership, so your team approves instead of interpreting the framework.

Profiles and a gap assessment

A Current Profile and Target Profile documented against the CSF Categories, with each gap scored, owned, and scheduled so the roadmap is clear.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Controls are tested continuously against live configuration, and when one fails, SecureSlate AI finds the gap and prepares a fix for your team to approve.

Risk and supply chain management

Cybersecurity risks and third-party suppliers assessed and tracked with owners, covering the Govern and Identify outcomes that CSF 2.0 moved to the front of the framework.

Access, training, and devices

Access reviews, security awareness training, and device checks run on a schedule, with evidence for the identity, training, and platform outcomes in the Protect function.

Monitoring and incident readiness

Continuous monitoring, alerting, and an incident response plan you have tested, covering the Detect, Respond, and Recover functions with records of what happened and what you did.
Identify, Protect, and Detect evidence

Several NIST CSF outcomes need evidence from your code and cloud, not a policy.

Risk assessment, platform security, and continuous monitoring are judged against what actually runs. Security scanning is part of the engagement, so the evidence comes from your real repositories, domains, and cloud accounts.
ID.RA Risk Assessment, PR.PS Platform Security

Code security scanning

Repositories scanned for vulnerable code, with findings ranked by severity and traced to the line, which evidences vulnerability identification and secure software development.
PR.AA Identity and Access Control

Secrets detection

API keys, tokens, and credentials committed to source code, found and pinpointed to the file and line, so credentials are managed rather than exposed in repositories.
ID.RA Risk Assessment

Dependency and license risk

An SBOM for every repository, with vulnerable open source components flagged, so third-party software vulnerabilities are identified and recorded in your risk assessment.
ID.RA Risk Assessment, DE.CM Continuous Monitoring

Public surface monitoring

Your domains and forgotten subdomains scanned on a schedule and when you ship, identifying vulnerabilities and keeping watch on your external attack surface.
ID.RA Risk Assessment

Dark web monitoring

Company email addresses checked against known breach data, adding threat intelligence about exposed credentials to your risk assessment.
PR.PS Platform Security, PR.DS Data Security

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access for risky settings in encryption, access, logging, and networking.
Beyond NIST CSF

One program, several frameworks.

NIST CSF maps to the standards and regulations your buyers and auditors already use, so aligning to it strengthens the rest of your program.

ISO 27001

The certifiable standard many CSF-aligned programs pursue when buyers want independent proof, with extensive mapping between the two.

SOC 2

The attestation US buyers ask for. CSF outcomes and the Trust Services Criteria overlap heavily, so the same evidence serves both.

CMMC

Defense contractors implement NIST SP 800-171 for CMMC, and the CSF provides the governance and risk layer around it.

HIPAA

HHS has published crosswalks between the HIPAA Security Rule and the NIST Cybersecurity Framework, so CSF alignment supports a HIPAA program.

PCI DSS

Payment security requirements fit inside a CSF-aligned program, with PCI DSS adding cardholder data controls and annual validation.

NIST AI RMF

NIST's framework for AI risk, which follows a similar govern, map, measure, and manage structure for AI systems.
NIST CSF guides

What a NIST CSF assessment actually looks at

Three guides your team can read before the scoping call, from what changed in version 2.0 to how the tiers work.

CSF 2.0
What changed in NIST CSF 2.0, including the new Govern function
Tiers 1 to 4
How the Implementation Tiers work and how to choose yours
CSF vs ISO
How NIST CSF and ISO 27001 compare, and when to use both
Resources

Read up before your scoping call.

Practical guides to NIST CSF, from its outcomes to how it compares with other frameworks.

FAQs

What teams ask before aligning to NIST CSF.

Find out what NIST CSF alignment will take

Bring your current security program and the stakeholders asking about it. You will leave the call with a gap summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?