NIST CSF 2.0

Profile your security against NIST CSF 2.0

We build your current and target profiles across all six functions, score each subcategory and turn the difference into a roadmap leadership can fund.

Book a NIST CSF 2.0 assessmentSee a sample report
VersionCSF 2.0 (2024)
Maintained byUS National Institute of Standards and Technology
Structure6 functions · 22 categories · 106 subcategories
Suited toAny sector, and US critical infrastructure
01 · The framework

The six functions

Version 2.0 adds Govern, which sits across the other five and covers strategy, roles, policy and supply chain risk.

GVGovernStrategy, roles, policy, oversight and supply chain risk management.
IDIdentifyAssets, risk assessment and improvement.
PRProtectIdentity and access, awareness, data, platform and infrastructure security.
DEDetectContinuous monitoring and adverse event analysis.
RSRespondIncident management, analysis, reporting and mitigation.
RCRecoverRecovery plan execution and communication.
02 · Tiers

Implementation Tiers

Tiers describe how rigorous your cyber risk governance and management are. We agree a target tier alongside your target profile.

Tier 1PartialAd hoc and reactive.
Tier 2Risk informedApproved practices, not yet organisation-wide.
Tier 3RepeatableFormal policy, applied consistently.
Tier 4AdaptiveContinuously improved from lessons learned and threat intelligence.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for NIST CSF 2.0 counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
CIS 18 (CIS Controls v8.1) ISO/IEC 27001:2022 SOC 2

Know where you stand against NIST CSF 2.0 in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a NIST CSF 2.0 assessment