Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
NIST CSF

NIST CSF 2.0: a current profile and a target profile, both on evidence

Map the six functions and 106 subcategories of the NIST Cybersecurity Framework 2.0 to controls with automated checks, score your current profile from evidence rather than self-assessment, and track the path to your target profile.

What is NIST CSF?

The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the US National Institute of Standards and Technology for managing cybersecurity risk. Version 2.0, released on 26 February 2024, organizes cybersecurity outcomes into six functions: Govern, which sets strategy, roles, policy and oversight; Identify, which covers assets, risks and improvement; Protect, which covers identity, access, awareness, data security, platform security and infrastructure resilience; Detect, which covers continuous monitoring and adverse event analysis; Respond, which covers incident management, analysis, reporting and mitigation; and Recover, which covers restoration and communication. The functions contain 22 categories and 106 subcategories. Organizations use the CSF by building a current profile, the outcomes they achieve today, and a target profile, the outcomes they intend to reach, and by rating their risk governance and management practices on four tiers from Partial to Adaptive. There is no certificate; the value is a common language that regulators, insurers, boards and enterprise buyers in the United States recognize and that maps to other standards.

In one paragraph

The NIST Cybersecurity Framework is the US National Institute of Standards and Technology's voluntary framework for managing cybersecurity risk. Version 2.0, released in February 2024, organizes outcomes into six functions, Govern, Identify, Protect, Detect, Respond and Recover, with 22 categories and 106 subcategories. It is not a certification; organizations describe their posture as a current profile and plan improvements toward a target profile, and it is widely referenced by US regulators, insurers and enterprise buyers.

Who it's for

Companies selling into US enterprises, critical infrastructure and the public sector, and any security team that wants one structure to report posture to its board.

With Viglyn

How Viglyn runs NIST CSF

  • Every subcategory mapped to a control in the library, with automated checks on identity, access, configuration, logging, vulnerability and backup evidence across your cloud, device and code systems
  • A current profile scored from evidence, by function and category, instead of a self-assessment spreadsheet
  • A target profile and the gap between the two, with each gap linked to the control, the owner and the evidence that will close it
  • Govern outcomes (strategy, roles, policy, supply-chain risk) held as dated documents with a full audit trail, and third-party risk run in the vendor module
  • Informative references used both ways: the same evidence counts toward SOC 2, ISO 27001 and NIST 800-53
Straight answers

The NIST CSF questions that decide it

Is NIST CSF a certification?

No. There is no NIST CSF certificate or auditor. You describe your posture as a profile and show the evidence behind it. Buyers and insurers who ask for NIST CSF alignment want that evidence and the plan to your target profile, which is what Viglyn produces.

How long does a NIST CSF profile take?

A first current profile takes days once your systems are connected, because most Protect and Detect subcategories are scored from automated checks. Writing the Govern documents and agreeing the target profile with leadership is where the weeks go, and our practitioners do that with you.

How much does NIST CSF cost with Viglyn?

NIST CSF counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no auditor fee because there is no audit.

Compared with

NIST CSF against the standards it is weighed with

FAQ

More NIST CSF questions

What changed in CSF 2.0?
The Govern function was added to make governance and supply-chain risk explicit, the scope widened from critical infrastructure to all organizations, and NIST published implementation examples and quick-start guides. Subcategories were reorganized; version 1.1 profiles map across with the published crosswalk.
How does NIST CSF relate to NIST 800-53 and ISO 27001?
The CSF describes outcomes; NIST 800-53 and ISO 27001 Annex A describe the controls that achieve them. NIST publishes informative references between them, and Viglyn uses the same mappings so one piece of evidence counts in all three.
What are the CSF tiers?
Four levels, Partial, Risk Informed, Repeatable and Adaptive, that describe how rigorous and integrated your risk governance and management practices are. They are not maturity scores to be audited; they help you decide how far you want to go.

See NIST CSF run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.