Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
NIST CSF vs ISO 27001

NIST CSF vs ISO 27001: a framework or a certificate?

NIST CSF is a voluntary framework of outcomes with no certificate; ISO 27001 is a certifiable management system standard. When each fits, and how the same evidence serves both.

The short answer

The NIST Cybersecurity Framework describes the outcomes a security program should achieve, in six functions, and you measure yourself against it with a profile; there is no certificate. ISO 27001 specifies a management system and is certified by an accredited body. US buyers, insurers and regulators often reference the CSF; international buyers ask for the ISO certificate. They map to each other closely, so most companies use the CSF as the structure for reporting posture and ISO 27001 as the proof.

Side by side

NIST CSF and ISO 27001, row by row

NIST CSFISO 27001
What it isA voluntary framework of outcomes (six functions, 106 subcategories in version 2.0)A certifiable standard for an information security management system
CertificateNone; a current and a target profileYes, from an accredited certification body
Who asks for itUS regulators, insurers, boards and enterprise buyersBuyers worldwide, especially Europe, UK and Asia-Pacific
PrescriptivenessWhat to achieve, with informative references to controlsWhat the management system must do, with 93 reference controls
TimeA first profile in days once systems are connectedThree to six months to Stage 2
With ViglynEvery subcategory mapped to controls; the profile scored from evidenceThe ISMS on the same evidence; audits in the platform
Straight answers

The questions that decide it

Can NIST CSF replace ISO 27001?

For a US buyer or insurer who asks for CSF alignment, a profile with evidence behind it is what they want. For a buyer who asks for ISO 27001, nothing but the certificate will do. Many companies run both because the CSF is how they talk about posture and ISO 27001 is how they prove it.

Which is faster to show buyers?

A NIST CSF current profile, which Viglyn scores from evidence in days. ISO 27001 takes months because the certificate requires the management system to exist and be audited. If a deal needs something soon, the profile buys time while the certification runs.

Do they use the same evidence?

Largely. NIST publishes informative references from CSF subcategories to ISO 27001 controls, and Viglyn applies the same mappings, so access, logging, vulnerability, backup and incident evidence counts toward both.

FAQ

More questions

Does the CSF have an audit?
No. You can have an independent assessor review your profile, and some buyers ask for that, but there is no accredited certification. Viglyn's evidence-based profile is what makes a self-declared profile credible.
What changed with CSF 2.0?
A sixth function, Govern, was added, the scope widened from critical infrastructure to all organizations, and the subcategories were reorganized. Profiles built on version 1.1 map across with the published crosswalk.
How much do they cost with Viglyn?
Both count as frameworks included in your plan, from $2,699 a year with implementation by our practitioners. ISO 27001's certification body charges its own fee, which you pay directly; the CSF has no audit fee.

Find out which one you are closer to

A practitioner maps your gaps for the framework you are going for, in the order to close them, and tells you the honest timeline. Free, no account, no card.