Most organisations reference the NIST Cybersecurity Framework; far fewer actually run their security programme on it. We build CSF 2.0 programmes with real current and target profiles, honest tier assessments, and the new Govern function treated as the foundation it is meant to be.
CSF 2.0 is a way of thinking about security across six functions: Govern, Identify, Protect, Detect, Respond and Recover. We turn it into a working programme with measures your board can read and your engineers can act on.
An honest current profile across all six functions and an implementation tier assessment without grade inflation, because a flattering assessment is a useless one. You get a defensible picture of where you genuinely stand.
A target profile matched to your threat model and risk appetite, not a generic aspiration, with a prioritised, costed roadmap that sequences the work by risk reduction per pound spent.
Controls, governance and metrics built into your operations, with board reporting that speaks outcomes rather than acronyms, and periodic reassessment so progress is demonstrated, not asserted.
Anyone can download the CSF. The value lies in an honest assessment, a target profile that reflects your actual threats, and the discipline to measure progress against it. Our Senior Lead Auditors bring precisely that discipline, sharpened by years of assessing security programmes professionally. And where certification matters commercially, we map the CSF profile to ISO 27001, so one programme serves the framework, the certificate, and your customers' questionnaires.
Built around the six functions, with Govern, supply chain and the community profiles treated as first-class.
Implementation tiers used as they were intended, to drive improvement, not to decorate a slide.
One control set serving the framework and the certificate, without duplicate evidence.
Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.
Business context, crown jewels and threat model established, because a target profile only means something relative to what you are defending and from whom.
An evidence-based assessment across all six functions, with an implementation tier reading your leadership can trust.
The destination agreed with leadership, and the route sequenced by risk reduction, cost and dependency.
Controls and governance deployed with your team, with knowledge transfer throughout so the programme belongs to you.
Metrics reported in business language, and periodic reassessment so the profile stays honest as threats and the organisation change.
No, there is no CSF certificate, which is exactly why honesty matters: the framework's value is internal discipline and external credibility, not a badge. Where customers demand a certificate, we map your CSF programme to ISO 27001 and take you through certification on the same control set.
The headline is the sixth function, Govern, elevating leadership, strategy, roles and supply chain oversight to the foundation of the framework. The scope also broadened beyond critical infrastructure to organisations of every size, with community profiles and improved guidance.
They answer different questions: the CSF organises how you think about and improve security; ISO 27001 certifies that a management system operates. Most of our clients run the CSF as the improvement engine and hold ISO 27001 as the proof: one programme, two purposes.
A focused current-profile assessment for a mid-sized organisation typically takes three to five weeks including evidence review and interviews. You will have a realistic plan from the scoping call.
A 30-minute scoping call with a senior lead auditor, and an honest reading of your security programme.