NIST CSF 2.0 · Cybersecurity Framework

A security programme, not a poster on the wall.

Most organisations reference the NIST Cybersecurity Framework; far fewer actually run their security programme on it. We build CSF 2.0 programmes with real current and target profiles, honest tier assessments, and the new Govern function treated as the foundation it is meant to be.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

From framework reference to operating reality.

CSF 2.0 is a way of thinking about security across six functions: Govern, Identify, Protect, Detect, Respond and Recover. We turn it into a working programme with measures your board can read and your engineers can act on.

01

Maturity Assessment

An honest current profile across all six functions and an implementation tier assessment without grade inflation, because a flattering assessment is a useless one. You get a defensible picture of where you genuinely stand.

02

Target Profile & Roadmap

A target profile matched to your threat model and risk appetite, not a generic aspiration, with a prioritised, costed roadmap that sequences the work by risk reduction per pound spent.

03

Implementation & Measurement

Controls, governance and metrics built into your operations, with board reporting that speaks outcomes rather than acronyms, and periodic reassessment so progress is demonstrated, not asserted.

Why Cybercontrols

The framework is free. The judgement is the product.

Anyone can download the CSF. The value lies in an honest assessment, a target profile that reflects your actual threats, and the discipline to measure progress against it. Our Senior Lead Auditors bring precisely that discipline, sharpened by years of assessing security programmes professionally. And where certification matters commercially, we map the CSF profile to ISO 27001, so one programme serves the framework, the certificate, and your customers' questionnaires.

CSF 2.0 native

Built around the six functions, with Govern, supply chain and the community profiles treated as first-class.

Honest tiers

Implementation tiers used as they were intended, to drive improvement, not to decorate a slide.

Maps to ISO 27001

One control set serving the framework and the certificate, without duplicate evidence.

Senior-led, always

Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.

How it works

From current profile to measured progress, without surprises.

Step 1

Scope & context

Business context, crown jewels and threat model established, because a target profile only means something relative to what you are defending and from whom.

Step 2

Current profile

An evidence-based assessment across all six functions, with an implementation tier reading your leadership can trust.

Step 3

Target profile & roadmap

The destination agreed with leadership, and the route sequenced by risk reduction, cost and dependency.

Step 4

Implement

Controls and governance deployed with your team, with knowledge transfer throughout so the programme belongs to you.

Step 5

Measure & reassess

Metrics reported in business language, and periodic reassessment so the profile stays honest as threats and the organisation change.

Questions we hear most

NIST CSF, answered plainly.

Is NIST CSF certifiable?

No, there is no CSF certificate, which is exactly why honesty matters: the framework's value is internal discipline and external credibility, not a badge. Where customers demand a certificate, we map your CSF programme to ISO 27001 and take you through certification on the same control set.

What changed in CSF 2.0?

The headline is the sixth function, Govern, elevating leadership, strategy, roles and supply chain oversight to the foundation of the framework. The scope also broadened beyond critical infrastructure to organisations of every size, with community profiles and improved guidance.

NIST CSF or ISO 27001, which should we choose?

They answer different questions: the CSF organises how you think about and improve security; ISO 27001 certifies that a management system operates. Most of our clients run the CSF as the improvement engine and hold ISO 27001 as the proof: one programme, two purposes.

How long does an assessment take?

A focused current-profile assessment for a mid-sized organisation typically takes three to five weeks including evidence review and interviews. You will have a realistic plan from the scoping call.

Ready to know exactly where you stand?

A 30-minute scoping call with a senior lead auditor, and an honest reading of your security programme.