NIST CSF is the framework nobody audits you against and everybody borrows from. Version 2.0 added a governance function and dropped the critical infrastructure framing, which is why it started appearing in questionnaires aimed at startups.
The short answer
NIST CSF is the Cybersecurity Framework published by the US National Institute of Standards and Technology. It organises security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is voluntary and there is no certificate. Its value is as a common vocabulary for describing a security programme and measuring where it currently sits against where you want it to be.
That absence of an audit is the point people miss. NIST CSF is a way of thinking about coverage, not a bar to clear.
On this page
The six NIST CSF functions
| Function | What it covers |
|---|---|
| Govern | Strategy, roles, policy, risk appetite and supply chain oversight, which is largely the territory of GRC |
| Identify | Asset inventory, risk assessment and understanding what you actually run |
| Protect | Access control, data security, endpoint protection, awareness training and platform hardening |
| Detect | Monitoring, logging and correlation across the estate |
| Respond | Incident response, analysis, containment and communication |
| Recover | Restoration, recovery planning and the improvements that follow an incident |
What changed in version 2.0
Version 2.0 was published in February 2024 and made two changes that matter to anyone outside the United States government supply chain.
The first is Govern. Version 1.1 had five functions, all operational. Adding governance moved accountability, roles and risk appetite into the framework itself, which is what lets a security programme be described to a board rather than only to engineers.
The second is scope. Version 1.1 was framed around critical infrastructure. Version 2.0 dropped that framing and is written for organisations of any size or sector, which is a large part of why NIST CSF now shows up in vendor questionnaires sent to small companies that have nothing to do with power grids.
Tiers and profiles
The functions describe what to cover. Tiers and profiles are how you say where you are and where you are going.
| Concept | What it means |
|---|---|
| Tier 1, Partial | Ad hoc, reactive, little organisational awareness of risk |
| Tier 2, Risk Informed | Risk is understood but practice is inconsistent and rarely documented |
| Tier 3, Repeatable | Formal policy, consistently applied and updated as things change |
| Tier 4, Adaptive | Practice adjusts continuously from lessons learned and threat intelligence |
| Current Profile | An honest description of what you do today, function by function |
| Target Profile | Where you intend to be, given your risk and your budget |
Tier 4 is not the goal
Tiers are not maturity grades to climb. NIST is explicit that the appropriate tier depends on your risk, your resources and your obligations, and that a small company operating well at Tier 2 or 3 may be exactly where it should be. Treating Tier 4 as a target is how teams end up buying tooling they cannot staff.
NIST CSF and ISO 27001
| NIST CSF | ISO 27001 | |
|---|---|---|
| Type | Voluntary framework | Certifiable standard |
| Outcome | A profile and a gap picture | A certificate from an accredited body |
| Structure | Six functions with outcome statements | An ISMS plus Annex A controls |
| Best used for | Organising and communicating a programme | Proving one to a buyer or regulator |
| Cost to reach | Time only | Audit fees and an ongoing surveillance cycle |
They are complements rather than alternatives. A common pattern is to use NIST CSF to structure the programme and decide sequencing, then certify against ISO 27001 or report under SOC 2 when a buyer needs evidence they can file.
Where NIST CSF gets asked for
| Context | What is expected |
|---|---|
| US enterprise vendor review | A self-assessment against the functions, often inside a larger security questionnaire |
| Cyber insurance | Underwriters use the functions as a structure for assessing controls, particularly Detect and Respond |
| Board and investor reporting | A profile is easier to present than a control list, which is what Govern was added for |
| Indian regulatory frameworks | SEBI CSCRF uses the same functional vocabulary of identify, protect, detect, respond and recover |
| Internal planning | The most common honest use: deciding what to fix next when everything looks urgent |
How Osto maps to NIST CSF
The six functions correspond closely to how the platform is built. Identify covers asset and API discovery plus cloud posture. Protect covers access, endpoint, web and data controls. Detect is SIEM and correlation across those modules. Respond and Recover attach to incident response. Govern is where the GRC layer sits.
Because the controls run in one stack, a current profile is something you can read rather than assemble. That matters most when NIST CSF is being used the way it was designed to be used, as a coverage picture, since a gap in Detect is usually a gap in what you can see rather than a missing document. The same control set maps to SOC 2, ISO 27001, GDPR and over 200 other frameworks at the same time.
Platform walkthrough
A profile you can read, not assemble
Identify, protect, detect, respond and recover running as live controls in one stack, mapped to SOC 2, ISO 27001 and 200+ frameworks from the same evidence base. One owner, one dashboard.
Book a demoCoverage across all six functions · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is NIST CSF?
The Cybersecurity Framework from the US National Institute of Standards and Technology. It organises security into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and provides tiers and profiles for describing current and target state. It is voluntary.
Can you get certified against NIST CSF?
No. There is no certification scheme and no accredited body issuing NIST CSF certificates. Organisations self-assess, or engage an assessor for an independent view. When a buyer wants a certificate, ISO 27001 or SOC 2 is the answer.
What changed in NIST CSF 2.0?
Published in February 2024, it added Govern as a sixth function covering strategy, roles, risk appetite and supply chain, and removed the critical infrastructure framing so the framework applies to organisations of any size or sector.
Should we use NIST CSF or ISO 27001?
Usually both, for different jobs. NIST CSF structures the programme and shows where the gaps are. ISO 27001 produces a certificate a buyer or regulator can accept. Using the framework to plan and the standard to prove is the common sequence.
Is NIST CSF relevant outside the United States?
Yes. Version 2.0 is written for any organisation, and the functional vocabulary appears in insurance assessments, enterprise questionnaires and regulatory frameworks including SEBI CSCRF in India.

