NIST CSF 2.0 · Govern · Profiles

NIST CSF 2.0 gap assessment: where you are, where you want to be and what to fix first

Your US parent or a large customer asks about NIST CSF, the board wants one maturity picture, and NIS2 and ISO/IEC 27001 are already on your plate. We build your Current and Target Profiles across the six CSF 2.0 Functions and a prioritized plan to close the gap. The same assessment shows your gaps against ISO/IEC 27001 and NIS2.

// In short

What a NIST CSF 2.0 assessment is

The NIST Cybersecurity Framework 2.0 is a voluntary framework for managing cybersecurity risk, published by the US National Institute of Standards and Technology on 26 February 2024. It describes outcomes in six Functions, from Govern to Recover, not specific controls. An assessment produces a Current Profile, a Target Profile and a plan to close the gap between them.

As of 24 September 2026. Source: NIST CSWP 29.

// What we do

Six Functions, one maturity picture

CSF 2.0 has 22 Categories across six Functions: Govern, Identify, Protect, Detect, Respond and Recover. We score each outcome on what we can see in your systems, not only on questionnaire answers.

  1. 01Govern

    The Govern Function (GV), new in 2.0

    Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV) and Supply Chain Risk Management (GV.SC). We check whether leadership sees the results and makes decisions, rather than just signing documents.

  2. 02Current Profile

    Current Profile backed by evidence

    The CSF outcomes you achieve today. Every rating points to an artifact: a configuration, a log, a procedure with its review date or a test result.

  3. 03Target Profile

    Target Profile agreed with leadership

    The outcomes you select and prioritize. A Community Profile for your sector can be the starting point.

  4. 04Tiers

    Tiers from Partial to Adaptive

    Partial (1), Risk Informed (2), Repeatable (3) and Adaptive (4) describe how rigorous your risk governance and management are. Not every area needs Tier 4.

  5. 05Mapping

    One assessment, several regimes

    We map CSF outcomes to ISO/IEC 27001:2022 Annex A controls and to the NIS2 Article 21 measures, including NIS2 in Poland (KSC). You see which gap blocks several goals at once.

  6. 06Action plan

    An action plan with owners

    We turn the gap between the Profiles into a plan with priorities, owners and dates. Once it is delivered, we update the Current Profile.

// Who it is for

When NIST CSF makes sense in Europe

CSF does not replace NIS2 obligations or ISO/IEC 27001 requirements. It helps you set priorities and show progress in one language.

Groups with a US parent

  • Headquarters reports maturity against CSF and expects the same from European subsidiaries
  • One group Target Profile, with local obligations added alongside

Customers and partners

  • Security questionnaires organized by CSF Functions
  • A Current Profile as a ready answer, with evidence for each outcome

The board

  • One maturity picture instead of separate reports for NIS2, ISO and IT audit
  • Priorities expressed in terms of risk and cost

// How we assess

From Profile scope to action plan

  1. Scope the Profile

    The whole company, one plant or one critical process, such as your financial systems. We agree the scope in writing before we start.

  2. Gather information

    Policies, the risk register, business impact analysis, configurations and logs. We talk to process owners, not only to IT.

  3. Current and Target Profiles

    A rating with evidence for each outcome, then the target outcomes and Tier per Function, agreed with leadership.

  4. Gap analysis and plan

    The differences between the Profiles, priorities and an action plan with owners, mapped to ISO/IEC 27001 and NIS2.

Deliver the plan and update the Current Profile

First step: Current and Target Profiles for one scope in 5 weeks

  1. Current Profile with evidence

    A rating of the outcomes in all six Functions for the agreed scope, with an artifact behind each rating.

  2. Target Profile and Tiers

    Target outcomes and a Tier for each Function, set in a workshop with leadership.

  3. Gap analysis and action plan

    A prioritized gap list with owners and dates, referenced to ISO/IEC 27001:2022 Annex A and NIS2 Article 21.

You end up with two Profiles and an action plan, ready for your board

We agree a fixed scope and date in writing before we start. Request the first step

// Scope

What we do and what we don't

We do

  • Current and Target Profiles under NIST CSF 2.0
  • A Govern review with your leadership in the room
  • Mapping of CSF outcomes to ISO/IEC 27001:2022 and NIS2 Article 21
  • An action plan with owners and dates
  • A follow-up assessment once the plan is delivered

We don't

  • Issue a "NIST CSF compliance" certificate: CSF is adopted voluntarily and describes outcomes, not how to achieve them
  • Rate you from a questionnaire alone, without evidence from your systems
  • Set Adaptive as the target for every area
  • Run a formal NIS2 audit or an ISO/IEC 27001 certification audit

For NIS2 obligations see NIS2 compliance in Poland (KSC), and for a certifiable management system see ISO/IEC 27001.

// FAQ

Questions about NIST CSF 2.0

How is NIST CSF different from ISO/IEC 27001?

ISO/IEC 27001 is a standard with requirements for an information security management system, certified by accredited bodies. NIST CSF 2.0 is a voluntary framework that describes outcomes in six Functions and leaves the how to you. They work well together: CSF gives you a maturity picture and priorities, ISO/IEC 27001 a management system you can certify.

Does NIST CSF help with NIS2?

Yes, as a way to organize the work. We map CSF outcomes to the NIS2 Article 21 measures, including NIS2 in Poland (the KSC Act), so you can see which gaps block both goals. CSF does not replace your NIS2 obligations or a formal audit.

What changed in version 2.0?

The biggest change is the new Govern Function: organizational context, risk strategy, roles, policy, oversight and supply chain risk. Version 2.0 has 22 Categories across six Functions and was published by NIST on 26 February 2024 (as of 24 September 2026).

Which Tier should we aim for?

That is a leadership decision, not a test result. The Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your risk management is. We usually set a higher Tier where an outage would stop sales or production and a lower one where the risk is small.

How long does the first step take and what do we get?

5 weeks for one scope: a Current Profile with evidence, a Target Profile, a gap analysis and an action plan with owners. We quote after the first call, once we know the scope.

Let's start with your Current Profile

Tell us the scope: the whole company, one site or one process. We reply within one business day, with questions about what you already have for ISO/IEC 27001 and NIS2.

Request the first step

Prefer to talk first?

30 minutes on whether NIST CSF is the right starting point for you.

Book a 30-minute call (opens in a new tab)