NIST CSF 2.0 · Govern · Profiles
NIST CSF 2.0 gap assessment: where you are, where you want to be and what to fix first
Your US parent or a large customer asks about NIST CSF, the board wants one maturity picture, and NIS2 and ISO/IEC 27001 are already on your plate. We build your Current and Target Profiles across the six CSF 2.0 Functions and a prioritized plan to close the gap. The same assessment shows your gaps against ISO/IEC 27001 and NIS2.
// In short
What a NIST CSF 2.0 assessment is
The NIST Cybersecurity Framework 2.0 is a voluntary framework for managing cybersecurity risk, published by the US National Institute of Standards and Technology on 26 February 2024. It describes outcomes in six Functions, from Govern to Recover, not specific controls. An assessment produces a Current Profile, a Target Profile and a plan to close the gap between them.
As of 24 September 2026. Source: NIST CSWP 29.
// What we do
Six Functions, one maturity picture
CSF 2.0 has 22 Categories across six Functions: Govern, Identify, Protect, Detect, Respond and Recover. We score each outcome on what we can see in your systems, not only on questionnaire answers.
01Govern
The Govern Function (GV), new in 2.0
Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV) and Supply Chain Risk Management (GV.SC). We check whether leadership sees the results and makes decisions, rather than just signing documents.
02Current Profile
Current Profile backed by evidence
The CSF outcomes you achieve today. Every rating points to an artifact: a configuration, a log, a procedure with its review date or a test result.
03Target Profile
Target Profile agreed with leadership
The outcomes you select and prioritize. A Community Profile for your sector can be the starting point.
04Tiers
Tiers from Partial to Adaptive
Partial (1), Risk Informed (2), Repeatable (3) and Adaptive (4) describe how rigorous your risk governance and management are. Not every area needs Tier 4.
05Mapping
One assessment, several regimes
We map CSF outcomes to ISO/IEC 27001:2022 Annex A controls and to the NIS2 Article 21 measures, including NIS2 in Poland (KSC). You see which gap blocks several goals at once.
06Action plan
An action plan with owners
We turn the gap between the Profiles into a plan with priorities, owners and dates. Once it is delivered, we update the Current Profile.
// Who it is for
When NIST CSF makes sense in Europe
CSF does not replace NIS2 obligations or ISO/IEC 27001 requirements. It helps you set priorities and show progress in one language.
Groups with a US parent
- Headquarters reports maturity against CSF and expects the same from European subsidiaries
- One group Target Profile, with local obligations added alongside
Customers and partners
- Security questionnaires organized by CSF Functions
- A Current Profile as a ready answer, with evidence for each outcome
The board
- One maturity picture instead of separate reports for NIS2, ISO and IT audit
- Priorities expressed in terms of risk and cost
// How we assess
From Profile scope to action plan
Scope the Profile
The whole company, one plant or one critical process, such as your financial systems. We agree the scope in writing before we start.
Gather information
Policies, the risk register, business impact analysis, configurations and logs. We talk to process owners, not only to IT.
Current and Target Profiles
A rating with evidence for each outcome, then the target outcomes and Tier per Function, agreed with leadership.
Gap analysis and plan
The differences between the Profiles, priorities and an action plan with owners, mapped to ISO/IEC 27001 and NIS2.
Deliver the plan and update the Current Profile
First step: Current and Target Profiles for one scope in 5 weeks
Current Profile with evidence
A rating of the outcomes in all six Functions for the agreed scope, with an artifact behind each rating.
Target Profile and Tiers
Target outcomes and a Tier for each Function, set in a workshop with leadership.
Gap analysis and action plan
A prioritized gap list with owners and dates, referenced to ISO/IEC 27001:2022 Annex A and NIS2 Article 21.
You end up with two Profiles and an action plan, ready for your board
We agree a fixed scope and date in writing before we start. Request the first step
// Scope
What we do and what we don't
We do
- Current and Target Profiles under NIST CSF 2.0
- A Govern review with your leadership in the room
- Mapping of CSF outcomes to ISO/IEC 27001:2022 and NIS2 Article 21
- An action plan with owners and dates
- A follow-up assessment once the plan is delivered
We don't
- Issue a "NIST CSF compliance" certificate: CSF is adopted voluntarily and describes outcomes, not how to achieve them
- Rate you from a questionnaire alone, without evidence from your systems
- Set Adaptive as the target for every area
- Run a formal NIS2 audit or an ISO/IEC 27001 certification audit
For NIS2 obligations see NIS2 compliance in Poland (KSC), and for a certifiable management system see ISO/IEC 27001.
// Read more
Related topics and services
More on risk and security processes on our blog:
// FAQ
Questions about NIST CSF 2.0
How is NIST CSF different from ISO/IEC 27001?
ISO/IEC 27001 is a standard with requirements for an information security management system, certified by accredited bodies. NIST CSF 2.0 is a voluntary framework that describes outcomes in six Functions and leaves the how to you. They work well together: CSF gives you a maturity picture and priorities, ISO/IEC 27001 a management system you can certify.
Does NIST CSF help with NIS2?
Yes, as a way to organize the work. We map CSF outcomes to the NIS2 Article 21 measures, including NIS2 in Poland (the KSC Act), so you can see which gaps block both goals. CSF does not replace your NIS2 obligations or a formal audit.
What changed in version 2.0?
The biggest change is the new Govern Function: organizational context, risk strategy, roles, policy, oversight and supply chain risk. Version 2.0 has 22 Categories across six Functions and was published by NIST on 26 February 2024 (as of 24 September 2026).
Which Tier should we aim for?
That is a leadership decision, not a test result. The Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your risk management is. We usually set a higher Tier where an outage would stop sales or production and a lower one where the risk is small.
How long does the first step take and what do we get?
5 weeks for one scope: a Current Profile with evidence, a Target Profile, a gap analysis and an action plan with owners. We quote after the first call, once we know the scope.
Let's start with your Current Profile
Tell us the scope: the whole company, one site or one process. We reply within one business day, with questions about what you already have for ISO/IEC 27001 and NIS2.
Request the first stepPrefer to talk first?
30 minutes on whether NIST CSF is the right starting point for you.
Book a 30-minute call (opens in a new tab)