Skip to main content
NIST CSF 2.0 · Security programme

Organise security around outcomes leaders understand.

NIST CSF 2.0 gives executives a shared language for cyber risk. Summit scores your current profile against evidence, validates controls through testing and delivers a prioritised roadmap leadership can fund.

Human-led VAPT · NDA first · report in 48h

6
functions: Govern, Identify, Protect, Detect, Respond and Recover
22
categories grouped under those functions
106
subcategories describing specific outcomes
4
implementation tiers, from Partial to Adaptive
Board and leadership view

Why NIST CSF matters to your board

The work is technical. The consequences of getting NIST CSF 2.0 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Clear reporting to leadership

Six functions turn technical detail into a view of posture that boards can compare quarter to quarter.

Budget decisions

A current and target profile show where spending closes real gaps rather than adding tools.

Customer and buyer confidence

Buyers recognise the framework. Evidence-based scores answer questionnaires with less rework.

Ownership and accountability

The Govern function names owners and risk appetite, so responsibility does not drift.

Fit

Who uses NIST CSF

Enterprises and boards

A clear, non-technical structure for reporting security posture to leadership.

Technology and SaaS vendors

A common reference to answer customer questionnaires without rebuilding answers.

Organisations without a mandate

Teams who want structure now and a path to ISO 27001 or SOC 2 later.

US public-sector suppliers

Government contracts often point to NIST guidance for security expectations.

Scope of work

What Summit delivers for NIST CSF 2.0

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Current Profile scored by category against evidence, with a target Profile that fits your risk.

Penetration testing

Human-led testing of Identify and Protect outcomes on your key systems.

Control validation

Checks that Protect, Detect and Respond outcomes work in practice.

Evidence pack

Scores tied to dated test reports and artefacts.

Remediation support and retest

Fix guidance, then a retest showing progress between Profiles.

Board-ready report

Function-by-function posture and roadmap in executive language.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

Using the framework step by step

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Set scope and goals

    Week 1

    Decide which part of the organisation and which outcomes you are assessing, and who will own the results.

  2. 2

    Build a current Profile

    Weeks 2 to 4

    Score each category honestly based on evidence, not intention.

  3. 3

    Choose a target Profile

    Week 5

    Pick realistic target outcomes and the tier that fits your risk and customers.

  4. 4

    Plan the gap

    Weeks 5 to 6

    Turn differences into a prioritised plan with owners, budgets and dates.

  5. 5

    Test and validate

    Months 2 to 3

    Use penetration testing and exercises to check the Protect, Detect and Respond outcomes actually work.

  6. 6

    Review regularly

    Quarterly

    Update the Profile as your business and threats change, and report progress.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • An executive summary

    Posture across the six functions in a page.

  • Current and target Profiles

    Scores with evidence references and agreed target tiers.

  • A prioritised roadmap

    Gaps turned into owned, dated actions.

  • Testing evidence

    Reports and retest letters that support the scores.

  • Quarterly review support

    The same Summit team stays with you as the Profile is updated.

The detail

What NIST CSF actually is

The NIST Cybersecurity Framework is voluntary guidance from the US National Institute of Standards and Technology. Version 2.0 was released in February 2024 and is meant for organisations of every size and sector, in any country. It is not a certification: nobody issues a “CSF certificate”. Teams use it to assess where they are, decide where to go and report progress.

It is organised around six functions. The new Govern function covers strategy, roles, policy and supply chain risk. Identify, Protect, Detect, Respond and Recover describe the lifecycle of managing risk from asset knowledge to getting back to normal after an incident.

Two tools make the framework practical. A Profile describes your current and target outcomes so you can plan the gap. Tiers describe how rigorous and integrated your risk management is. Many organisations also map CSF outcomes to ISO 27001, SOC 2 or customer questionnaires.

Key terms in plain English

Function
A high-level group of outcomes: Govern, Identify, Protect, Detect, Respond or Recover.
Profile
A snapshot of your current outcomes and your target outcomes, used to plan priorities.
Tier
A measure of how mature and integrated risk management is, from Tier 1 Partial to Tier 4 Adaptive.
Informative reference
A mapping from a CSF outcome to a standard such as ISO 27001 or a NIST SP 800-53 control.
Requirements

The six functions at a glance

Think of the functions as a loop rather than a straight line. Each one has categories you can score and improve independently.

GV

Govern: set direction and accountability

New in 2.0. Covers organisational context, risk management strategy, roles and responsibilities, policy, oversight and supply chain risk. This is where cybersecurity connects to business decisions.

What it looks like in practice

  • Named owners and an approved policy
  • A risk appetite leaders understand
  • Supply chain risk process
ID

Identify: know what you protect

Maintain an inventory of assets and data, understand the risks to them and track improvement opportunities. You cannot protect what you do not know exists.

What it looks like in practice

  • Asset and data inventory
  • Risk assessments with results acted on
  • Vulnerability discovery, including penetration testing
PR

Protect: put safeguards in place

Identity management and access control, awareness and training, data security, platform security and the resilience of technology infrastructure.

What it looks like in practice

  • Multi-factor authentication and least privilege
  • Encryption and secure configuration
  • Training for staff and developers
DE

Detect: find problems quickly

Continuous monitoring and analysis of adverse events so you can spot compromise early and declare an incident with confidence.

What it looks like in practice

  • Centralised logging and alerting
  • Defined thresholds for escalation
  • Regular testing of detection coverage
RS

Respond: act on detected incidents

Incident management, analysis, reporting, communication and mitigation. Plans must be practised so people know their role under pressure.

What it looks like in practice

  • Incident response plan with roles
  • Communication templates
  • Post-incident lessons captured
RC

Recover: restore and learn

Run recovery plans, communicate during recovery and make sure operations return to normal with improvements captured.

What it looks like in practice

  • Tested backups and restore times
  • Recovery priorities agreed in advance
  • Improvements fed back into Govern and Identify
Where testing fits

How penetration testing supports NIST CSF 2.0

NIST CSF describes outcomes rather than prescribing tests, but the Identify and Protect functions explicitly rely on finding vulnerabilities and validating safeguards. Independent testing provides evidence that outcomes are real.

ID.RA

Risk assessment

Vulnerabilities in assets are identified, validated and recorded. Penetration test findings supply tested, evidence-backed input.

ID.IM

Improvement

Lessons from tests and assessments drive improvement. Retests show progress.

PR.PS

Platform security

Configuration and software are managed to secure standards. Tests expose where defaults and drift remain.

DE.CM

Continuous monitoring

Red team style exercises show whether detection actually notices an attacker.

Avoid these

Common NIST CSF 2.0 mistakes, and how to avoid them

!

Scoring by hope

A profile built on opinion cannot be defended. Tie every score to evidence.

!

Treating it as a checklist

The framework is outcome-based. Meeting the spirit matters more than ticking boxes.

!

Ignoring Govern

Without ownership and policy, technical controls drift. Start with the Govern function.

!

Setting an unrealistic target tier

Moving to a higher tier takes time and money. Choose targets based on risk, not ambition.

FAQ

NIST CSF 2.0 questions, answered

Is NIST CSF a certification?

No. It is voluntary guidance. Organisations use it for self-assessment and planning, and there is no official certificate.

What is new in NIST CSF 2.0?

A new Govern function, a broader audience beyond critical infrastructure, more attention to supply chain risk and online resources such as implementation examples.

How does CSF relate to ISO 27001?

They overlap. CSF is flexible guidance for managing outcomes, while ISO 27001 is a certifiable management system standard. Many teams map between them.

Does the framework require penetration testing?

No specific test is mandated, but several outcomes depend on identifying vulnerabilities and verifying safeguards, which testing supports.

Who should own the CSF profile?

Usually the security leader, with executive sponsorship. The Govern function expects clear accountability at a senior level.

Ready to get NIST CSF 2.0 sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →