The voluntary US cybersecurity framework, organised around six functions since version 2.0 added Govern. Widely used as a strategic backbone.
The NIST Cybersecurity Framework is a voluntary, risk-based framework for organising cybersecurity activity, published by the US National Institute of Standards and Technology. Version 2.0 organises it around six functions:
The addition of GOVERN in version 2.0 was the substantive change. It recognises what practitioners already knew: security programmes fail on accountability, policy and supply chain oversight more often than on technical controls.
The framework works through profiles — a current profile describing where you are and a target profile describing where you need to be, with the gap between them forming the roadmap. Nothing requires uniform maturity across all six functions, which is what makes it genuinely risk-based.
It is not certifiable. There is no NIST CSF certificate. It is a framework for organising and communicating security posture, not a scheme for demonstrating it to third parties.
Where the problem is that security activity is uncoordinated rather than absent, and the six functions give it shape.
Profile comparison over time communicates progress in a way a control checklist does not, which makes it unusually good for governance reporting.
Where the WA Government Cyber Security Policy integrates NIST CSF directly alongside the Essential Eight and the ASD ISM.
Where NIST frameworks are the common reference point in security conversations with US counterparties.
CSF is widely used as the neutral structure that other frameworks map into, which makes it useful for anyone juggling several obligations.
Where the organisation actually sits across the six functions today, assessed against evidence.
Where it needs to be, driven by risk, sector and obligations rather than by an aspiration to score highly everywhere. Not every function needs the same maturity.
The distance between profiles, prioritised by risk reduction rather than by ease.
The GOVERN function exists because programmes fail on accountability more often than on technique. Roles, policy, risk tolerance and supply chain oversight come before control work.
Identify, Protect, Detect, Respond and Recover, with technical implementation often driven by CIS Controls or the Essential Eight underneath.
Profile comparison over time is what makes CSF genuinely good for board reporting — it shows movement rather than a static rating.
Soveriq uses NIST CSF where an organisation needs a coherent structure and a way to report progress to a board, rather than a certificate. Current profile, target profile, and a roadmap between them, with technical implementation driven by CIS Controls or the Essential Eight underneath.
Where a certifiable obligation also exists, we map the CSF work into ISO 27001 so the same programme serves both. For WA government entities, the policy already integrates CSF, so this is not a parallel effort.
Being direct about what this is. There is no NIST CSF certificate. If what you need is evidence for a customer or a tender, we will tell you to pursue ISO 27001 instead, and use CSF as the organising structure rather than the deliverable.
Modules 03 and 04 do not apply in the certification sense. Where the work supports an ISO 27001 certification or a jurisdictional obligation, those modules apply to that programme.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. There is no certification scheme and no certificate. If you need something to show a buyer, that is ISO 27001. NIST CSF is for organising and communicating your security posture.
The most significant addition is the GOVERN function, which elevates governance, roles, policy and supply chain risk to sit alongside the original five. It reflects a recognition that most security programmes fail on governance rather than on technique.
Different purposes. CSF is a voluntary framework for structuring and communicating; ISO 27001 is a certifiable management system. If a customer or tender demands evidence, you need 27001. If you need a way to organise a programme and report it to a board, CSF does that better. Using both is coherent and common.
Yes, and increasingly so. The WA Government Cyber Security Policy integrates it directly, and it is widely used by Australian enterprises as a reporting structure regardless of jurisdiction.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope