Frameworks

NIST Cybersecurity Framework 2.0

The common language of security programs — now with governance at the center.

Book a demo

NIST CSF isn't a certification; it's the framework American organizations use to structure, measure, and communicate their security program. Version 2.0 expanded it beyond critical infrastructure to everyone — and promoted governance to a first-class function.

Six functions, one story

Govern, Identify, Protect, Detect, Respond, Recover. The 2.0 addition of Govern — strategy, roles, oversight, supply-chain risk — reflects where security programs actually fail: not in firewalls, but in ownership. CSF gives boards and engineers a shared vocabulary for both.

Profiles and tiers, used honestly

CSF's power tool is the profile: score your current state against a target state and let the gap drive the roadmap. Implementation tiers describe how mature your risk practices are. Used honestly, this becomes a defensible, board-ready narrative of progress; used as a checkbox, it's wallpaper.

How Compriska helps

Compriska maintains your CSF profile with scored subcategories, maps every control you already run under SOC 2 or ISO 27001 into the framework automatically, and turns the current-versus-target gap into an owned, dated roadmap the executive dashboard can track.

Frequently asked questions

Can we get certified against NIST CSF?

No — CSF is a voluntary framework, not a certifiable standard. Its value is in structuring and communicating your program; pair it with SOC 2 or ISO 27001 when customers need third-party attestation.

Other frameworks

Automate NIST CSF with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo