Frameworks
NIST Cybersecurity Framework 2.0
The common language of security programs — now with governance at the center.
Book a demoNIST CSF isn't a certification; it's the framework American organizations use to structure, measure, and communicate their security program. Version 2.0 expanded it beyond critical infrastructure to everyone — and promoted governance to a first-class function.
Six functions, one story
Govern, Identify, Protect, Detect, Respond, Recover. The 2.0 addition of Govern — strategy, roles, oversight, supply-chain risk — reflects where security programs actually fail: not in firewalls, but in ownership. CSF gives boards and engineers a shared vocabulary for both.
Profiles and tiers, used honestly
CSF's power tool is the profile: score your current state against a target state and let the gap drive the roadmap. Implementation tiers describe how mature your risk practices are. Used honestly, this becomes a defensible, board-ready narrative of progress; used as a checkbox, it's wallpaper.
How Compriska helps
Compriska maintains your CSF profile with scored subcategories, maps every control you already run under SOC 2 or ISO 27001 into the framework automatically, and turns the current-versus-target gap into an owned, dated roadmap the executive dashboard can track.
Frequently asked questions
Can we get certified against NIST CSF?
No — CSF is a voluntary framework, not a certifiable standard. Its value is in structuring and communicating your program; pair it with SOC 2 or ISO 27001 when customers need third-party attestation.
Other frameworks
Automate NIST CSF with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo