Skip to content

NIST CSF

NIST CSF 2.0 implemented once, reported many times

All six CSF 2.0 functions, Govern, Identify, Protect, Detect, Respond and Recover, map to the same controls that satisfy your ISMS, BCMS and DSMS. One implementation answers every relevant audit.

Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover
6 functions
Cross-mapped to ISO 27001, BSI IT-Grundschutz, NIS2
3 frameworks
NIST CSF 2.0 publication year
2024

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • NIST CSFRequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

The framework international customers expect

The NIST Cybersecurity Framework is one of the most widely adopted security frameworks globally. Originally developed for US critical infrastructure, it has become a de facto standard for organisations of all sizes seeking a structured, risk-based approach to cybersecurity.

02

One implementation, many frameworks

KaitoSec's multi-framework mapping lets you satisfy NIST CSF subcategories using the same controls that cover ISO 27001 Annex A, BSI IT-Grundschutz and NIS2.

03

Govern function wired into the ISMS

CSF 2.0 elevated governance into a peer function alongside Identify, Protect, Detect, Respond and Recover. KaitoSec's policy and acknowledgement workflows, role assignments and management-review records produce the Govern evidence directly out of the operating ISMS.

The workflow

01

Track maturity per function

Each CSF function shows current and target maturity, the underlying ISMS controls implementing it, and the gap between today and the next assessment. This view feeds management reviews and board briefings.

02

Profile builder for current and target state

Build current and target profiles for each part of the organisation. The comparison produces a work queue sorted by residual risk rather than chapter number.

03

Map CSF subcategories to ISO 27001, IT-Grundschutz and NIS2

Every CSF subcategory is mapped against the corresponding ISO 27001 control, BSI IT-Grundschutz Baustein and NIS2 measure where the substance overlaps. A control is implemented once and becomes visible in all four frameworks at once.

FAQ

What changed in NIST CSF 2.0?

CSF 2.0, published in 2024, adds a sixth function, Govern, which covers organisational context, risk management strategy, roles and responsibilities, policy and oversight. The 2.0 release is also explicitly intended for organisations of all sizes and sectors, not only US critical infrastructure. KaitoSec ships the 2.0 catalogue out of the box.

How does NIST CSF compare to ISO 27001?

ISO 27001 is an auditable management system standard with mandatory clauses and a control library. NIST CSF is a risk-management framework with functions, categories and subcategories. Many organisations adopt CSF as the strategic frame and ISO 27001 as the management system that delivers it. KaitoSec carries both and shows the mapping at every level. This is the same one-control-many-frameworks argument behind resilience made easy.

Can we use CSF profiles to drive improvement work?

Yes. The most common pattern is to build a current profile from where you are today, a target profile from where the business wants to be, and use the gap as the improvement backlog. KaitoSec stores profiles as first-class objects so the gap is always live, not a once-a-year spreadsheet.

Is NIST CSF relevant for European organisations?

Yes. CSF is sector-neutral and increasingly referenced in European supply-chain and customer due-diligence requests, particularly from US-headquartered customers. For European organisations carrying ISO 27001 or NIS2 obligations, CSF is the framing supervisors and customers often expect to see alongside the local standard.