Skip to content

Compliance & frameworks

NIST CSF

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework 2.0 organizes security into six functions — Govern, Identify, Protect, Detect, Respond, and Recover — that give technical teams and the board a shared language for cloud risk. It is not a checklist of controls but a way to structure them, which is exactly why it travels well across auditors, regulators, insurers, and executives. For a multi-cloud company, CSF is often the frame leadership already uses to ask "where are we exposed, and are we watching?" — and the one your other frameworks can be mapped back into.

Who it applies to

NIST CSF is voluntary — there is no CSF law and no body that certifies you against it. What drives adoption is that regulators, enterprise customers, and cyber-insurance underwriters increasingly expect its language: federal and critical-infrastructure contracts reference it, and vendor-risk teams use it to compare suppliers. If your leadership or your insurer wants a maturity picture that spans the whole security program rather than a single audit, CSF is usually the frame they reach for.

Cloud control themes

What NIST CSF asks of your cloud

  • Govern (GV.SC / GV.RM) — cloud risk governance and third-party / supply-chain oversight, new and expanded in CSF 2.0
  • Identify (ID.AM) — knowing which accounts, workloads, and data stores you actually run across clouds
  • Protect (PR.AA / PR.DS) — identity, least privilege, MFA, and encryption of data at rest and in transit
  • Detect (DE.CM / DE.AE) — log coverage and continuous monitoring that would let you see an incident
  • Respond & Recover (RS / RC) — whether your logging and configuration would support investigation and restoration

Domain × framework

Which assessment domains produce NIST CSF evidence

Assessment domainHow it maps
Identity & accessIAM findings map to the Protect function's PR.AA identity-management and access-control category — least privilege, MFA, and deprovisioning evidence.
Data securityEncryption and storage-exposure findings evidence the PR.DS data-security category under Protect.
Network exposureSegmentation and boundary findings support PR.IR technology-infrastructure-resilience and the ID.AM view of what is exposed.
Logging & monitoringLog coverage and detection findings map directly to the Detect function (DE.CM continuous monitoring, DE.AE adverse-event analysis) and underpin Respond and Recover.
Configuration & postureBaseline-drift findings evidence PR.PS platform security and feed the ID.RA risk picture that informs the Govern function.
Framework mappingCSF's six functions are the crosswalk layer itself — the mapping domain expresses the same cloud findings in CSF language alongside SOC 2, ISO 27001, or your sector framework.

What you get

A findings report organized to the six CSF 2.0 functions: each cloud gap placed under Govern, Identify, Protect, Detect, Respond, or Recover, ranked by real risk, so leadership sees the posture in the language they already use and your engineers get a remediation order they can run.

Most relevant to: FinTech, Healthcare, Commercial real estate

Questions

Do you map to CSF 1.1 or 2.0?

CSF 2.0, including the new Govern function and its expanded supply-chain risk category. If your program still references 1.1, the underlying findings translate cleanly — the functions your cloud evidence maps to did not change, they were reorganized.

Is there a CSF certification, and does the health check grant a maturity rating?

No. CSF is a voluntary framework with no accrediting body and no official certificate. The health check is readiness work — it places your cloud findings under the CSF functions so you can see and prioritize gaps; any formal maturity tiering is your own or your assessor's call.

Does CSF replace SOC 2, ISO 27001, or our sector framework?

No — CSF sits above them as an organizing layer. We can express the same cloud findings in CSF terms and in your control framework at once, which is often why leadership asks for CSF: it lets one set of evidence tell a consistent story across audiences.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check