BlueSteel Cybersecurity

CSF 2.0 ยท six functions

NIST CSF

The Cybersecurity Framework is not certifiable and that is the point. It gives you a common language for describing your security posture to a board, an insurer or a customer, and a structure for deciding what to improve next. It is often the right starting point when no specific framework has been mandated yet.

What the engagement covers

Any organisation wanting a defensible security programme. Typical timeline: 2 to 4 months to a current and target profile.

  • Current profile assessment across the six functions: govern, identify, protect, detect, respond, recover
  • Target profile agreed against your risk appetite rather than a generic maturity ideal
  • Prioritised roadmap between the two, costed
  • Mapping to whichever certifiable framework you are likely to need next, so the work is not repeated
  • Board and insurer facing reporting

Phases

Where an engagement sits at any point, in the language your assessor uses.

  • Current profile assessment
  • Target profile and roadmap agreed
  • Improvement execution
  • Target profile reached, reassessed on a cycle

Related reading

Common questions

Can you be certified against NIST CSF?

No. There is no certification body and no certificate. What you get is a defensible, structured account of your posture and a roadmap, which is what boards and insurers are usually asking for.

What changed in CSF 2.0?

The addition of Govern as a sixth function alongside identify, protect, detect, respond and recover. It elevates governance, roles, policy and supply chain risk from being spread across other functions to being a function in its own right.

Should we do CSF or go straight to a certifiable framework?

If a customer or a contract has named a framework, go to that one. CSF is most useful when nobody has named one yet and you need to decide what to build first without wasting the work.

START HERE

Do not guess how far away you are.

A scored assessment against the NIST CSF control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, which within 90 days takes 25% off the first year. Nothing obliges you to.

See what an assessment covers

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Read the reviews

Start with a scope

Bring the deadline and who is asking for it. Thirty minutes.