Frameworks · NIST CSF 2.0
NIST CSF: organize your cybersecurity program by functions.
We adopt the NIST Cybersecurity Framework 2.0 to organize your program and measure its maturity — no certification, with a focus on governance and improvement.
Who it applies to
NIST CSF applies to any organization that wants to structure and mature its cybersecurity program with a common language, without needing to be certified.
What the framework requires
NIST CSF isn’t certified: it’s a voluntary framework that organizes the program into six functions and lets you measure maturity (Tiers) and define a target profile.
Six functions
Profiles
Maturity Tiers
A common language
Risks of not acting
- Managing cybersecurity without a structure or a common language.
- Being unable to measure maturity or demonstrate progress.
- Scattering effort without a clear target profile.
- Making it harder to communicate risk to leadership.
The i-Prot proposal
We adopt NIST CSF 2.0 as the program framework: we assess the current profile, define the target and a roadmap by function, with maturity metrics. Integrated into the CGF cycle.
How we work with this framework
Current profile
Target profile
Gap analysis
Roadmap
Measurement and improvement
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses NIST CSF as a source of requirements. This framework mainly covers the Assess, Prioritize, Design and Improve stages of the cycle.
See the CGF methodology →
Complyze and NIST CSF
Complyze organizes the program by function, keeps the target profile and tracks maturity (Tiers) and the roadmap’s progress.
Frequently asked questions
Want to structure your program with NIST CSF?
Tell us your context and we’ll define the target profile and the roadmap.
By submitting you accept our privacy policy.